Re: [Lxc-users] Can we run Ubuntu template on RHEL6?

2012-03-07 Thread Mauras Olivier
On Wed, Mar 7, 2012 at 3:16 PM, Allen Elliott wrote: > HI: > I created a template of Ubuntu 10.10, and run it on RHEL6(with kernel > 2.6.32). I can't start it until I recompiled the 3.0 kernel. > > It seems fine most of time, except the connection, I can't connect to > the guest OS from the host w

Re: [Lxc-users] RH and clones 6.2, LXC, SElinux and multiple DEVPTS instances

2012-03-07 Thread Mauras Olivier
st. After removing everything > /dev/pts related from the fstab in the /etc directory of the containers, > everything magically worked. > > BR, > --ilf > > > On Tue, 2012-03-06 at 10:54 +0100, Mauras Olivier wrote: > > Hello, > > I've finally successfully

Re: [Lxc-users] RH and clones 6.2, LXC, SElinux and multiple DEVPTS instances

2012-03-06 Thread Mauras Olivier
On Tue, Mar 6, 2012 at 1:19 PM, Mauras Olivier wrote: > > > On Tue, Mar 6, 2012 at 12:13 PM, Ramez Hanna wrote: > >> On Tue, Mar 6, 2012 at 1:07 PM, Mauras Olivier >> wrote: >> > >> > >> > On Tue, Mar 6, 2012 at 11:12 AM, Ramez Hanna >> w

Re: [Lxc-users] RH and clones 6.2, LXC, SElinux and multiple DEVPTS instances

2012-03-06 Thread Mauras Olivier
On Tue, Mar 6, 2012 at 12:13 PM, Ramez Hanna wrote: > On Tue, Mar 6, 2012 at 1:07 PM, Mauras Olivier > wrote: > > > > > > On Tue, Mar 6, 2012 at 11:12 AM, Ramez Hanna > wrote: > >> > >> On Tue, Mar 6, 2012 at 12:06 PM, Iliyan Stoyanov wrote:

Re: [Lxc-users] RH and clones 6.2, LXC, SElinux and multiple DEVPTS instances

2012-03-06 Thread Mauras Olivier
this issue a week ago with > > some of my SL6.2 containers on a fedora 16 host. After removing > everything > > /dev/pts related from the fstab in the /etc directory of the containers, > > everything magically worked. > > > > BR, > > --ilf > >

Re: [Lxc-users] RH and clones 6.2, LXC, SElinux and multiple DEVPTS instances

2012-03-06 Thread Mauras Olivier
unt devpts fs also. I had this issue a week ago with > some of my SL6.2 containers on a fedora 16 host. After removing everything > /dev/pts related from the fstab in the /etc directory of the containers, > everything magically worked. > > BR, > --ilf > > > On Tue, 2

[Lxc-users] RH and clones 6.2, LXC, SElinux and multiple DEVPTS instances

2012-03-06 Thread Mauras Olivier
Hello, I've finally successfully migrated my SMACK setup over SElinux to isolate my containers - Thanks to the folks on #selinux@freenode - on a Scientific Linux 6.2 host. (I may share my policy with some details if some of you are interested) So far so good, after loads of hits and misses almost

Re: [Lxc-users] [MySQL] Weird performances problem between containers on a same host

2011-08-11 Thread Mauras Olivier
Ok so to make things working out quickly, i added some network interfaces to the host and moved the MySQL container on a second bridge using eth2 No more speed problem... It only happens on containers sharing the same devices. On Thu, Aug 11, 2011 at 10:10 AM, Mauras Olivier wrote: > A

Re: [Lxc-users] [MySQL] Weird performances problem between containers on a same host

2011-08-11 Thread Mauras Olivier
Also, bandwidth between containers is very bad... scp a file doesn't get over 2.1MB/s - On gigabit interface - and drop over time. On Thu, Aug 11, 2011 at 9:32 AM, Mauras Olivier wrote: > So here's my results. > On 55 packets transmitted for the mysql request > 25 cor

Re: [Lxc-users] [MySQL] Weird performances problem between containers on a same host

2011-08-11 Thread Mauras Olivier
f not supported? --- Misc --- Veth pair device: enabled Macvlan: enabled Vlan: enabled File capabilities: enabled Thanks, Olivier On Wed, Aug 10, 2011 at 6:25 PM, Daniel Lezcano wrote: > On 08/10/2011 05:54 PM, Daniel Lezcano wrote: > > On 08/10/2011 04:51 PM, Mauras Olivier wrote: > >>

[Lxc-users] [MySQL] Weird performances problem between containers on a same host

2011-08-10 Thread Mauras Olivier
Hello, I have several containers running on a host - ~10 One of them is running a MySQL database. Several of the others are running php code under apache that fetch datas from the database. Host is using eth0, while my containers are on a bridge using eth1, and configured in macvlan bridge mode.

Re: [Lxc-users] Mitigating LXC Container Evasion?

2011-08-03 Thread Mauras Olivier
want to check the documentation if you need to fine tune network accesses. Cheers, Olivier On Wed, Aug 3, 2011 at 7:36 PM, Andre Nathan wrote: > Hi Olivier > > On Tue, 2011-08-02 at 12:13 +0200, Mauras Olivier wrote: > > Here's a practical example: > > # smack_label.py -w -r

Re: [Lxc-users] Mitigating LXC Container Evasion?

2011-08-02 Thread Mauras Olivier
ly setting up the rules you need to secure your containers and datas inside them. All smack documentation is available in the Kernel sources directory. Hope this helps and that i've made myself clear enough, Olivier On Mon, Aug 1, 2011 at 2:27 PM, Andre Nathan wrote: > Hi Olivier > &g

Re: [Lxc-users] Mitigating LXC Container Evasion?

2011-07-31 Thread Mauras Olivier
Hello Matthew, Here's an example in on of my containers: root@nasty:~# ps ax PID TTY STAT TIME COMMAND 1 ?Ss 0:13 init [3] 44 ?Ss 0:02 /usr/sbin/syslogd 141 ?Ss 0:00 /usr/sbin/sshd 144 ?S 0:01 /usr/sbin/crond -l6 149 ?

Re: [Lxc-users] LXC on ESXi (help)

2011-05-17 Thread Mauras Olivier
I tried this way either, but there's two blocking problems with that - At least for me: - Can't use this feature on 2.6.32 kernels - Have to reboot to had a new interface to setup a new container - Yeah the say you want to add up a 11th container ;) Olivier On Tue, May 17, 2011 at 5:36 PM, Ulli

Re: [Lxc-users] LXC on ESXi (help)

2011-05-17 Thread Mauras Olivier
Hello David, As you can see you only force the MAC adress _inside_ the container, on the host the MAC for the veth is "out of the bounds" for ESX it doesn't seem to like that - At least that's my guess cause i have not been able to make it work correctly with this configuration. First thing to ch

Re: [Lxc-users] Fwd: Container inside an ESX VM

2011-05-02 Thread Mauras Olivier
On Wed, Apr 27, 2011 at 11:59 AM, Mauras Olivier wrote: > > > On Tue, Apr 26, 2011 at 6:03 PM, Mauras Olivier > wrote: > >> >> >> On Sat, Apr 23, 2011 at 12:40 PM, Mauras Olivier > > wrote: >> >>> Hi Geordy, >>> >>> Thanks

Re: [Lxc-users] Fwd: Container inside an ESX VM

2011-04-27 Thread Mauras Olivier
On Tue, Apr 26, 2011 at 6:03 PM, Mauras Olivier wrote: > > > On Sat, Apr 23, 2011 at 12:40 PM, Mauras Olivier > wrote: > >> Hi Geordy, >> >> Thanks for your reply. The first one is actually already set here. I asked >> ESX folks to create me my own vswitch

Re: [Lxc-users] Fwd: Container inside an ESX VM

2011-04-26 Thread Mauras Olivier
On Sat, Apr 23, 2011 at 12:40 PM, Mauras Olivier wrote: > Hi Geordy, > > Thanks for your reply. The first one is actually already set here. I asked > ESX folks to create me my own vswitch with promisc mode enabled. > I saw the second one coming, but didn't think that

Re: [Lxc-users] Fwd: Container inside an ESX VM

2011-04-23 Thread Mauras Olivier
Hi Geordy, Thanks for your reply. The first one is actually already set here. I asked ESX folks to create me my own vswitch with promisc mode enabled. I saw the second one coming, but didn't think that could make something... There's also a setting like "mac.verify" that can be set to false direct

Re: [Lxc-users] Fwd: Container inside an ESX VM

2011-04-18 Thread Mauras Olivier
t 5minutes later interface get shut down and kernel panic... That's all for today :D On Mon, Apr 18, 2011 at 11:47 AM, Mauras Olivier wrote: > Thanks, help is really appreciated. > > > Cheers, > Olivier > > > On Sun, Apr 17, 2011 at 8:39 AM, Geordy Korte wrote: > &

Re: [Lxc-users] Fwd: Container inside an ESX VM

2011-04-18 Thread Mauras Olivier
Thanks, help is really appreciated. Cheers, Olivier On Sun, Apr 17, 2011 at 8:39 AM, Geordy Korte wrote: > Hi, > > Thought about it some more and i think it might be an advanced esx feature > that restricts this. Basically a couple of adv features block spoofing and > mac changes on a vhost. I

Re: [Lxc-users] Fwd: Container inside an ESX VM

2011-04-16 Thread Mauras Olivier
On Sat, Apr 16, 2011 at 3:45 PM, Serge Hallyn wrote: > > As you see in this example, before issuing the network restart, my veth > MAC > > was already higher than the eth0 MAC but the guest hadn't a working > network > > connection. > > Thanks for the info. > > > After restarting network on the ho

[Lxc-users] Fwd: Container inside an ESX VM

2011-04-15 Thread Mauras Olivier
Missed the list in copy. sorry. On Fri, Apr 15, 2011 at 3:20 PM, Serge Hallyn wrote: > Quoting Mauras Olivier (oliver.mau...@gmail.com): > > Hello, > > > > I'm struggling for two days now with some completely weird network > > behaviours. > > My host is a

[Lxc-users] Container inside an ESX VM

2011-04-15 Thread Mauras Olivier
Hello, I'm struggling for two days now with some completely weird network behaviours. My host is a virtual machine hosted on an ESX farm. I planned to deploy several containers on it to achieve various tasks. Host is running Scientific Linux 6 with default kernel (2.6.32), and my container is an

[Lxc-users] ESX VM host and network issues

2011-04-14 Thread Mauras Olivier
Hello, I'm struggling for two days now with some completely weird network behaviours. My host is a virtual machine hosted on an ESX farm. I planned to deploy several containers on it to achieve various tasks. Host is running Scientific Linux 6 with default kernel (2.6.32), and my container is an

[Lxc-users] ESX VM host and network issues

2011-04-14 Thread Mauras Olivier
Hello, I'm struggling for two days now with some completely weird network behaviours. My host is a virtual machine hosted on an ESX farm. I planned to deploy several containers on it to achieve various tasks. Host is running Scientific Linux 6 with default kernel (2.6.32), and my container is an