Skip to content

docker-bench-security scenario: "ContainerCreating" - PR157 fixing #136 Azure/AKS breaks KINDΒ #186

@halfluke

Description

@halfluke

This is in a deployment with KIND:

kubectl apply -f scenarios/docker-bench-security/deployment.yaml

kubectl get pods -o wide

NAME                                              READY   STATUS              RESTARTS      AGE     IP                NODE                NOMINATED NODE   READINESS GATES
batch-check-job-mv8kk                             1/1     Running             0             2d      10.244.231.215    kubernetes-worker   <none>           <none>
build-code-deployment-6b6546cdbc-9qc28            1/1     Running             3 (46h ago)   11d     10.244.231.218    kubernetes-worker   <none>           <none>
docker-bench-security-9rkqh                       0/1     ContainerCreating   0             3m22s  

Stuck on ContainerCreating after 1 hour...

Events:
  Type     Reason       Age                  From               Message
  ----     ------       ----                 ----               -------
  Normal   Scheduled    3m11s                default-scheduler  Successfully assigned default/docker-bench-security-dmhbq to kubernetes-worker
  Warning  FailedMount  64s (x9 over 3m12s)  kubelet            MountVolume.SetUp failed for volume "docker-sock-volume" : hostPath type check failed: /var/run/docker.sock is not a directory

157 coming from #136

Need to go back to type: Socket here to make it work in KIND:

volumes:

  • name: docker-sock-volume
    hostPath:
    path: /var/run/docker.sock
    type: Socket

root@kubernetes-master:~/kubernetes-goat/scenarios/docker-bench-security# kubectl get pods -o wide 
NAME                                              READY   STATUS    RESTARTS       AGE    IP                NODE                NOMINATED NODE   READINESS GATES
batch-check-job-mv8kk                             1/1     Running   0              2d1h   10.244.231.215    kubernetes-worker   <none>           <none>
build-code-deployment-6b6546cdbc-9qc28            1/1     Running   3 (46h ago)    11d    10.244.231.218    kubernetes-worker   <none>           <none>
docker-bench-security-k45r6                       1/1     Running   0              117s   192.168.183.201   kubernetes-worker   <none>           <none>
Events:
  Type    Reason     Age   From               Message
  ----    ------     ----  ----               -------
  Normal  Scheduled  13m   default-scheduler  Successfully assigned default/docker-bench-security-k45r6 to kubernetes-worker
  Normal  Pulling    13m   kubelet            Pulling image "madhuakula/hacker-container"
  Normal  Pulled     11m   kubelet            Successfully pulled image "madhuakula/hacker-container" in 1m29.796s (1m29.796s including waiting). Image size: 444025991 bytes.
  Normal  Created    11m   kubelet            Created container: docker-bench
  Normal  Started    11m   kubelet            Started container docker-bench

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions