From 52d14c96c729700427c958b048e14980c217d4ff Mon Sep 17 00:00:00 2001 From: corbin-coleman Date: Mon, 14 Jan 2019 23:27:51 +0000 Subject: [PATCH 1/2] Start docker.service after containerd.service Signed-off-by: corbin-coleman (cherry picked from commit 27f7ae18f42d10221c214163e253ba79b79731d8) Signed-off-by: Sebastiaan van Stijn Upstream-commit: 00600cd1217bd545762dbef7c488136735d662b6 Component: packaging --- components/packaging/systemd/docker.service | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/components/packaging/systemd/docker.service b/components/packaging/systemd/docker.service index 9cc6216dab..1605e2896d 100644 --- a/components/packaging/systemd/docker.service +++ b/components/packaging/systemd/docker.service @@ -2,7 +2,7 @@ Description=Docker Application Container Engine Documentation=https://docs.docker.com BindsTo=containerd.service -After=network-online.target firewalld.service +After=network-online.target firewalld.service containerd.service Wants=network-online.target Requires=docker.socket From 24e4136d6cd269ffa7b821a36c94474be0dadbbd Mon Sep 17 00:00:00 2001 From: Sebastiaan van Stijn Date: Mon, 11 Feb 2019 14:28:03 +0100 Subject: [PATCH 2/2] systemd: set --containerd socket patch to prevent race-condition containerd is now running as a separate service, and should no longer be started as a managed child-process of dockerd. The dockerd service already specifies that it should be started `After` the containerd.service, but there is still a race condition, where containerd is started, but its socket is not yet created. In that situation, `dockerd` detects that the containerd socket is missing, and will start a new instance of containerd (as a managed child-process), which causes live-restore to fail. This patch explicitly sets the `--containerd` daemon option. If this option is set, `dockerd` will not start a new instance of containerd. Signed-off-by: Sebastiaan van Stijn (cherry picked from commit 1985463b1337e55c0dfcad2fb985fb5af5a10c78) Signed-off-by: Sebastiaan van Stijn Upstream-commit: 15653df497646518ec5af5cab55ebb4461ee5b80 Component: packaging --- components/packaging/systemd/docker.service | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/components/packaging/systemd/docker.service b/components/packaging/systemd/docker.service index 9cc6216dab..13ca4d1a3c 100644 --- a/components/packaging/systemd/docker.service +++ b/components/packaging/systemd/docker.service @@ -11,7 +11,7 @@ Type=notify # the default is not to use systemd for cgroups because the delegate issues still # exists and systemd currently does not support the cgroup feature set required # for containers run by docker -ExecStart=/usr/bin/dockerd -H fd:// +ExecStart=/usr/bin/dockerd -H fd:// --containerd=/run/containerd/containerd.sock ExecReload=/bin/kill -s HUP $MAINPID TimeoutSec=0 RestartSec=2