!VhzbGHamdfMiGxpXyg:robins.wtf

NixOS Incus and LXC

46 Members
lxc, lxd, incus discussions related to NixOS16 Servers

Load older messages


SenderMessageTime
12 May 2025
@c0ba1t:matrix.orgCobalt* Doesn't seem to be a supported backend in the virtualization module though22:18:54
@adam:robins.wtfadamcstephens Huh? 22:27:06
@hexa:lossy.networkhexaOCI is not virtualization but containerizationn22:29:14
@hexa:lossy.networkhexahence the name Open Container Intiativei22:29:34
@hexa:lossy.networkhexa* OCI is not virtualization but containerization22:29:41
@c0ba1t:matrix.orgCobaltI was referring to `virtualisation.oci-containers`, the nixos "module" for declarative containers with podman/docker. 22:32:16
@c0ba1t:matrix.orgCobaltApologies, it that caused confusion here22:33:09
@c0ba1t:matrix.orgCobalt* Apologies, if that caused confusion here22:33:18
@hexa:lossy.networkhexamisnomer22:33:27
@hexa:lossy.networkhexa* misnomer, yeah22:33:36
@adam:robins.wtfadamcstephens Ahh that makes sense. Guessing if you'd solve declarative incus oci containers you'd do most of the work for declarative instances. ;) 22:45:49
17 May 2025
@adam:robins.wtfadamcstephensbah, I guess I need to figure out this instance networking issue I'd seen on my desktop. It's in the 25.05 upgrade :/21:16:16
@adam:robins.wtfadamcstephensit seems that incus interfaces attached to a bridge with a pvid aren't able to communicate. 21:17:09
@adam:robins.wtfadamcstephens* it seems that incus interfaces with a pvid attached to a vlan-aware bridge aren't able to communicate. 21:17:24
@adam:robins.wtfadamcstephens
veth4aa189fb      2010 PVID Egress Untagged
21:35:52
@adam:robins.wtfadamcstephenstraffic egressing from the bridge to that interface is fine, but traffic ingress is getting dropped for some reason21:36:19
@adam:robins.wtfadamcstephenshmm, it's the firewall 21:48:17
@adam:robins.wtfadamcstephens solved by setting networking.firewall.checkReversePath = "loose" 22:08:59
21 May 2025
@spaenny:boehm.sh@spaenny:boehm.sh left the room.09:33:02
26 May 2025
@galaxyyy:matrix.orgSaturn
In reply to @adam:robins.wtf
sorry. i've never even tried the oci support. though you made me realize we have zero tests for it

It ended up being a commit(s) made in 6.12. I made a patch to revert said commit(s) and override Incus for my deployments and that has fixed it.

I made a post on the LinuxContainer forums here: https://discuss.linuxcontainers.org/t/app-containers-oci-not-getting-ipv4/23708

19:35:33
@galaxyyy:matrix.orgSaturn

Now I'm struggling to get a NVIDIA GPU passed to a container with nvidia.runtime

Seems to be a NixOS specific issue based on some forum posts

19:36:46
@adam:robins.wtfadamcstephens https://discuss.linuxcontainers.org/t/incus-6-11-update-containers-with-nvidia-gpu-passthrough-will-not-start/23400/16 23:09:39
@adam:robins.wtfadamcstephens Someone can submit a PR, but I don't use this capability and haven't prioritized patching it. 23:11:19
@adam:robins.wtfadamcstephens I'm really not sure why upstream thinks it appropriate to ship broken stuff, then encourage distributions to patch it with unreleased patches  23:15:06
@adam:robins.wtfadamcstephens Just so upstream can keep their version numbers aligned  23:16:04
@adam:robins.wtfadamcstephens Anyway, my rant aside, I'd review a PR but am not super motivated to fix this. In one sense I'm also trying to encourage others to get involved in the LXC stack 23:30:17
@galaxyyy:matrix.orgSaturnUnderstood. I'm testing this now on my end, if it works I'll submit a PR23:42:46
27 May 2025
@deeok:matrix.org@deeok:matrix.org joined the room.21:08:34
7 Jun 2025
@deeok:matrix.org@deeok:matrix.org changed their display name from deeok to matrixrooms.info mod bot (does NOT read/send messages and/or invites; used for checking reported rooms).22:14:25
8 Jun 2025
@deeok:matrix.org@deeok:matrix.org left the room.00:06:25

Show newer messages


Back to Room ListRoom Version: 10