When having netns configured:
set netns name example
And trying to use a container then you will most likely receive this error during commit:
vyos@vyos# commit
[ container ]
Traceback (most recent call last):
File "/usr/libexec/vyos/services/vyos-configd", line 157, in run_script
script.apply(c)
File "/usr/libexec/vyos//conf_mode/container.py", line 681, in apply
cmd(f'systemctl restart vyos-container-{name}.service')
File "/usr/lib/python3/dist-packages/vyos/utils/process.py", line 174, in cmd
raise OSError(code, feedback)
PermissionError: [Errno 1] failed to run command: systemctl restart vyos-container-dns-server.service
returned:
exit code: 1
[[container]] failed
Commit failed
[edit]Trying to start container manually through "sudo podman" you will see that it fails to start the container due to missing dependency of package slirp4netns (with dependencies).
Suggestions:
- Add slirp4netns (with dependencies) to VyOS.
or
- Remove possibility to configure netns through VyOS config since it doesnt seems to be complete?
As in there doesnt seem to exist any other parts of the config where which NETNS to be used can be defined (like with VRF).
Bonus)
IMHO the use of NETNS should be "hidden" (removed from config) and part of creating a VRF just like with other NOSes such as Arista EOS etc.
That is creating a VRF would also create a NETNS with the same name and its actually entering the NETNS you do whe you in the opmode run "force cli vrf".