Page MenuHomeVyOS Platform

Containers with port-mappings doesnt seem to work when using VRFs
Open, NormalPublicBUG

Description

I am attempting to run lscr.io/linuxserver/kasm:1.19.0 as a container in VyOS.

My VyOS host have 2 VRFs configured: MGMT (10.99.0.100/24) and PROD (192.168.1.20/24 with defgw: 192.168.1.254).

The container itself doesnt seem to be able to bind to VRF's (at least I havent found an obvious way to do so) so having allow-host-networks wont work.

This means Im forced to create a custom network for the container and use port-mappings.

I did so with:

set container network kasm prefix '198.18.1.0/24'
set container network kasm type bridge
set container network kasm vrf 'PROD'

And then configured the port-mappings for the container:

set container name kasm network kasm address '198.18.1.100'
set container name kasm network kasm mac '<REMOVED>'
set container name kasm port TCP_443 destination '443'
set container name kasm port TCP_443 listen-address '192.168.1.20'
set container name kasm port TCP_443 protocol 'tcp'
set container name kasm port TCP_443 source '443'
set container name kasm port TCP_3000 destination '3000'
set container name kasm port TCP_3000 listen-address '192.168.1.20'
set container name kasm port TCP_3000 protocol 'tcp'
set container name kasm port TCP_3000 source '3000'

However the port-mappings seems to not pick up on the VRF I wish to be used:

> sudo ss -atulpn
tcp   LISTEN 0      4096        192.168.1.20:443        0.0.0.0:*    users:(("conmon",pid=90861,fd=5))      
tcp   LISTEN 6      4096        192.168.1.20:3000       0.0.0.0:*    users:(("conmon",pid=90861,fd=6))

Running a tcpdump on the host I do see the SYN, SYN+ACK, ACK being performed followed by PSH+ACK, ACK by the client connecting to https://192.168.1.20:3000 and then nothing.

What am I doing wrong?

Shouldnt there be some vrf command for set container name <name> port <portname> vrf <vrf>?

The whole container config:

Create directories at the host:

mkdir -p /config/container/kasm/opt
mkdir -p /config/container/kasm/profiles

Add this to VyOS config (vrf MGMT and PROD are already present):

set container name kasm environment PGID value '102'
set container name kasm environment PUID value '0'
set container name kasm environment TZ value 'Europe/Stockholm'
set container name kasm image 'lscr.io/linuxserver/kasm:1.19.0'
set container name kasm memory '16384'
set container name kasm network kasm address '198.18.1.100'
set container name kasm network kasm mac '<REMOVED>'
set container name kasm port TCP_443 destination '443'
set container name kasm port TCP_443 listen-address '192.168.1.20'
set container name kasm port TCP_443 protocol 'tcp'
set container name kasm port TCP_443 source '443'
set container name kasm port TCP_3000 destination '3000'
set container name kasm port TCP_3000 listen-address '192.168.1.20'
set container name kasm port TCP_3000 protocol 'tcp'
set container name kasm port TCP_3000 source '3000'
set container name kasm privileged
set container name kasm restart 'on-failure'
set container name kasm volume opt destination '/opt'
set container name kasm volume opt source '/config/container/kasm/opt'
set container name kasm volume profiles destination '/profiles'
set container name kasm volume profiles source '/config/container/kasm/profiles'
set container network kasm prefix '198.18.1.0/24'
set container network kasm type bridge
set container network kasm vrf 'PROD'

When adding above the line set container name kasm network kasm mac '<REMOVED>' can be left out since VyOS will autoassign a MAC-address anyway.

Details

Version
Stream 2026.03
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)