Uploaded image for project: 'Satellite'
  1. Satellite
  2. SAT-38707

IoP services fail when fapolicyd is enabled

XMLWordPrintable

    • None
    • None
    • None
    • None

      Description of problem:

      fapolicyd blocks container processes from running on Satellite w/ IoP enabled.

      This is reported in RHEL:

      fapolicyd default rule file 30-patterns.rules prevents starting containers
      https://issues.redhat.com/browse/RHEL-37912 

      How reproducible:

      100%

      Is this issue a regression from an earlier version:

      No

      Steps to Reproduce:

      1.) Enabled fapolicyd on RHEL 9 system

      2.) Install Satellite 6.18 + IoP

      3.) See iop service startup failures.

       

      Business Impact / Additional info:

       

      2025-09-22 22:30:07 [ERROR ] [configure] Sep 22 22:30:06 satellite.example.com podman[34702]: 2025-09-22 22:30:06.37095434 -0400 EDT m=+9.713549470 container create [...] (image=registry.stage.redhat.io/amq-streams/kafka-39-rhel9:2.9.1-1, name=iop-core-kafka, [...])2025-09-22 22:30:07 [ERROR ] [configure] Sep 22 22:30:06 satellite.example.com podman[34702]: 2025-09-22 22:30:06.345684594 -0400 EDT m=+9.688279714 image pull [...] registry.stage.redhat.io/amq-streams/kafka-39-rhel9:2.9.1-12025-09-22 22:30:07 [ERROR ] [configure] Sep 22 22:30:06 satellite.example.com conmon[34900]: conmon a108bd43b2ef03e90b75 <nwarn>: runtime stderr: /usr/bin/crun: error while loading shared libraries: libsystemd.so.0: cannot open shared object file: Operation not permitted2025-09-22 22:30:07 [ERROR ] [configure] Sep 22 22:30:06 ip-10-0-168-16.rhos-01.prod.psi.rdu2.redhat.com conmon[34900]: conmon a108bd43b2ef03e90b75 <error>: Failed to create container: exit status 1272025-09-22 22:30:07 [ERROR ] [configure] Sep 22 22:30:06 ip-10-0-168-16.rhos-01.prod.psi.rdu2.redhat.com iop-core-kafka[34902]: /usr/bin/crun: error while loading shared libraries: libsystemd.so.0: cannot open shared object file: Operation not permitted2025-09-22 22:30:07 [ERROR ] [configure] Sep 22 22:30:06 ip-10-0-168-16.rhos-01.prod.psi.rdu2.redhat.com iop-core-kafka[34702]: time="2025-09-22T22:30:06-04:00" level=error msg="Removing container [...] from runtime after creation failed" 

              ehelms@redhat.com Eric Helms
              rhn-support-tpapaioa Tasos Papaioannou
              Tasos Papaioannou Tasos Papaioannou
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: