Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Debian Firewall build is broken #75

Closed
mwindower opened this issue Mar 2, 2021 · 1 comment
Closed

Debian Firewall build is broken #75

mwindower opened this issue Mar 2, 2021 · 1 comment

Comments

@mwindower
Copy link
Contributor

mwindower commented Mar 2, 2021

In buster-backports we get systemd in the version 247.3-1 (s. https://metadata.ftp-master.debian.org/changelogs//main/s/systemd/systemd_247.3-1_changelog)

Since 247.2-2 debian switched to "unified" cgroup hierarchy (cgroup2)

We deactivate this during machine installation and set systemd.unified_cgroup_hierarchy=0 as kernel parameter (s. a0690d3)

For normal machines this setting is appropriate but on firewalls things are different:
we need cgroup2 for services on the firewall that are started with ip vrf exec ... e.g. chrony, firewall-controller.

Specifying legacy or hybrid mode for cgroup_hierarchy was unsuccessful.

mwindower added a commit that referenced this issue Mar 4, 2021
* use metal-network from ipv6 branch

* forgot debian

* install nftables in debian from testing

* fix build

* install nftables in debian from testing

* use google-public-dns instead of cloudflare

* deactivate debian firewall because of #75

* use metal-networker v0.6.0

* use metal-networker v0.6.1

Co-authored-by: Markus Wennrich <[email protected]>
Co-authored-by: mwindower <[email protected]>
@mwindower
Copy link
Contributor Author

Deactivated debian firewall build for now with #70

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant