What Concierge is for says to use concierge in virtual machines, CI runners and dedicated test hosts, and not on your daily workstation, but we don't say anywhere how to get one of those machines. For Multipass that's not much of a gap (multipass launch, multipass shell, done). For an LXD container it very much is, because MicroK8s inside a container needs a pile of configuration that isn't obvious and fails in confusing ways when any of it is missing.
The Web team's launcher has worked all of it out already:
security.nesting=true and security.privileged=true
linux.kernel_modules=ip_vs,ip_vs_rr,ip_vs_wrr,ip_vs_sh,ip_tables,ip6_tables,netlink_diag,nf_nat,overlay,br_netfilter
/dev/kmsg passed through as a unix-char device, which kubelet requires
lxc.apparmor.profile=unconfined and lxc.cgroup.devices.allow=a via raw.lxc
- remapping the container's
ubuntu user to the host's UID and GID, so that a bind-mounted project directory is readable from both sides
We should write a how-to covering both cases, ending with sudo concierge prepare -p dev inside the machine.
I don't think we want concierge to create the machine itself (that's a different tool, and spread already does it for our own tests), but the knowledge is worth writing down either way.
What Concierge is for says to use concierge in virtual machines, CI runners and dedicated test hosts, and not on your daily workstation, but we don't say anywhere how to get one of those machines. For Multipass that's not much of a gap (
multipass launch,multipass shell, done). For an LXD container it very much is, because MicroK8s inside a container needs a pile of configuration that isn't obvious and fails in confusing ways when any of it is missing.The Web team's launcher has worked all of it out already:
security.nesting=trueandsecurity.privileged=truelinux.kernel_modules=ip_vs,ip_vs_rr,ip_vs_wrr,ip_vs_sh,ip_tables,ip6_tables,netlink_diag,nf_nat,overlay,br_netfilter/dev/kmsgpassed through as aunix-chardevice, whichkubeletrequireslxc.apparmor.profile=unconfinedandlxc.cgroup.devices.allow=aviaraw.lxcubuntuuser to the host's UID and GID, so that a bind-mounted project directory is readable from both sidesWe should write a how-to covering both cases, ending with
sudo concierge prepare -p devinside the machine.I don't think we want concierge to create the machine itself (that's a different tool, and
spreadalready does it for our own tests), but the knowledge is worth writing down either way.