[Users] sync in container

2012-02-01 Thread Maoke
hi all, we found sync in container may cause high disk I/O load (not able to supress it even with blkio throttle settings). do anyone have the similar experience and information to share? thanks a lot in advance. best, maoke ___ Users mailing list User

[Users] vmstat FPE

2012-02-01 Thread Maoke
hi all, we recently found the vmstat in container result in Float Point Exception (but it is not a problem in the host). the kernel is 2.6.32-042stab044.11 and the procps version 3.2.7. any suggestions and hints? thanks a lot in advance! best, maoke ___

Re: [Users] Share container's HD space over servers

2012-02-01 Thread Scott Dowdle
Blau, - Original Message - > I've setup a mirrored GlusterFs to share container's disc space and to > have a spare fisical server in case it's needed. > I only share the "private" directory over two servers, is it OK or I > should share whole "lib/vz" directory? Now I switched from origina

Re: [Users] Problems doing live migration

2012-02-01 Thread Scott Dowdle
Greetings, - Original Message - > I'm trying to do a manual live migration on a Linux > 2.6.32-5-openvz-amd64 and > openvz 3.0.24, but I'm getting some troubles: > > .- Container's suspend seems OK. > .- But I'm not able to dump the container: > "Can not dump container: Invalid argument >

Re: [Users] RHEL6 and stateful firewall inside container

2012-02-01 Thread Vasily Averin
On 02/01/2012 04:39 PM, Vasily Averin wrote: > Hi Mikko, > > 1) You need to enable conntrack support for container, it is disabled by > default. > IIRC following command should be enough to enable conntrack support for > specified container only: > # vzctl set --iptables iptable_filter --iptabl

Re: [Users] RHEL6 and stateful firewall inside container

2012-02-01 Thread Vasily Averin
Hi Mikko, 1) You need to enable conntrack support for container, it is disabled by default. IIRC following command should be enough to enable conntrack support for specified container only: # vzctl set --iptables iptable_filter --iptables ip_conntrack --save 2) Also you need to load all modul

[Users] RHEL6 and stateful firewall inside container

2012-02-01 Thread Mikko Vasili Hirvonen
Hello users@openvz.org I'm trying to upgrade our rhel5 based openvz servers to rhel6 but I got problem with iptables. If I try to use firewall inside container, I can load rules, but firewall rejects all incoming packets. Host is redhet-6 and container is centos-6. I tested with kernels vzkernel-