Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[docker-in-docker] v4 with iptablesSwitchAtRuntime:true default on Ubuntu 26.04 host/devcontainer image activates iptables-legacy instead of iptables-nft

Aperta
#1,709 0 commenti 1 reazione 1 assegnatario Vedi su GitHub

I maintainer di solito rispondono entro 8 giorni

@v-Kaniska244 ci sta già lavorando.

Dal 20/8/2026.

Valutazione

Questa issue non è ancora stata valutata.

Descrizione

After upgrading the devcontainer configuration of siemens/ghostwire to use an Ubuntu 26.04 base image and the docker-in-docker:4 feature on a Ubuntu 26.04 host a test related to nft packet forwarding rules failed. Diving deeper revealed that the docker-in-docker:4 feature with the default setting iptablesSwitchAtRuntime:true activates iptables-legacy instead of iptables-nft.

It seems that the feature sees that ip_tables is listed in /proc/modules and thus unfortunately falls on the wrong side of the slice of bread, activating iptables-legacy.

Forcing iptablesSwitchAtRuntime:false correctly activates iptables-nft instead when building on this host.

The problem now is that when other users/projects use the default iptablesSwitchAtRuntime:true setting they end up with the legacy when the nft would have been the better choice: as there is no Go native iptables (legacy) interface module available, but there is a Go native nftables module from Google, not least Edgeshark/Ghostwire as well as some other tools cannot correctly figure out the port forwarding inside dev containers when using these diagnosis tools.

Would it be possible to fix this in the way that iptables-nft gets activated when nf_tables is available, as well as iptables-nft? This would hopefully make the slice of bread fall on the better side for many unsuspecting devcontainer feature users.

Lingua principale
Shell
Stelle
1.5k
Fork
621
Merge medio
7g 8h
PR unite (30g)
10

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di devcontainers/features

Tutte le issue di devcontainers/features

Issue simili

Altre issue su Shell/Bash

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.