last time I saw this, someone had an AV scanner (Microsoft Defender for Linux) deployed, and it was scanning all the image layers as they were being pulled. This left the temp files open and unable to be unlinked when containerd expected to be able to do so.
👍 1
creamy-pencil-82913
03/25/2024, 10:02 PM
I would generally recommend against running an endpoint security product that’s not container-aware. If they can’t disable it, it should be prevented from mucking about with anything under /var/lib/rancher
a
agreeable-art-61329
03/25/2024, 10:03 PM
Noted! I ran across that previous issue as well. I’ll forward that along and see if there are any potential threads to pull. Appreciate the insight.