[systemd-devel] Systemd, cgrupsv2, cgrulesengd, and nftables

Lennart Poettering lennart at poettering.net
Thu Jun 13 20:27:23 UTC 2024


On Do, 13.06.24 21:38, Mikhail Morfikov (mmorfikov at gmail.com) wrote:

> I'm trying to make the 4 things (systemd, cgrupsv2, cgrulesengd, and nftables)
> work together, but I think I'm missing something.

Is "cgrulesengd" interfering with the cgroup tree?

Sorry, but that's simply not supported. cgroupv2 has a single-writer
rule, i.e. every part of the tree has only a single writer, a single
manager. And you must delegate a subtree to other managers if a
different manager shall also manage cgroups.

Hence, if you have something that just takes systemd managed processes
and moves them elsewhere, it's simply not supported. Sorry, you voided
your warranty.

Lennart

--
Lennart Poettering, Berlin


More information about the systemd-devel mailing list