# Docker pihole & gentoo pi64

**URL:** https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771
**Category:** docker
**Created:** [December 2, 2019, 12:32pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771 "2019-12-02T12:32:37Z")
**Posts on this page:** 14
**Page:** 1

<div class="post-metadata">

### Author: ![br6](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/br6/32/10979_2.png) [@br6](https://discourse.pi-hole.net/u/br6)
#### Post date: [December 2, 2019, 12:32pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/1 "2019-12-02T12:32:37Z")

</div>

#### Please follow the below template, it will help us to help you!

## Expected Behaviour:

_[functioning admin page no lighttp error]_

## Actual Behaviour:

\_[2019-12-02 12:25:12: (server.c.970) couldn't get 'max filedescriptors' Operation not permitted

Stopping lighttpd

ghttpd: no process found]\_

## Debug Token:

_[[https://tricorder.pi-hole.net/5r98xdq248](https://tricorder.pi-hole.net/5r98xdq248)]_

---

<div class="post-metadata">

### Author: ![br6](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/br6/32/10979_2.png) [@br6](https://discourse.pi-hole.net/u/br6)
#### Post date: [December 2, 2019, 2:08pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/2 "2019-12-02T14:08:29Z")

</div>

here is link to working pihole docker in Manjaro arm on same pi4

## Debug Token:

_[[https://tricorder.pi-hole.net/k1vr9gkenh](https://tricorder.pi-hole.net/k1vr9gkenh)]_

---

<div class="post-metadata">

### Author: ![DanSchaper](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/danschaper/32/91_2.png) [@DanSchaper](https://discourse.pi-hole.net/u/DanSchaper)
#### Post date: [December 2, 2019, 6:25pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/3 "2019-12-02T18:25:42Z")

</div>

Is SELinux enabled on the Gentoo install?

---

<div class="post-metadata">

### Author: ![br6](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/br6/32/10979_2.png) [@br6](https://discourse.pi-hole.net/u/br6)
#### Post date: [December 3, 2019, 10:14am UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/7 "2019-12-03T10:14:45Z")

</div>

no I check the status and its disabled  
selinuxenabled  
if [$? -ne 0]  
then  
echo "DISABLED"  
else  
echo "ENABLED"  
fi

---

<div class="post-metadata">

### Author: ![br6](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/br6/32/10979_2.png) [@br6](https://discourse.pi-hole.net/u/br6)
#### Post date: [December 3, 2019, 1:51pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/8 "2019-12-03T13:51:02Z")

</div>

I believe the issue is actually port 80 not working/blocked between gentoo pi64 (sakaki) host and docker containers

---

<div class="post-metadata">

### Author: ![DanSchaper](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/danschaper/32/91_2.png) [@DanSchaper](https://discourse.pi-hole.net/u/DanSchaper)
#### Post date: [December 3, 2019, 3:59pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/9 "2019-12-03T15:59:10Z")

</div>

A blocked port wouldn't cause a lack of permissions error though.

---

<div class="post-metadata">

### Author: ![br6](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/br6/32/10979_2.png) [@br6](https://discourse.pi-hole.net/u/br6)
#### Post date: [December 3, 2019, 4:34pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/10 "2019-12-03T16:34:43Z")

</div>

here is my docker info  
docker info  
Client:  
Debug Mode: false

Server:  
Containers: 3  
Running: 2  
Paused: 0  
Stopped: 1  
Images: 4  
Server Version: 19.03.4  
Storage Driver: overlay2  
Backing Filesystem: extfs  
Supports d\_type: true  
Native Overlay Diff: true  
Logging Driver: json-file  
Cgroup Driver: cgroupfs  
Plugins:  
Volume: local  
Network: bridge host ipvlan macvlan null overlay  
Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog  
Swarm: inactive  
Runtimes: runc  
Default Runtime: runc  
Init Binary: docker-init  
containerd version: b34a5c8af56e510852c35414db4c1f4fa6172339  
runc version:  
init version: fec3683b971d9c3ef73f284f176672c44b448662  
Security Options:  
seccomp  
Profile: default  
Kernel Version: 4.19.86-v8-5a3f41938f71-p4-bis+  
Operating System: Gentoo/Linux  
OSType: linux  
Architecture: aarch64  
CPUs: 4  
Total Memory: 3.666GiB  
Name: pi64  
ID: xxx  
Docker Root Dir: /var/lib/docker  
Debug Mode: false  
Registry: [https://index.docker.io/v1/](https://index.docker.io/v1/)  
Labels:  
Experimental: false  
Insecure Registries:  
127.0.0.0/8  
Live Restore Enabled: false

WARNING: No swap limit support  
WARNING: No cpu cfs quota support  
WARNING: No cpu cfs period support

---

<div class="post-metadata">

### Author: ![br6](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/br6/32/10979_2.png) [@br6](https://discourse.pi-hole.net/u/br6)
#### Post date: [December 8, 2019, 11:53am UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/11 "2019-12-08T11:53:26Z")

</div>

I have confirmed behaviour from other uses, its not a port related issue as docker is forwarding 80 to host correctly.  
maybe its privilege related as mentioned by the maintainer for gentoo pi 64  
[https://www.raspberrypi.org/forums/viewtopic.php?f=54&t=188448&start=375#p1577365](https://www.raspberrypi.org/forums/viewtopic.php?f=54&t=188448&start=375#p1577365)

I can post permissions ls -all from the pihole folder

---

<div class="post-metadata">

### Author: ![DanSchaper](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/danschaper/32/91_2.png) [@DanSchaper](https://discourse.pi-hole.net/u/DanSchaper)
#### Post date: [December 8, 2019, 6:44pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/12 "2019-12-08T18:44:17Z")

</div>

I would suggest contacting the creator of the Gentoo 64 on RPi image. This is a problem with that specific image and works in all other supported distros.

---

<div class="post-metadata">

### Author: ![br6](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/br6/32/10979_2.png) [@br6](https://discourse.pi-hole.net/u/br6)
#### Post date: [December 8, 2019, 9:13pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/13 "2019-12-08T21:13:28Z")

</div>

I have enabled privilege mode for pihole in portainer and it is now accessible (web gui) not sure if that is safe practice though

---

<div class="post-metadata">

### Author: ![electricbrain2](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/electricbrain2/32/13830_2.png) [@electricbrain2](https://discourse.pi-hole.net/u/electricbrain2)
#### Post date: [April 3, 2020, 12:09pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/14 "2020-04-03T12:09:02Z")

</div>

Hi just a quick reply:  
Same issue with Fedora 30 (arm64 - RPi3B+) and I assume 31 with the last OS update (kernel 5.5).  
Identical error message.  
Your fix has worked here too (--priviledged) . Agree about this being somewhat unsafe.  
It may be possible to sort through the various --cap-add options to find the right one.  
I think Fedora is a "supported distro" so in theory its "just" a matter of the devs loading it up and updating to the latest to reproduce this issue.  
I also have the s6 issue where it loops forever (commonly caused by --dns 127.0.0.1 not being present) now.  
Pretty sure it was the last OS update that caused these issues (however I only update this machine every couple of months).  
BTW I gave up on the Gentoo Sakaki image and went over to the James A Chamber's Ubuntu arm64 image on the RPi4B units - very happy with it.

---

<div class="post-metadata">

### Author: ![electricbrain2](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/electricbrain2/32/13830_2.png) [@electricbrain2](https://discourse.pi-hole.net/u/electricbrain2)
#### Post date: [April 3, 2020, 12:28pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/15 "2020-04-03T12:28:15Z")

</div>

Replying to my own reply:  
I've have to abandon 4.3.2-1\_aarch64. It loops forever and won't startup lighttpd. Complete fail now with the latest update of Fedora 30.  
4.3.1-4\_aarch64 runs OK, but with the --priviledged noted above.  
Hope this helps someone as we were down here for while.

---

<div class="post-metadata">

### Author: ![thrubovc](https://discourse-cdn.pi-hole.net/user_avatar/discourse.pi-hole.net/thrubovc/32/15764_2.png) [@thrubovc](https://discourse.pi-hole.net/u/thrubovc)
#### Post date: [May 13, 2020, 7:15am UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/16 "2020-05-13T07:15:49Z")

</div>

for anyone interested in some details, [this](https://github.com/seccomp/libseccomp/pull/235) should be fixing the issue. by the way, none of the --add-cap capabilities help, not even --add-cap=ALL, you really have to stick with privileged mode for now.  
EDIT: I'm using pihole on manjaro aarch64

---

<div class="post-metadata">

### Author: ![nosolohacking](https://discourse-cdn.pi-hole.net/letter_avatar_proxy/v4/letter/n/e480ec/32.png) [@nosolohacking](https://discourse.pi-hole.net/u/nosolohacking)
#### Post date: [June 21, 2020, 5:31pm UTC](https://discourse.pi-hole.net/t/docker-pihole-gentoo-pi64/25771/17 "2020-06-21T17:31:01Z")

</div>

The issue is related to privileged mode, check this article to find how to fix it: [NoSoloHacking.info](https://www.nosolohacking.info/docker-pihole-error-server-c-970-couldnt-get-max-filedescriptors-operation-not-permitted/)
