# Unable to attach or mount volumes: unmounted volumes=\[dockersocket-host\]

**URL:** <https://discourse.jupyter.org/t/unable-to-attach-or-mount-volumes-unmounted-volumes-dockersocket-host/14950>\
**Category:** BinderHub\
**Created:** [July 15, 2022, 11:32pm UTC](https://discourse.jupyter.org/t/unable-to-attach-or-mount-volumes-unmounted-volumes-dockersocket-host/14950 "2022-07-15T23:32:36Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![unknownsolo](https://avatars.discourse-cdn.com/v4/letter/u/b9bd4f/32.png) [@unknownsolo](https://discourse.jupyter.org/u/unknownsolo)\
**Post date:** [July 15, 2022, 11:32pm UTC](https://discourse.jupyter.org/t/unable-to-attach-or-mount-volumes-unmounted-volumes-dockersocket-host/14950/1 "2022-07-15T23:32:36Z")

</div>

Hello, I was able to successfully deploy BinderHub and JypyterHub on OpenShift 4.9. I can visit BinderHub’s page, but if I launch anything, the containers in OpenShift, and the binderhub-image-cleaner pods have the following errors:

```auto
MountVolume.SetUp failed for volume "dockersocket-dind" : hostPath type check failed: /var/run/dind/docker.sock is not a socket file

Unable to attach or mount volumes: unmounted volumes=[dockersocket-host], unattached volumes=[kube-api-access-ft6dp dockerlib-dind dockersocket-dind dockerlib-host dockersocket-host]: timed out waiting for the condition

Unable to attach or mount volumes: unmounted volumes=[dockersocket-host], unattached volumes=[dockerlib-host dockersocket-host kube-api-access-ft6dp dockerlib-dind dockersocket-dind]: timed out waiting for the condition

MountVolume.SetUp failed for volume "dockersocket-host" : hostPath type check failed: /var/run/docker.sock is not a socket file

Unable to attach or mount volumes: unmounted volumes=[dockersocket-host], unattached volumes=[dockersocket-dind dockerlib-host dockersocket-host kube-api-access-ft6dp dockerlib-dind]: timed out waiting for the condition

```

any help is greatly appreciated!

---

<div class="post-metadata">

**Author:** ![manics](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/manics/32/85_2.png) [@manics](https://discourse.jupyter.org/u/manics)\
**Post date:** [July 16, 2022, 4:37pm UTC](https://discourse.jupyter.org/t/unable-to-attach-or-mount-volumes-unmounted-volumes-dockersocket-host/14950/2 "2022-07-16T16:37:04Z")

</div>

OpenShift imposes stronger security rules than a standard Kubernetes cluster. Maybe it prevents you from connecting to the Docker daemon?

---

<div class="post-metadata">

**Author:** ![unknownsolo](https://avatars.discourse-cdn.com/v4/letter/u/b9bd4f/32.png) [@unknownsolo](https://discourse.jupyter.org/u/unknownsolo)\
**Post date:** [July 17, 2022, 2:36am UTC](https://discourse.jupyter.org/t/unable-to-attach-or-mount-volumes-unmounted-volumes-dockersocket-host/14950/3 "2022-07-17T02:36:16Z")

</div>

Not sure where to go from here. I was having issues deploying at first until I gave this project privileged access. I am now able to deploy and browse to BinderHub’s URL and JupyterHub’s URL, just not able run anything due to the error above!

---

<div class="post-metadata">

**Author:** ![unknownsolo](https://avatars.discourse-cdn.com/v4/letter/u/b9bd4f/32.png) [@unknownsolo](https://discourse.jupyter.org/u/unknownsolo)\
**Post date:** [July 18, 2022, 4:16am UTC](https://discourse.jupyter.org/t/unable-to-attach-or-mount-volumes-unmounted-volumes-dockersocket-host/14950/4 "2022-07-18T04:16:18Z")

</div>

Looks like OpenShift 4 no longer has a docker daemon ([OpenShift 4: Image Builds](https://cloud.redhat.com/blog/openshift-4-image-builds)). Is there anything I can do to make this work on OpenShift 4?

---

<div class="post-metadata">

**Author:** ![manics](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/manics/32/85_2.png) [@manics](https://discourse.jupyter.org/u/manics)\
**Post date:** [July 22, 2022, 8:49pm UTC](https://discourse.jupyter.org/t/unable-to-attach-or-mount-volumes-unmounted-volumes-dockersocket-host/14950/5 "2022-07-22T20:49:05Z")

</div>

Short answer: no not easily.

Longer answer:  
There’s some development work in BinderHub to decouple the building of images from the launching of them. For example, you can run BinderHub without Kubernetes:

> **[binderhub/testing/local-binder-local-hub at master · jupyterhub/binderhub](https://github.com/jupyterhub/binderhub/tree/master/testing/local-binder-local-hub)**
>
> master/testing/local-binder-local-hub

repo2docker has a pluggable container engine:

> <https://github.com/jupyterhub/repo2docker/blob/e40242c067105c70ae91ec28806df7e823dc934b/repo2docker/engine.py>

For example you can use rootless daemonless Podman instead of Docker:

> **[GitHub - manics/repo2podman: A repo2docker plugin that lets you use Podman...](https://github.com/manics/repo2podman)**
>
> A repo2docker plugin that lets you use Podman instead of Docker - GitHub - manics/repo2podman: A repo2docker plugin that lets you use Podman instead of Docker

You could write a new repo2docker engine that uses a build system supported by OpenShift?

---

<div class="post-metadata">

**Author:** ![manics](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/manics/32/85_2.png) [@manics](https://discourse.jupyter.org/u/manics)\
**Post date:** [July 25, 2022, 9:06pm UTC](https://discourse.jupyter.org/t/unable-to-attach-or-mount-volumes-unmounted-volumes-dockersocket-host/14950/6 "2022-07-25T21:06:33Z")

</div>

I’ve opened an issue on the BinderHub repo:

> <https://github.com/jupyterhub/binderhub/issues/1513>
>
> \### Proposed change
> Docker has been removed from several K8s distributions. In …addition there have been requests to run BinderHub on more restricted K8s distributions such as OpenShift https://discourse.jupyter.org/t/unable-to-attach-or-mount-volumes-unmounted-volumes-dockersocket-host/14950
> 
> \### Alternative options
> Do nothing, though in future we may need to modify the deployment instructions to ensure Docker is available on the K8s hosts.
> 
> \### Who would use this feature?
> Someone who wants to run BinderHub on K8s without Docker.
> Someone who wants to run BinderHub with reduced privileges.
> 
> \### (Optional): Suggest a solution
> There are several non-Docker container builders available, include:
> \- podman https://podman.io/
> \- buildah (used by Podman for building images) https://buildah.io/
> \- img https://github.com/genuinetools/img
> 
> repo2podman already works https://github.com/manics/repo2podman and it shouldn't be too hard to swap-in one of the other builders.
> 
> In theory it should be possible to run these without full privileges, with limited added capabilities, e.g.
> \- https://www.redhat.com/sysadmin/podman-inside-container
> \- https://blog.jessfraz.com/post/building-container-images-securely-on-kubernetes/
> 
> So far I've managed to get a proof-of-concept podman builder running using full privileges, supported by https://github.com/jupyterhub/binderhub/pull/1512 on AWS EKS:
> \`\`\`yaml
> image:
> name: docker.io/manics/binderhub-dev
> tag: 2022-07-25-20-00
> 
> registry:
> url: docker.io
> username: \<username\>
> password: \<password\>
> 
> service:
> type: ClusterIP
> 
> config:
> BinderHub:
> base\_url: /binder/
> build\_capabilities:
> - privileged
> build\_docker\_host: ""
> build\_image: "ghcr.io/manics/repo2podman:main"
> hub\_url: /jupyter/
> hub\_url\_local: http://hub:8081/jupyter/
> image\_prefix: \<username\>/binder-
> auth\_enabled: false
> use\_registry: true
> Application:
> log\_level: DEBUG
> 
> extraConfig:
> 0-repo2podman: |
> from binderhub.build import Build
> class Repo2PodmanBuild(Build):
> def get\_r2d\_cmd\_options(self):
> return \["--engine=podman"\] + super().get\_r2d\_cmd\_options()
> c.BinderHub.build\_class = Repo2PodmanBuild
> 
> jupyterhub:
> hub:
> baseUrl: /jupyter
> networkPolicy:
> enabled: false
> proxy:
> service:
> type: ClusterIP
> chp:
> networkPolicy:
> enabled: false
> scheduling:
> userScheduler:
> enabled: false
> ingress:
> enabled: true
> pathSuffix: "\*"
> pathType: ImplementationSpecific
> # https://kubernetes-sigs.github.io/aws-load-balancer-controller/v2.4/guide/ingress/annotations/
> annotations:
> kubernetes.io/ingress.class: alb
> alb.ingress.kubernetes.io/group.name: binder
> alb.ingress.kubernetes.io/target-type: ip
> alb.ingress.kubernetes.io/scheme: internet-facing
> 
> 
> ingress:
> enabled: true
> pathSuffix: "binder/\*"
> pathType: ImplementationSpecific
> # https://kubernetes-sigs.github.io/aws-load-balancer-controller/v2.4/guide/ingress/annotations/
> annotations:
> kubernetes.io/ingress.class: alb
> alb.ingress.kubernetes.io/group.name: binder
> alb.ingress.kubernetes.io/target-type: ip
> alb.ingress.kubernetes.io/scheme: internet-facing
> \`\`\`
> 
> There are several limitations:
> \- Still requires a privileged container
> \- No caching since it's not connecting to an external Docker daemon (probably need a host volume mount for the container store)
> \- Docker registry is playing up, not sure if that's related or something else

---

<div class="post-metadata">

**Author:** ![unknownsolo](https://avatars.discourse-cdn.com/v4/letter/u/b9bd4f/32.png) [@unknownsolo](https://discourse.jupyter.org/u/unknownsolo)\
**Post date:** [August 5, 2022, 12:32am UTC](https://discourse.jupyter.org/t/unable-to-attach-or-mount-volumes-unmounted-volumes-dockersocket-host/14950/7 "2022-08-05T00:32:34Z")

</div>

Thank you! I will keep monitoring this. In the meantime, we need something and have found deepnote to do what we need. That said, once BinderHub has full support for OpenShift, it will be very easy for us to switch back.

Let me know if there is anything I can help test on OpenShift.

---

<div class="post-metadata">

**Author:** ![Derrik](https://yyz1.discourse-cdn.com/flex031/user_avatar/discourse.jupyter.org/derrik/32/9581_2.png) [@Derrik](https://discourse.jupyter.org/u/Derrik)\
**Post date:** [April 7, 2023, 1:09am UTC](https://discourse.jupyter.org/t/unable-to-attach-or-mount-volumes-unmounted-volumes-dockersocket-host/14950/9 "2023-04-07T01:09:35Z")

</div>

This looks to the case on EKS 1.25 as well. I noticed that the newer binderhub dev releases 1.0.0 don’t have this issue but I can’t seem to get the rest of the configure working on those versions.
