Skip to content

Template Creation Times Out When the Sandbox CIDR Overlaps the LAN

Symptom

Template creation fails during the CREATING_TEMPLATE phase:

bash
cubemastercli run fail: template tpl-xx creation failed: context deadline exceeded

Or cube-bench reports errors during a benchmark run:

bash
create HTTP 500: {"code":500,"message":"CubeMaster returned error code 130595: context deadline exceeded"}

Environment

  • Cube Sandbox version: e29453
  • Deployment mode: bare-metal or local physical-machine deployment
  • Host OS / kernel: Ubuntu 22.04 / Linux 6.6
  • Related components: Cubelet, persistent TAP devices

Root Cause

On a bare-metal or local physical-machine deployment, Cube creates many persistent TAP devices named like z192.168.0.x or z192.168.1.x.

The default configuration is in Cubelet/config/config.toml. By default, Cube creates 500 TAP devices from the 192.168.0.0/18 CIDR:

toml
[plugins]
  [plugins."io.cubelet.internal.v1.network"]
    object_dir = "/usr/local/services/cubetoolbox/cube-vs/network"
    eth_name = "eth0"
    tap_init_num = 500
    cidr = "192.168.0.0/18"

Cube's default sandbox CIDR is 192.168.0.0/18. If the host LAN also uses a related range, such as 192.168.1.x, sandbox addresses can overlap with the real LAN, causing routing and port probing failures.

How to diagnose

  1. Check the Cubelet log at /data/log/Cubelet/Cubelet-req.log for PortBindingFailed errors.
  2. Verify the host LAN IP range: ip addr show — look for the inet line on your primary NIC.
  3. Compare with the sandbox CIDR in Cubelet/config/config.toml.

Fix

Change the sandbox CIDR to a non-overlapping range. For example, if your LAN uses 192.168.1.0/24, change the Cubelet config to use 10.0.0.0/18:

toml
[plugins]
  [plugins."io.cubelet.internal.v1.network"]
    object_dir = "/usr/local/services/cubetoolbox/cube-vs/network"
    eth_name = "eth0"
    tap_init_num = 500
    cidr = "10.0.0.0/18"

Then restart the Cubelet and network-agent services:

bash
sudo systemctl restart cube-sandbox-cubelet.service
sudo systemctl restart cube-sandbox-network-agent.service

Re-run the template creation or benchmark to verify the fix.