Skip to content

Instantly share code, notes, and snippets.

@buildsville
Created January 23, 2019 09:53
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save buildsville/8866467fb38bd463c5796ac6fa63ba30 to your computer and use it in GitHub Desktop.
Save buildsville/8866467fb38bd463c5796ac6fa63ba30 to your computer and use it in GitHub Desktop.
diff of `sysctl -a` before and after installing docker to ubuntu
43c43
< fs.dentry-state = 40564 25626 45 0 0 0
---
> fs.dentry-state = 44527 29373 45 0 0 0
47,49c47,49
< fs.file-nr = 960 0 199438
< fs.inode-nr = 36858 492
< fs.inode-state = 36858 492 0 0 0 0 0
---
> fs.file-nr = 992 0 199438
> fs.inode-nr = 39071 676
> fs.inode-state = 39071 676 0 0 0 0 0
75c75
< fs.quota.syncs = 0
---
> fs.quota.syncs = 2
119c119
< kernel.ns_last_pid = 15928
---
> kernel.ns_last_pid = 19834
150c150
< kernel.pty.nr = 1
---
> kernel.pty.nr = 2
153c153
< kernel.random.entropy_avail = 336
---
> kernel.random.entropy_avail = 903
157c157
< kernel.random.uuid = 893e70f9-05b8-4c80-9456-6d2fa09d9f41
---
> kernel.random.uuid = 5a64d771-4fc6-4539-be0b-85eacc0cf7ac
206a207,212
> net.bridge.bridge-nf-call-arptables = 1
> net.bridge.bridge-nf-call-ip6tables = 1
> net.bridge.bridge-nf-call-iptables = 1
> net.bridge.bridge-nf-filter-pppoe-tagged = 0
> net.bridge.bridge-nf-filter-vlan-tagged = 0
> net.bridge.bridge-nf-pass-vlan-input-dev = 0
244c250
< net.ipv4.conf.all.accept_redirects = 1
---
> net.ipv4.conf.all.accept_redirects = 0
257c263
< net.ipv4.conf.all.forwarding = 0
---
> net.ipv4.conf.all.forwarding = 1
288c294
< net.ipv4.conf.default.forwarding = 0
---
> net.ipv4.conf.default.forwarding = 1
304a311,341
> net.ipv4.conf.docker0.accept_local = 0
> net.ipv4.conf.docker0.accept_redirects = 1
> net.ipv4.conf.docker0.accept_source_route = 1
> net.ipv4.conf.docker0.arp_accept = 0
> net.ipv4.conf.docker0.arp_announce = 0
> net.ipv4.conf.docker0.arp_filter = 0
> net.ipv4.conf.docker0.arp_ignore = 0
> net.ipv4.conf.docker0.arp_notify = 0
> net.ipv4.conf.docker0.bootp_relay = 0
> net.ipv4.conf.docker0.disable_policy = 0
> net.ipv4.conf.docker0.disable_xfrm = 0
> net.ipv4.conf.docker0.drop_gratuitous_arp = 0
> net.ipv4.conf.docker0.drop_unicast_in_l2_multicast = 0
> net.ipv4.conf.docker0.force_igmp_version = 0
> net.ipv4.conf.docker0.forwarding = 1
> net.ipv4.conf.docker0.igmpv2_unsolicited_report_interval = 10000
> net.ipv4.conf.docker0.igmpv3_unsolicited_report_interval = 1000
> net.ipv4.conf.docker0.ignore_routes_with_linkdown = 0
> net.ipv4.conf.docker0.log_martians = 0
> net.ipv4.conf.docker0.mc_forwarding = 0
> net.ipv4.conf.docker0.medium_id = 0
> net.ipv4.conf.docker0.promote_secondaries = 0
> net.ipv4.conf.docker0.proxy_arp = 0
> net.ipv4.conf.docker0.proxy_arp_pvlan = 0
> net.ipv4.conf.docker0.route_localnet = 0
> net.ipv4.conf.docker0.rp_filter = 1
> net.ipv4.conf.docker0.secure_redirects = 1
> net.ipv4.conf.docker0.send_redirects = 1
> net.ipv4.conf.docker0.shared_media = 1
> net.ipv4.conf.docker0.src_valid_mark = 0
> net.ipv4.conf.docker0.tag = 0
319c356
< net.ipv4.conf.eth0.forwarding = 0
---
> net.ipv4.conf.eth0.forwarding = 1
350c387
< net.ipv4.conf.eth1.forwarding = 0
---
> net.ipv4.conf.eth1.forwarding = 1
381c418
< net.ipv4.conf.lo.forwarding = 0
---
> net.ipv4.conf.lo.forwarding = 1
419c456
< net.ipv4.ip_forward = 0
---
> net.ipv4.ip_forward = 1
448a486,499
> net.ipv4.neigh.docker0.anycast_delay = 100
> net.ipv4.neigh.docker0.app_solicit = 0
> net.ipv4.neigh.docker0.base_reachable_time_ms = 30000
> net.ipv4.neigh.docker0.delay_first_probe_time = 5
> net.ipv4.neigh.docker0.gc_stale_time = 60
> net.ipv4.neigh.docker0.locktime = 100
> net.ipv4.neigh.docker0.mcast_resolicit = 0
> net.ipv4.neigh.docker0.mcast_solicit = 3
> net.ipv4.neigh.docker0.proxy_delay = 80
> net.ipv4.neigh.docker0.proxy_qlen = 64
> net.ipv4.neigh.docker0.retrans_time_ms = 1000
> net.ipv4.neigh.docker0.ucast_solicit = 3
> net.ipv4.neigh.docker0.unres_qlen = 101
> net.ipv4.neigh.docker0.unres_qlen_bytes = 212992
678a730,777
> net.ipv6.conf.docker0.accept_dad = 1
> net.ipv6.conf.docker0.accept_ra = 1
> net.ipv6.conf.docker0.accept_ra_defrtr = 1
> net.ipv6.conf.docker0.accept_ra_from_local = 0
> net.ipv6.conf.docker0.accept_ra_min_hop_limit = 1
> net.ipv6.conf.docker0.accept_ra_mtu = 1
> net.ipv6.conf.docker0.accept_ra_pinfo = 1
> net.ipv6.conf.docker0.accept_ra_rt_info_max_plen = 0
> net.ipv6.conf.docker0.accept_ra_rt_info_min_plen = 0
> net.ipv6.conf.docker0.accept_ra_rtr_pref = 1
> net.ipv6.conf.docker0.accept_redirects = 1
> net.ipv6.conf.docker0.accept_source_route = 0
> net.ipv6.conf.docker0.addr_gen_mode = 0
> net.ipv6.conf.docker0.autoconf = 1
> net.ipv6.conf.docker0.dad_transmits = 1
> net.ipv6.conf.docker0.disable_ipv6 = 0
> net.ipv6.conf.docker0.disable_policy = 0
> net.ipv6.conf.docker0.drop_unicast_in_l2_multicast = 0
> net.ipv6.conf.docker0.drop_unsolicited_na = 0
> net.ipv6.conf.docker0.enhanced_dad = 1
> net.ipv6.conf.docker0.force_mld_version = 0
> net.ipv6.conf.docker0.force_tllao = 0
> net.ipv6.conf.docker0.forwarding = 0
> net.ipv6.conf.docker0.hop_limit = 64
> net.ipv6.conf.docker0.ignore_routes_with_linkdown = 0
> net.ipv6.conf.docker0.keep_addr_on_down = 0
> net.ipv6.conf.docker0.max_addresses = 16
> net.ipv6.conf.docker0.max_desync_factor = 600
> net.ipv6.conf.docker0.mc_forwarding = 0
> net.ipv6.conf.docker0.mldv1_unsolicited_report_interval = 10000
> net.ipv6.conf.docker0.mldv2_unsolicited_report_interval = 1000
> net.ipv6.conf.docker0.mtu = 1500
> net.ipv6.conf.docker0.ndisc_notify = 0
> net.ipv6.conf.docker0.ndisc_tclass = 0
> net.ipv6.conf.docker0.proxy_ndp = 0
> net.ipv6.conf.docker0.regen_max_retry = 3
> net.ipv6.conf.docker0.router_probe_interval = 60
> net.ipv6.conf.docker0.router_solicitation_delay = 1
> net.ipv6.conf.docker0.router_solicitation_interval = 4
> net.ipv6.conf.docker0.router_solicitation_max_interval = 3600
> net.ipv6.conf.docker0.router_solicitations = -1
> net.ipv6.conf.docker0.seg6_enabled = 0
> net.ipv6.conf.docker0.seg6_require_hmac = 0
> net.ipv6.conf.docker0.suppress_frag_ndisc = 1
> net.ipv6.conf.docker0.temp_prefered_lft = 86400
> net.ipv6.conf.docker0.temp_valid_lft = 604800
> net.ipv6.conf.docker0.use_oif_addrs_only = 0
> net.ipv6.conf.docker0.use_tempaddr = 2
858a958,971
> net.ipv6.neigh.docker0.anycast_delay = 100
> net.ipv6.neigh.docker0.app_solicit = 0
> net.ipv6.neigh.docker0.base_reachable_time_ms = 30000
> net.ipv6.neigh.docker0.delay_first_probe_time = 5
> net.ipv6.neigh.docker0.gc_stale_time = 60
> net.ipv6.neigh.docker0.locktime = 0
> net.ipv6.neigh.docker0.mcast_resolicit = 0
> net.ipv6.neigh.docker0.mcast_solicit = 3
> net.ipv6.neigh.docker0.proxy_delay = 80
> net.ipv6.neigh.docker0.proxy_qlen = 64
> net.ipv6.neigh.docker0.retrans_time_ms = 1000
> net.ipv6.neigh.docker0.ucast_solicit = 3
> net.ipv6.neigh.docker0.unres_qlen = 101
> net.ipv6.neigh.docker0.unres_qlen_bytes = 212992
911a1025,1068
> net.netfilter.nf_conntrack_acct = 0
> net.netfilter.nf_conntrack_buckets = 16384
> net.netfilter.nf_conntrack_checksum = 1
> net.netfilter.nf_conntrack_count = 2
> net.netfilter.nf_conntrack_dccp_loose = 1
> net.netfilter.nf_conntrack_dccp_timeout_closereq = 64
> net.netfilter.nf_conntrack_dccp_timeout_closing = 64
> net.netfilter.nf_conntrack_dccp_timeout_open = 43200
> net.netfilter.nf_conntrack_dccp_timeout_partopen = 480
> net.netfilter.nf_conntrack_dccp_timeout_request = 240
> net.netfilter.nf_conntrack_dccp_timeout_respond = 480
> net.netfilter.nf_conntrack_dccp_timeout_timewait = 240
> net.netfilter.nf_conntrack_events = 1
> net.netfilter.nf_conntrack_expect_max = 256
> net.netfilter.nf_conntrack_generic_timeout = 600
> net.netfilter.nf_conntrack_helper = 0
> net.netfilter.nf_conntrack_icmp_timeout = 30
> net.netfilter.nf_conntrack_log_invalid = 0
> net.netfilter.nf_conntrack_max = 65536
> net.netfilter.nf_conntrack_sctp_timeout_closed = 10
> net.netfilter.nf_conntrack_sctp_timeout_cookie_echoed = 3
> net.netfilter.nf_conntrack_sctp_timeout_cookie_wait = 3
> net.netfilter.nf_conntrack_sctp_timeout_established = 432000
> net.netfilter.nf_conntrack_sctp_timeout_heartbeat_acked = 210
> net.netfilter.nf_conntrack_sctp_timeout_heartbeat_sent = 30
> net.netfilter.nf_conntrack_sctp_timeout_shutdown_ack_sent = 3
> net.netfilter.nf_conntrack_sctp_timeout_shutdown_recd = 0
> net.netfilter.nf_conntrack_sctp_timeout_shutdown_sent = 0
> net.netfilter.nf_conntrack_tcp_be_liberal = 0
> net.netfilter.nf_conntrack_tcp_loose = 1
> net.netfilter.nf_conntrack_tcp_max_retrans = 3
> net.netfilter.nf_conntrack_tcp_timeout_close = 10
> net.netfilter.nf_conntrack_tcp_timeout_close_wait = 60
> net.netfilter.nf_conntrack_tcp_timeout_established = 432000
> net.netfilter.nf_conntrack_tcp_timeout_fin_wait = 120
> net.netfilter.nf_conntrack_tcp_timeout_last_ack = 30
> net.netfilter.nf_conntrack_tcp_timeout_max_retrans = 300
> net.netfilter.nf_conntrack_tcp_timeout_syn_recv = 60
> net.netfilter.nf_conntrack_tcp_timeout_syn_sent = 120
> net.netfilter.nf_conntrack_tcp_timeout_time_wait = 120
> net.netfilter.nf_conntrack_tcp_timeout_unacknowledged = 300
> net.netfilter.nf_conntrack_timestamp = 0
> net.netfilter.nf_conntrack_udp_timeout = 30
> net.netfilter.nf_conntrack_udp_timeout_stream = 180
925a1083
> net.nf_conntrack_max = 65536
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment