egress@1b5a010ed964:/$ chrome --version Trace/brea...
# ask-ai
a
egress@1b5a010ed964:/$ chrome --version Trace/breakpoint trap (core dumped) egress@1b5a010ed964:/$ chrome --headless=new --disable-gpu --no-sandbox --dump-dom https://www.baidu.com2 Trace/breakpoint trap (core dumped) 执行测试命令,打印下面内容,是什么问题
t
Thanks for reaching out, 徐旭. I'm an AI assistant and I'm here to help. Give me a moment while I research this topic.
Hey there! The "Trace/breakpoint trap (core dumped)" error you’re seeing when running Chrome commands in LiveKit egress usually happens because the
--cap-add=SYS_ADMIN
flag is missing from your Docker run command. Since egress version v1.7.6, Chrome sandboxing is turned on by default to keep things more secure, and this flag is necessary for that. To fix this, just make sure your Docker run command includes the
--cap-add SYS_ADMIN
flag like this:
Copy code
docker run --rm \
  --cap-add SYS_ADMIN \
  -e EGRESS_CONFIG_FILE=/out/config.yaml \
  -v ~/livekit-egress:/out \
  livekit/egress
If you’re working with a custom seccomp profile to enable Chrome sandboxing, don’t forget to add the
--security-opt seccomp=chrome-sandboxing-seccomp-profile.json
option. This profile helps Chrome’s sandbox environment by allowing the necessary system calls. If you have any questions or need a hand with this, just let me know—I’m here to help! Sources: magefile.go | Self-hosting the Egress Service | LiveKit Docs
a
加了--cap-add SYS_ADMIN,执行还是上面报错,有其他原因吗
t
If the "Trace/breakpoint trap (core dumped)" error still shows up after adding
--cap-add SYS_ADMIN
, don’t worry—let’s explore a few more things together: 1. Seccomp Profile: Make sure to include the
--security-opt seccomp=chrome-sandboxing-seccomp-profile.json
option in your Docker run command. This profile is essential for Chrome sandboxing to work smoothly. 2. System Resources: It’s a good idea to check that your system has at least 4 CPUs and 4 GB of memory. Sometimes, not having enough resources can cause Chrome to struggle during startup. 3. Configuration: Take a look at whether
enable_chrome_sandbox
is set to
true
in your configuration. If it is, the necessary Docker security setup (including the seccomp profile) needs to be fully in place. Keeping an eye on your system’s CPU and memory usage while starting egress can really help spot any resource issues. Please feel free to reach out if you’d like me to walk you through any of these steps or if you have more questions—I’m here to help! Sources: test/edge.go | Self-hosting the Egress Service | LiveKit Docs
a
加了--cap-add SYS_ADMIN,禁用了沙盒,cpu 内存充足,还是报错怎么排查
加了--cap-add SYS_ADMIN,禁用了沙盒,cpu 内存充足,还是报错怎么排查