abundant-magician-17307
09/24/2025, 9:34 AMtall-airline-16756
09/24/2025, 9:35 AMtall-airline-16756
09/24/2025, 9:35 AM--no-sandbox and --cap-add SYS_ADMIN can be frustrating. This often happens due to conflicting security settings or missing system call permissions. Let’s walk through some steps together to help you resolve this:
1. Try to avoid using `--no-sandbox`: Instead, it’s better to enable Chrome’s sandboxing by setting enable_chrome_sandbox: true in your Egress configuration. This helps keep things more secure and stable.
2. Use the right seccomp profile: Chrome needs specific system calls like clone and unshare. Make sure to use the provided seccomp profile to allow these calls:
docker run --rm \
-e EGRESS_CONFIG_FILE=/out/config.yaml \
-v ~/egress-test:/out \
--security-opt seccomp=chrome-sandboxing-seccomp-profile.json \
livekit/egress
3. Check Docker capabilities: When you’re not using --no-sandbox, remember to include --cap-add=SYS_ADMIN to ensure proper permissions.
4. Enable debug logging: Adding log_level: debug to your Egress configuration can give you more detailed logs to help pinpoint any issues.
5. Verify system-level settings: It’s also a good idea to check kernel parameters like vm.max_map_count and make sure they’re set correctly (for example, 524288).
Just a quick note: disabling the sandbox with --no-sandbox isn’t recommended because it can reduce security and cause instability. If you’re still running into trouble, please make sure you’re using Egress v1.7.6 or later and that your configuration matches the updated security model. We’re here to help you every step of the way!
Sources: Self-hosting the Egress Service | LiveKit Docs | chrome-sandboxing-seccomp-profile.json | steam-headless/overlay/etc/cont-init.d/11-setup_sysctl_values.sh | Getting Help | livekit/livekit_composite | DeepWiki