Non-root Chromium sandbox startup fails: credentials.cc Permission denied
brancoyuri
HOBBYOP

a day ago

Hello Railway team/community,

On Hobby, a minimal non-root Chromium startup probe fails before opening any external website. Docker builds succeed and all 22 application tests pass, but Chromium exits immediately:

FATAL:sandbox/linux/services/credentials.cc:137] Check failed: . : Permission denied (13)

Setup: node:24-bookworm-slim; Debian apt packages chromium, chromium-sandbox, ca-certificates, fonts-liberation; USER node (non-root). Region us-west2, 1 vCPU/1 GB, restart NEVER, no volume or public endpoint. No --no-sandbox, privileged mode or added capabilities.

Reproduction command:

chromium --headless --disable-gpu --disable-background-networking --no-first-run --dump-dom about:blank

We use a 30-second timeout. Two deployments reproduce the same immediate failure. Installing the official chromium-sandbox package and rebuilding did not fix it. No customer account has been connected, and the probe is stopped without automatic restarts.

Is there a supported configuration to run non-root Chromium with its sandbox enabled on Railway? If so, what settings or image are required? If this is a runtime restriction, could the Railway team confirm it? We want to keep browser security enabled and avoid repeated deployments without a viable configuration.

Thank you.

$10 Bounty

1 Replies

Railway
BOT

a day ago

This thread has been opened as a bounty so the community can help solve it.

Status changed to Open Railway • 1 day ago


I'd try using Railway Sandboxes instead.


Welcome!

Sign in to your Railway account to join the conversation.

Loading...