Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Offical apps | Community apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Discuss
  3. Can a packaged app run headless Chromium with its sandbox on?

Can a packaged app run headless Chromium with its sandbox on?

Scheduled Pinned Locked Moved Discuss
chromechromiumsandboxprivileges
3 Posts 2 Posters 82 Views 2 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • L
    L
    LoudLemur
    wrote last edited by
    #1

    We are preparing a community package for Crawl4AI, which fetches web pages with a real headless Chromium and returns them as clean text for language models.

    Chromium protects the host by running each page's renderer inside its own sandbox. On Linux that sandbox needs either unprivileged user namespaces or the setuid chrome-sandbox helper. When neither is available, the only way to start Chromium is --no-sandbox, and upstream's image ships exactly that flag, with a comment saying a renderer exploit can then reach the container.

    Upstream suggests two ways to turn the sandbox back on: allow unprivileged user namespaces on the host, or run the container with a custom seccomp profile. As far as we can tell, a package can do neither: the manifest has no seccomp setting, and host sysctls are outside the package.

    A crawler is software that deliberately opens untrusted pages, so we would rather not ship it unsandboxed without asking first. Three questions:

    1. Inside an app container on Cloudron 9.x, are unprivileged user namespaces (unshare --user) allowed, or are they blocked by Docker's default seccomp profile or AppArmor on the host?

    2. Is no-new-privileges set on app containers? If not, would a setuid chrome-sandbox helper be an acceptable route, or does the platform discourage setuid binaries in packages?

    3. How do existing apps that bundle Chromium handle this? Do they all run --no-sandbox, and is that the accepted practice here?

    If the answer is that --no-sandbox is the only option, we plan to say so plainly in the app description, keep the API token mandatory, and rely on the container's own isolation. If there is a better route, we would like to use it.

    We can test whatever is suggested on our staging Cloudron and report back here.

    1 Reply Last reply
    2
    • jamesJ
      jamesJ
      james
      Staff
      wrote last edited by
      #2

      Hello @loudlemur
      Not sure if helpful, but @brutalbirdie did package https://git.cloudron.io/elias/browserless-cloudron-app/ which uses playwright chrome, msedge, chromium, firefox, webkit browsers.
      If I remember correctly browserless runs all browsers inside docker with --no-sandbox

      L 1 Reply Last reply
      2
      • jamesJ james

        Hello @loudlemur
        Not sure if helpful, but @brutalbirdie did package https://git.cloudron.io/elias/browserless-cloudron-app/ which uses playwright chrome, msedge, chromium, firefox, webkit browsers.
        If I remember correctly browserless runs all browsers inside docker with --no-sandbox

        L
        L
        LoudLemur
        wrote last edited by
        #3

        @james said:

        Not sure if helpful,

        Brilliant Brutal Birdie and thanks, that helps a lot!

        1 Reply Last reply
        1

        Hello! It looks like you're interested in this conversation, but you don't have an account yet.

        Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

        With your input, this post could be even better 💗

        Register Login
        Reply
        • Reply as topic
        Log in to reply
        • Oldest to Newest
        • Newest to Oldest
        • Most Votes


        • Login

        • Don't have an account? Register

        • Login or register to search.
        • First post
          Last post
        0
        • Categories
        • Recent
        • Tags
        • Popular
        • Bookmarks
        • Search