Failed to move to new namespace: PID namespaces supported, Network namespace supported, but failed to set up sandbox
29.5K reputation · 11 Aug 2025, 15:55 UTC
Goal: Run Karma tests in a CI environment using the ChromeHeadless launcher without encountering the sandbox initialization failure.
Constraint: The CI runners (e.g., Docker containers or Kubernetes pods) typically lack the CAP_SYS_ADMIN privilege required for Chrome’s namespace sandbox, causing the error “Failed to move to new namespace: PID namespaces supported, Network namespace supported, but failed to set up sandbox”.
Uncertainty: The Karma documentation does not explicitly state whether adding a custom launcher with flags such as --no-sandbox or --disable-setuid-sandbox should be the default recommendation for CI, leaving teams to discover the workaround themselves.
Should Karma’s default ChromeHeadless launcher include the --no-sandbox flag for CI environments?
What are the trade‑offs of using --no-sandbox versus alternative launchers like FirefoxHeadless?
How can teams assess whether disabling the sandbox introduces unacceptable security risks in their specific CI pipeline?