# Error logged after first install

**URL:** <https://forum.collaboraonline.com/t/error-logged-after-first-install/3845>\
**Category:** Installation & Configuration\
**Created:** [July 6, 2025, 4:45pm UTC](https://forum.collaboraonline.com/t/error-logged-after-first-install/3845 "2025-07-06T16:45:36Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![darshan](https://dub1.discourse-cdn.com/flex013/user_avatar/forum.collaboraonline.com/darshan/32/2230_2.png) [@darshan](https://forum.collaboraonline.com/u/darshan)\
**Post date:** [July 7, 2025, 4:15pm UTC](https://forum.collaboraonline.com/t/error-logged-after-first-install/3845/2 "2025-07-07T16:15:45Z")

</div>

Hii @Theking2 welcome to the community 🙂

The error you’re encountering is related to user namespaces and mount namespace isolation not being supported or permitted in your Docker setup. These are needed by default in Collabora Online for process isolation and security (`mount_jail_tree`).

#### Option 1

Disable `mount_jail_tree` in `coolwsd.xml`

If you’re in a Docker environment and you **trust the workload** (e.g. not multi-tenant or untrusted docs), the simplest solution is to disable the jail system:

1. Locate your `coolwsd.xml` (mounted or copied into the container, typically in `/etc/coolwsd/coolwsd.xml`)
2. Set:

```auto
<mount_jail_tree>false</mount_jail_tree>

```

1. Restart the container.

**Security Note:** This disables mount namespace isolation, which reduces sandboxing protections. Only do this in trusted, internal setups.

#### Option 2: Use Docker with Required Capabilities

If you want to keep the jail feature, run your container with extra privileges:

```auto
docker run --cap-add=SYS_ADMIN --security-opt seccomp=unconfined ...

```

Or if you’re using `docker-compose`:

```auto
services:
  collabora:
    image: collabora/code
    cap_add:
      - SYS_ADMIN
    security_opt:
      - seccomp=unconfined
    ...

```

This will allow `unshare()` to succeed and let Collabora isolate the environment properly.

* * *

### 3: Use Podman (Rootless Compatible)

If you prefer to keep your deployment fully rootless and secure, [Podman](https://podman.io/) supports user namespaces better than Docker by default.

> **[FAQ — SDK https://sdk.collaboraonline.com/ documentation](https://sdk.collaboraonline.com/docs/faq.html)**

Thanks  
Darshan

---

_[View the full topic](https://forum.collaboraonline.com/t/error-logged-after-first-install/3845)._
