# Can't start crowdsec in rootless podman

**URL:** <https://discourse.crowdsec.net/t/cant-start-crowdsec-in-rootless-podman/2788>\
**Category:** crowdsec\
**Created:** [March 13, 2026, 10:41pm UTC](https://discourse.crowdsec.net/t/cant-start-crowdsec-in-rootless-podman/2788 "2026-03-13T22:41:53Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Damncold](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/damncold/32/1391_2.png) [@Damncold](https://discourse.crowdsec.net/u/Damncold)\
**Post date:** [March 13, 2026, 10:41pm UTC](https://discourse.crowdsec.net/t/cant-start-crowdsec-in-rootless-podman/2788/1 "2026-03-13T22:41:53Z")

</div>

Hi,

im trying to get crowdsec running in rootless podman.

But i get the following error:

```plaintext
crowdsec-pangolin[243452]: ln: /var/lib/crowdsec/data/GeoLite2-ASN.mmdb: Permission denied

```

I think the permissions are correct:

```bash
marco@DMZ:~/docker/appdata/pangolin/crowdsec/data$ l
insgesamt 9,2M
drwxrwxr-x 2 marco marco 4,0K 13. Mär 23:24 ./
drwxrwx--- 7 marco marco 4,0K 13. Mär 23:04 ../
-rw-r--r-- 1 marco marco 9,2M 4. Mär 23:24 GeoLite2-Country.mmdb

marco@DMZ:~/docker/appdata/pangolin/crowdsec/data$ id
uid=1000(marco) gid=1000(marco) Gruppen=1000(marco),24(cdrom),25(floppy),27(sudo),29(audio),30(dip),44(video),46(plugdev),100(users),106(netdev)

```

This is my quadlet file:

```plaintext
[Unit]
Description=crowdsec
After=gerbil.service

[Container]
ContainerName=crowdsec-pangolin
Image=docker.io/crowdsecurity/crowdsec:latest

Environment=TZ=Europe/Berlin
Environment=COLLECTIONS="crowdsecurity/traefik crowdsecurity/appsec-virtual-patching crowdsecurity/appsec-generic-rules"
Environment=ACQUIRE_FILES="/var/log/traefik/*.log"
Environment=ENROLL_INSTANCE_NAME="crowdsec-pangolin"
Environment=ENROLL_TAGS=podman
Environment=GID=1000
Environment=PARSERS=crowdsecurity/whitelists"

User=1000:1000

Volume=%h/docker/appdata/pangolin/crowdsec:/etc/crowdsec
Volume=%h/docker/appdata/pangolin/crowdsec/data:/var/lib/crowdsec/data
Volume=%h/docker/appdata/pangolin/traefik/logs:/var/log/traefik:ro
Volume=%h/docker/appdata/pangolin/traefik/captcha.html:/etc/traefik/conf/captcha.html

[Service]
Restart=unless-stopped

```

Couldn’t find anything related to this, beside:

> [@Running crowdsec as non-root user in Docker?](https://discourse.crowdsec.net/t/running-crowdsec-as-non-root-user-in-docker/2021/3):
>
> @isdnfan, how do you cope with the contents of /var/lib/crowdsec/data/ crowdsec | time=“2025-09-15T07:01:01Z” level=error msg=“open /var/lib/crowdsec/data/rdns\_seo\_bots.txt: permission denied” crowdsec | time=“2025-09-15T07:01:01Z” level=error msg=“open /var/lib/crowdsec/data/rdns\_seo\_bots.regex: permission denied” crowdsec | time=“2025-09-15T07:01:01Z” level=error msg=“open /var/lib/crowdsec/data/ip\_seo\_bots.txt: permission denied”

But can’t see the solution there.

Can anyone help me with this?

---

<div class="post-metadata">

**Author:** ![Damncold](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/damncold/32/1391_2.png) [@Damncold](https://discourse.crowdsec.net/u/Damncold)\
**Post date:** [March 14, 2026, 8:47am UTC](https://discourse.crowdsec.net/t/cant-start-crowdsec-in-rootless-podman/2788/2 "2026-03-14T08:47:42Z")

</div>

After removing:

```plaintext
User=1000:1000

```

from my quadlet.

I get now the following error:

```bash
Mär 14 09:28:44 DMZ crowdsec-pangolin[340627]: /var/lib/crowdsec/data was found in a volume

```

This is a volume i used in an old crowdsec container.

But this is disabled and i also removed all volumes via podman volume rm …

I’m still stuck here

---

<div class="post-metadata">

**Author:** ![Damncold](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/damncold/32/1391_2.png) [@Damncold](https://discourse.crowdsec.net/u/Damncold)\
**Post date:** [March 15, 2026, 8:53pm UTC](https://discourse.crowdsec.net/t/cant-start-crowdsec-in-rootless-podman/2788/3 "2026-03-15T20:53:03Z")

</div>

seems that i still dont understand podman and the namespace /user permission things …

i switch to named volumes, and now its working …
