# TCP backend inside the namespace as non-root

**URL:** <https://discourse.haproxy.org/t/tcp-backend-inside-the-namespace-as-non-root/1261>\
**Category:** Help!\
**Created:** [May 23, 2017, 6:21pm UTC](https://discourse.haproxy.org/t/tcp-backend-inside-the-namespace-as-non-root/1261 "2017-05-23T18:21:32Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![shefys](https://avatars.discourse-cdn.com/v4/letter/s/53a042/32.png) [@shefys](https://discourse.haproxy.org/u/shefys)\
**Post date:** [May 23, 2017, 6:21pm UTC](https://discourse.haproxy.org/t/tcp-backend-inside-the-namespace-as-non-root/1261/1 "2017-05-23T18:21:32Z")

</div>

Hi,

Is there any way to run haproxy as non-root with a backend configured inside the namespace?  
I tried to setcap cap\_sys\_admin+ep /usr/sbin/haproxy but it didn’t help.

If I start haproxy with user ‘haproxy’ then it is not able to open connections to the backend servers located within namespace:  
setns(5, CLONE\_NEWNET) = -1 EPERM (Operation not permitted)  
gettimeofday({1495561253, 588872}, NULL) = 0

If I run haproxy as root - everything works.

My config:

```
frontend netns1_fend
	log global
    mode tcp
    option tcplog
    bind 1.2.3.4:443 namespace netns1
    bind 1.2.4.4:443 namespace netns1
	default_backend netns1_bend

backend netns1_bend
	mode tcp
	option tcplog
	option tcp-check
	server h1 172.16.1.219:443 check namespace netns1
    server h2 172.16.1.90:443 check namespace netns1
```
