Error in Passbolt log

Hi,

I see the following message in my log

2026-09-14T10:08:21+02:00 [1:passbolt1:systemd] Started passbolt.service - Podman passbolt.service.
2026-09-14T10:08:21+02:00 [1:passbolt1:systemd] Reached target default.target - Main User Target.
2026-09-14T10:08:21+02:00 [1:passbolt1:systemd] Starting passbolt-db.service - Podman passbolt-db.service…
2026-09-14T10:08:21+02:00 [1:passbolt1:podman] time=“2026-09-14T10:08:21+02:00” level=error msg=“User-selected graph driver \“overlay\” overwritten by graph driver \“vfs\” from database - delete libpod local files (\”/home/passbolt1/.local/share/containers/storage\“) to resolve. May prevent use of images created by other tools”

How can ik solve this this

Can you provide more information about your System? Which distribution? What’s its update/upgrade history?

Please paste the output of

runagent -m passbolt1 podman system info

And

podman system info

Hello Davide,

Sorry :wink:

NS8 on debian 13

System info

podman system info
ERRO\[0000\] User-selected graph driver "overlay" overwritten by graph driver "vfs                                                                                      " from database - delete libpod local files ("/home/passbolt1/.local/share/conta                                                                                      iners/storage") to resolve.  May prevent use of images created by other tools
ERRO\[0000\] User-selected graph driver "overlay" overwritten by graph driver "vfs                                                                                      " from database - delete libpod local files ("/home/passbolt1/.local/share/conta                                                                                      iners/storage") to resolve.  May prevent use of images created by other tools
host:
arch: amd64
buildahVersion: 1.39.3
cgroupControllers:

* cpu
* memory
* pids
  cgroupManager: systemd
  cgroupVersion: v2
  conmon:
  package: conmon_2.1.12-4_amd64
  path: /usr/bin/conmon
  version: 'conmon version 2.1.12, commit: unknown'
  cpuUtilization:
  idlePercent: 98.02
  systemPercent: 0.56
  userPercent: 1.42
  cpus: 2
  databaseBackend: boltdb
  distribution:
  codename: trixie
  distribution: debian
  version: "13"
  eventLogger: journald
  freeLocks: 2040
  hostname: ns8
  idMappings:
  gidmap:
  * container_id: 0
    host_id: 1014
    size: 1
  * container_id: 1
    host_id: 755360
    size: 65536
    uidmap:
  * container_id: 0
    host_id: 1014
    size: 1
  * container_id: 1
    host_id: 755360
    size: 65536
    kernel: 6.12.107+deb13-amd64
    linkmode: dynamic
    logDriver: journald
    memFree: 602333184
    memTotal: 33663295488
    networkBackend: netavark
    networkBackendInfo:
    backend: netavark
    dns:
    package: aardvark-dns_1.14.0-3_amd64
    path: /usr/lib/podman/aardvark-dns
    version: aardvark-dns 1.14.0
    package: netavark_1.14.0-2_amd64
    path: /usr/lib/podman/netavark
    version: netavark 1.14.0
    ociRuntime:
    name: crun
    package: crun_1.21-1_amd64
    path: /usr/bin/crun
    version: |-
    crun version 1.21
    commit: 10269840aa07fb7e6b7e1acff6198692d8ff5c88
    rundir: /run/user/1014/crun
    spec: 1.0.0
    +SYSTEMD +SELINUX +APPARMOR +CAP +SECCOMP +EBPF +CRIU +WASM:wasmedge +YAJL
    os: linux
    pasta:
    executable: /usr/bin/pasta
    package: passt_0.0\~git20250503.587980c-2+deb13u1_amd64
    version: ""
    remoteSocket:
    exists: true
    path: /run/user/1014/podman/podman.sock
    rootlessNetworkCmd: pasta
    security:
    apparmorEnabled: false
    capabilities: CAP_CHOWN,CAP_DAC_OVERRIDE,CAP_FOWNER,CAP_FSETID,CAP_KILL,CAP\_                                                                                      NET_BIND_SERVICE,CAP_SETFCAP,CAP_SETGID,CAP_SETPCAP,CAP_SETUID,CAP_SYS_CHROOT
    rootless: true
    seccompEnabled: true
    seccompProfilePath: /usr/share/containers/seccomp.json
    selinuxEnabled: false
    serviceIsRemote: false
    slirp4netns:
    executable: /usr/bin/slirp4netns
    package: slirp4netns_1.2.1-1.1_amd64
    version: |-
    slirp4netns version 1.2.1
    commit: 09e31e92fa3d2a1d3ca261adaeb012c8d75a8194
    libslirp: 4.8.0
    SLIRP_CONFIG_VERSION_MAX: 5
    libseccomp: 2.6.0
    swapFree: 9612816384
    swapTotal: 9613340672
    uptime: 26h 53m 0.00s (Approximately 1.08 days)
    variant: ""
    plugins:
    authorization: null
    log:
* k8s-file
* none
* passthrough
* journald
  network:
* bridge
* macvlan
* ipvlan
  volume:
* local
  registries:
  docker.io:
  Blocked: false
  Insecure: false
  Location: docker.io
  MirrorByDigestOnly: false
  Mirrors:
  * Insecure: false
    Location: ghcr.io/nethserver/docker.io
    PullFromMirror: ""
    Prefix: docker.io
    PullFromMirror: ""
    store:
    configFile: /home/passbolt1/.config/containers/storage.conf
    containerStore:
    number: 3
    paused: 0
    running: 3
    stopped: 0
    graphDriverName: vfs
    graphOptions: {}
    graphRoot: /home/passbolt1/.local/share/containers/storage
    graphRootAllocated: 201314131968
    graphRootUsed: 99179204608
    graphStatus: {}
    imageCopyTmpDir: /var/tmp
    imageStore:
    number: 7
    runRoot: /run/user/1014/containers
    transientStore: false
    volumePath: /home/passbolt1/.local/share/containers/storage/volumes
    version:
    APIVersion: 5.4.2
    BuildOrigin: Debian
    Built: 1766335321
    BuiltTime: Sun Dec 21 17:42:01 2025
    GitCommit: ""
    GoVersion: go1.24.4
    Os: linux
    OsArch: linux/amd64
    Version: 5.4.2

podman system info

ERRO[0000] User-selected graph driver "overlay" overwritten by graph driver "vfs                                                                                      " from database - delete libpod local files ("/home/passbolt1/.local/share/conta                                                                                      iners/storage") to resolve.  May prevent use of images created by other tools
ERRO[0000] User-selected graph driver "overlay" overwritten by graph driver "vfs                                                                                      " from database - delete libpod local files ("/home/passbolt1/.local/share/conta                                                                                      iners/storage") to resolve.  May prevent use of images created by other tools
host:
  arch: amd64
  buildahVersion: 1.39.3
  cgroupControllers:
  - cpu
  - memory
  - pids
  cgroupManager: systemd
  cgroupVersion: v2
  conmon:
    package: conmon_2.1.12-4_amd64
    path: /usr/bin/conmon
    version: 'conmon version 2.1.12, commit: unknown'
  cpuUtilization:
    idlePercent: 98.02
    systemPercent: 0.56
    userPercent: 1.42
  cpus: 2
  databaseBackend: boltdb
  distribution:
    codename: trixie
    distribution: debian
    version: "13"
  eventLogger: journald
  freeLocks: 2040
  hostname: ns8
  idMappings:
    gidmap:
    - container_id: 0
      host_id: 1014
      size: 1
    - container_id: 1
      host_id: 755360
      size: 65536
    uidmap:
    - container_id: 0
      host_id: 1014
      size: 1
    - container_id: 1
      host_id: 755360
      size: 65536
  kernel: 6.12.107+deb13-amd64
  linkmode: dynamic
  logDriver: journald
  memFree: 602333184
  memTotal: 33663295488
  networkBackend: netavark
  networkBackendInfo:
    backend: netavark
    dns:
      package: aardvark-dns_1.14.0-3_amd64
      path: /usr/lib/podman/aardvark-dns
      version: aardvark-dns 1.14.0
    package: netavark_1.14.0-2_amd64
    path: /usr/lib/podman/netavark
    version: netavark 1.14.0
  ociRuntime:
    name: crun
    package: crun_1.21-1_amd64
    path: /usr/bin/crun
    version: |-
      crun version 1.21
      commit: 10269840aa07fb7e6b7e1acff6198692d8ff5c88
      rundir: /run/user/1014/crun
      spec: 1.0.0
      +SYSTEMD +SELINUX +APPARMOR +CAP +SECCOMP +EBPF +CRIU +WASM:wasmedge +YAJL
  os: linux
  pasta:
    executable: /usr/bin/pasta
    package: passt_0.0~git20250503.587980c-2+deb13u1_amd64
    version: ""
  remoteSocket:
    exists: true
    path: /run/user/1014/podman/podman.sock
  rootlessNetworkCmd: pasta
  security:
    apparmorEnabled: false
    capabilities: CAP_CHOWN,CAP_DAC_OVERRIDE,CAP_FOWNER,CAP_FSETID,CAP_KILL,CAP_                                                                                      NET_BIND_SERVICE,CAP_SETFCAP,CAP_SETGID,CAP_SETPCAP,CAP_SETUID,CAP_SYS_CHROOT
    rootless: true
    seccompEnabled: true
    seccompProfilePath: /usr/share/containers/seccomp.json
    selinuxEnabled: false
  serviceIsRemote: false
  slirp4netns:
    executable: /usr/bin/slirp4netns
    package: slirp4netns_1.2.1-1.1_amd64
    version: |-
      slirp4netns version 1.2.1
      commit: 09e31e92fa3d2a1d3ca261adaeb012c8d75a8194
      libslirp: 4.8.0
      SLIRP_CONFIG_VERSION_MAX: 5
      libseccomp: 2.6.0
  swapFree: 9612816384
  swapTotal: 9613340672
  uptime: 26h 53m 0.00s (Approximately 1.08 days)
  variant: ""
plugins:
  authorization: null
  log:
  - k8s-file
  - none
  - passthrough
  - journald
  network:
  - bridge
  - macvlan
  - ipvlan
  volume:
  - local
registries:
  docker.io:
    Blocked: false
    Insecure: false
    Location: docker.io
    MirrorByDigestOnly: false
    Mirrors:
    - Insecure: false
      Location: ghcr.io/nethserver/docker.io
      PullFromMirror: ""
    Prefix: docker.io
    PullFromMirror: ""
store:
  configFile: /home/passbolt1/.config/containers/storage.conf
  containerStore:
    number: 3
    paused: 0
    running: 3
    stopped: 0
  graphDriverName: vfs
  graphOptions: {}
  graphRoot: /home/passbolt1/.local/share/containers/storage
  graphRootAllocated: 201314131968
  graphRootUsed: 99179204608
  graphStatus: {}
  imageCopyTmpDir: /var/tmp
  imageStore:
    number: 7
  runRoot: /run/user/1014/containers
  transientStore: false
  volumePath: /home/passbolt1/.local/share/containers/storage/volumes
version:
  APIVersion: 5.4.2
  BuildOrigin: Debian
  Built: 1766335321
  BuiltTime: Sun Dec 21 17:42:01 2025
  GitCommit: ""
  GoVersion: go1.24.4
  Os: linux
  OsArch: linux/amd64
  Version: 5.4.2

root@ns8:~# ^C
root@ns8:~# ^C
root@ns8:~# podman system info
host:
  arch: amd64
  buildahVersion: 1.39.3
  cgroupControllers:
  - cpuset
  - cpu
  - io
  - memory
  - hugetlb
  - pids
  - rdma
  - misc
  cgroupManager: systemd
  cgroupVersion: v2
  conmon:
    package: conmon_2.1.12-4_amd64
    path: /usr/bin/conmon
    version: 'conmon version 2.1.12, commit: unknown'
  cpuUtilization:
    idlePercent: 98.02
    systemPercent: 0.56
    userPercent: 1.42
  cpus: 2
  databaseBackend: boltdb
  distribution:
    codename: trixie
    distribution: debian
    version: "13"
  eventLogger: journald
  freeLocks: 2034
  hostname: ns8
  idMappings:
    gidmap: null
    uidmap: null
  kernel: 6.12.107+deb13-amd64
  linkmode: dynamic
  logDriver: journald
  memFree: 600281088
  memTotal: 33663295488
  networkBackend: netavark
  networkBackendInfo:
    backend: netavark
    dns:
      package: aardvark-dns_1.14.0-3_amd64
      path: /usr/lib/podman/aardvark-dns
      version: aardvark-dns 1.14.0
    package: netavark_1.14.0-2_amd64
    path: /usr/lib/podman/netavark
    version: netavark 1.14.0
  ociRuntime:
    name: crun
    package: crun_1.21-1_amd64
    path: /usr/bin/crun
    version: |-
      crun version 1.21
      commit: 10269840aa07fb7e6b7e1acff6198692d8ff5c88
      rundir: /run/user/0/crun
      spec: 1.0.0
      +SYSTEMD +SELINUX +APPARMOR +CAP +SECCOMP +EBPF +CRIU +WASM:wasmedge +YAJL
  os: linux
  pasta:
    executable: /usr/bin/pasta
    package: passt_0.0~git20250503.587980c-2+deb13u1_amd64
    version: ""
  remoteSocket:
    exists: true
    path: /run/podman/podman.sock
  rootlessNetworkCmd: pasta
  security:
    apparmorEnabled: true
    capabilities: CAP_CHOWN,CAP_DAC_OVERRIDE,CAP_FOWNER,CAP_FSETID,CAP_KILL,CAP_NET_BIND_SERVICE,CAP_SETFCAP,CAP_SETGID,CAP_SETPCAP,CAP_SETUID,CAP_SYS_CHROOT
    rootless: false
    seccompEnabled: true
    seccompProfilePath: /usr/share/containers/seccomp.json
    selinuxEnabled: false
  serviceIsRemote: false
  slirp4netns:
    executable: /usr/bin/slirp4netns
    package: slirp4netns_1.2.1-1.1_amd64
    version: |-
      slirp4netns version 1.2.1
      commit: 09e31e92fa3d2a1d3ca261adaeb012c8d75a8194
      libslirp: 4.8.0
      SLIRP_CONFIG_VERSION_MAX: 5
      libseccomp: 2.6.0
  swapFree: 9612816384
  swapTotal: 9613340672
  uptime: 26h 54m 40.00s (Approximately 1.08 days)
  variant: ""
plugins:
  authorization: null
  log:
  - k8s-file
  - none
  - passthrough
  - journald
  network:
  - bridge
  - macvlan
  - ipvlan
  volume:
  - local
registries:
  docker.io:
    Blocked: false
    Insecure: false
    Location: docker.io
    MirrorByDigestOnly: false
    Mirrors:
    - Insecure: false
      Location: ghcr.io/nethserver/docker.io
      PullFromMirror: ""
    Prefix: docker.io
    PullFromMirror: ""
store:
  configFile: /usr/share/containers/storage.conf
  containerStore:
    number: 7
    paused: 0
    running: 6
    stopped: 1
  graphDriverName: overlay
  graphOptions:
    overlay.mountopt: nodev
  graphRoot: /var/lib/containers/storage
  graphRootAllocated: 201314131968
  graphRootUsed: 99180503040
  graphStatus:
    Backing Filesystem: extfs
    Native Overlay Diff: "true"
    Supports d_type: "true"
    Supports shifting: "true"
    Supports volatile: "true"
    Using metacopy: "false"
  imageCopyTmpDir: /var/tmp
  imageStore:
    number: 35
  runRoot: /run/containers/storage
  transientStore: false
  volumePath: /var/lib/containers/storage/volumes
version:
  APIVersion: 5.4.2
  BuildOrigin: Debian
  Built: 1766335321
  BuiltTime: Sun Dec 21 17:42:01 2025
  GitCommit: ""
  GoVersion: go1.24.4
  Os: linux
  OsArch: linux/amd64
  Version: 5.4.2

Make sure fuse-overlayfs is installed:

apt install fuse-overlayfs

Then try to restore a passbolt backup, check that it’s fully working, then see if the error disappears in the new instance.

fuse-overlayfs was already installed on the system

Do i need to restore anyway a backup ?

And… i’ve never rstores a banckup yet in NS
Yes restore and it will go ok ?

How did you install this Debian in origin? Was it a 12 or it was born as 13?

Please paste the output of

cat /home/passbolt1/.config/containers/storage.conf

The install was origin D12 and upgeraded to D13 (by the instruction as on the forum by MrMarkuz)

cat /home/passbolt1/.config/containers/storage.conf

File doesn’t exit



 cat /usr/share/containers/storage.conf
# This file is the configuration file for all tools
# that use the containers/storage library. The storage.conf file
# overrides all other storage.conf files. Container engines using the
# container/storage library do not inherit fields from other storage.conf
# files.
#
#  Note: The storage.conf file overrides other storage.conf files based on this                                                                precedence:
#      /usr/containers/storage.conf
#      /etc/containers/storage.conf
#      $HOME/.config/containers/storage.conf
#      $XDG_CONFIG_HOME/containers/storage.conf (if XDG_CONFIG_HOME is set)
# See man 5 containers-storage.conf for more information
# The "storage" table contains all of the server options.
[storage]

# Default storage driver, must be set for proper operation.
driver = "overlay"

# Temporary storage location
runroot = "/run/containers/storage"

# Priority list for the storage drivers that will be tested one
# after the other to pick the storage driver if it is not defined.
# driver_priority = ["overlay", "btrfs"]

# Primary Read/Write location of container storage
# When changing the graphroot location on an SELinux system, you must
# ensure the labeling matches the default location's labels with the
# following commands:
# semanage fcontext -a -e /var/lib/containers/storage /NEWSTORAGEPATH
# restorecon -R -v /NEWSTORAGEPATH
graphroot = "/var/lib/containers/storage"

# Optional alternate location of image store if a location separate from the
# container store is required. If set, it must be different than graphroot.
# imagestore = ""


# Storage path for rootless users
#
# rootless_storage_path = "$HOME/.local/share/containers/storage"

# Transient store mode makes all container metadata be saved in temporary storag                                                               e
# (i.e. runroot above). This is faster, but doesn't persist across reboots.
# Additional garbage collection must also be performed at boot-time, so this
# option should remain disabled in most configurations.
# transient_store = true

[storage.options]
# Storage options to be passed to underlying storage drivers

# AdditionalImageStores is used to pass paths to additional Read/Only image stor                                                               es
# Must be comma separated list.
additionalimagestores = [
]

# Options controlling how storage is populated when pulling images.
[storage.options.pull_options]
# Enable the "zstd:chunked" feature, which allows partial pulls, reusing
# content that already exists on the system. This is disabled by default,
# and must be explicitly enabled to be used. For more on zstd:chunked, see
# https://github.com/containers/storage/blob/main/docs/containers-storage-zstd-c                                                               hunked.md
# This is a "string bool": "false" | "true" (cannot be native TOML boolean)
# enable_partial_images = "false"

# Tells containers/storage to use hard links rather then create new files in
# the image, if an identical file already existed in storage.
# This is a "string bool": "false" | "true" (cannot be native TOML boolean)
# use_hard_links = "false"

# Path to an ostree repository that might have
# previously pulled content which can be used when attempting to avoid
# pulling content from the container registry.
# ostree_repos=""

# If set to "true", containers/storage will convert images that are
# not already in zstd:chunked format to that format before processing
# in order to take advantage of local deduplication and hard linking.
# It is an expensive operation so it is not enabled by default.
# This is a "string bool": "false" | "true" (cannot be native TOML boolean)
# convert_images = "false"

# This should ALMOST NEVER be set.
# It allows partial pulls of images without guaranteeing that "partial
# pulls" and non-partial pulls both result in consistent image contents.
# This allows pulling estargz images and early versions of zstd:chunked images;
# otherwise, these layers always use the traditional non-partial pull path.
#
# This option should be enabled EXTREMELY rarely, only if ALL images that could
# EVER be conceivably pulled on this system are GUARANTEED (e.g. using a signatu                                                               re policy)
# to come from a build system trusted to never attack image integrity.
#
# If this consistency enforcement were disabled, malicious images could be built
# in a way designed to evade other audit mechanisms, so presence of most other a                                                               udit
# mechanisms is not a replacement for the above-mentioned need for all images to                                                                come
# from a trusted build system.
#
# As a side effect, enabling this option will also make image IDs unpredictable
# (usually not equal to the traditional value matching the config digest).
# insecure_allow_unpredictable_image_contents = "false"

# Root-auto-userns-user is a user name which can be used to look up one or more                                                                UID/GID
# ranges in the /etc/subuid and /etc/subgid file.  These ranges will be partitio                                                               ned
# to containers configured to create automatically a user namespace.  Containers
# configured to automatically create a user namespace can still overlap with con                                                               tainers
# having an explicit mapping set.
# This setting is ignored when running as rootless.
# root-auto-userns-user = "storage"
#
# Auto-userns-min-size is the minimum size for a user namespace created automati                                                               cally.
# auto-userns-min-size=1024
#
# Auto-userns-max-size is the maximum size for a user namespace created automati                                                               cally.
# auto-userns-max-size=65536

[storage.options.overlay]
# ignore_chown_errors can be set to allow a non privileged user running with
# a single UID within a user namespace to run containers. The user can pull
# and use any image even those with multiple uids.  Note multiple UIDs will be
# squashed down to the default uid in the container.  These images will have no
# separation between the users in the container. Only supported for the overlay
# and vfs drivers.
# This is a "string bool": "false" | "true" (cannot be native TOML boolean)
#ignore_chown_errors = "false"

# Inodes is used to set a maximum inodes of the container image.
# inodes = ""

# Path to an helper program to use for mounting the file system instead of mount                                                               ing it
# directly.
#mount_program = "/usr/bin/fuse-overlayfs"

# mountopt specifies comma separated list of extra mount options
mountopt = "nodev"

# Set to skip a PRIVATE bind mount on the storage home directory.
# This is a "string bool": "false" | "true" (cannot be native TOML boolean)
# skip_mount_home = "false"

# Set to use composefs to mount data layers with overlay.
# This is a "string bool": "false" | "true" (cannot be native TOML boolean)
# use_composefs = "false"

# Size is used to set a maximum size of the container image.
# size = ""

# ForceMask specifies the permissions mask that is used for new files and
# directories.
#
# The values "shared" and "private" are accepted.
# Octal permission masks are also accepted.
#
#  "": No value specified.
#     All files/directories, get set with the permissions identified within the
#     image.
#  "private": it is equivalent to 0700.
#     All files/directories get set with 0700 permissions.  The owner has rwx
#     access to the files. No other users on the system can access the files.
#     This setting could be used with networked based homedirs.
#  "shared": it is equivalent to 0755.
#     The owner has rwx access to the files and everyone else can read, access
#     and execute them. This setting is useful for sharing containers storage
#     with other users.  For instance have a storage owned by root but shared
#     to rootless users as an additional store.
#     NOTE:  All files within the image are made readable and executable by any
#     user on the system. Even /etc/shadow within your image is now readable by
#     any user.
#
#   OCTAL: Users can experiment with other OCTAL Permissions.
#
#  Note: The force_mask Flag is an experimental feature, it could change in the
#  future.  When "force_mask" is set the original permission mask is stored in
#  the "user.containers.override_stat" xattr and the "mount_program" option must
#  be specified. Mount programs like "/usr/bin/fuse-overlayfs" present the
#  extended attribute permissions to processes within containers rather than the
#  "force_mask"  permissions.
#
# force_mask = ""

Did you install Passbolt on D12 or 13?

Still, a restore attempt would be useful in general and it also says if a new Podman 5.4.2 installation, with default SQLite and graphRoot settings, solves the issue.

Otherwise we’ve to look at something else.

It was installed on D12
i’ll check for a restore tonight (when i’m home).

Ok, thank you for digging this. Meanwhile I ask if there are other applications on the same node, when they were installed, and if they present a similar vfs/overlayfs ERROR message or not.

Is this a question for me ?