mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-09-28 19:06:52 +03:00
run smoke nginx -t and the write probe as the runtime user
This commit is contained in:
@@ -96,7 +96,9 @@ jobs:
|
||||
echo "response carries frame-ancestors, which breaks cross-origin iframe embedding"
|
||||
exit 1
|
||||
fi
|
||||
docker exec frigate /usr/local/nginx/sbin/nginx -t -c /tmp/nginx/conf/nginx.conf
|
||||
# -t must NOT run as root: ngx_create_paths would chown the live cache
|
||||
# and temp dirs to the `user root` directive user, breaking the workers
|
||||
docker exec frigate /command/s6-setuidgid frigate /usr/local/nginx/sbin/nginx -e stderr -t -c /tmp/nginx/conf/nginx.conf
|
||||
docker exec frigate stat -c %a /etc/letsencrypt/live/frigate/privkey.pem | grep -qx 600
|
||||
docker exec frigate stat -c %a /dev/shm/go2rtc.yaml | grep -qx 640
|
||||
- name: Assert services run as non-root
|
||||
@@ -119,8 +121,15 @@ jobs:
|
||||
code=$(curl -s -o /dev/null -w '%{http_code}' -X POST http://127.0.0.1:5000/api/login \
|
||||
-H 'content-type: application/json' -d '{"user":"admin","password":"definitely-wrong"}')
|
||||
[ "$code" = "401" ] || { echo "login endpoint returned $code"; exit 1; }
|
||||
# nginx runtime state must belong to the runtime user (a root nginx -t
|
||||
# in the step above would have chowned it to root)
|
||||
owners=$(docker exec frigate stat -c %U /tmp/nginx /dev/shm/nginx_cache)
|
||||
echo "$owners"
|
||||
if echo "$owners" | grep -qvx frigate; then
|
||||
echo "nginx runtime dirs are not owned by frigate"; exit 1
|
||||
fi
|
||||
# runtime user can write recordings storage
|
||||
docker exec frigate s6-setuidgid frigate touch /media/frigate/.write-probe
|
||||
docker exec frigate /command/s6-setuidgid frigate touch /media/frigate/.write-probe
|
||||
docker exec frigate rm /media/frigate/.write-probe
|
||||
- name: Assert escape hatch restores root
|
||||
run: |
|
||||
|
||||
@@ -76,3 +76,5 @@ Use `group_add` in compose (`--group-add` with `docker run`) to give the runtime
|
||||
go2rtc's ffmpeg processes no longer appear in Intel GPU stats. Frigate reads per-process GPU usage from `/proc/<pid>/fdinfo`, which the kernel won't let one user read for another user's processes, so anything go2rtc spawns is invisible to it. Overall GPU utilization is unaffected.
|
||||
|
||||
If you mount your own TLS certificate at `/etc/letsencrypt/live/frigate`, the private key has to be readable by the runtime user. Frigate won't change ownership of a certificate you supplied, since the mount may be read-only.
|
||||
|
||||
If you're debugging nginx, run the config check as the runtime user: `docker exec frigate /command/s6-setuidgid frigate nginx -t -c /tmp/nginx/conf/nginx.conf`. Running `nginx -t` as root hands nginx's runtime directories to root as a side effect, which breaks the running workers until the service restarts.
|
||||
|
||||
Reference in New Issue
Block a user