mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-09-27 02:38:56 +03:00
Container security hardening (phase 2) (#24068)
* Create frigate and go2rtc runtime users in the image * Add single fix-ownership helper for volume permission migration * Add init-usermod oneshot for PUID and PGID remapping * Chown newly created runtime directories to the frigate user * Run sentinel-guarded ownership sweep during prepare * Add host-side volume permission migration script * Guard log directory ownership for user-mode startup * Fall back to plain s6-log when running without root * Assert PUID remapping and sweep sentinel in CI smoke test * Skip the ownership sweep in the devcontainer * Pin FRIGATE_RUN_AS_ROOT in ownership tests * Do not record the sweep as complete when a chown failed * Validate PUID and PGID in the migration script * Treat a failed ownership scan as an incomplete sweep * Reject PUID and PGID of 0 during remapping * Handle symlinks, dry runs, and sentinel write failures in the sweep * Treat an absent sweep root as an incomplete sweep
This commit is contained in:
@@ -1,4 +1,12 @@
|
||||
#!/command/with-contenv bash
|
||||
# shellcheck shell=bash
|
||||
|
||||
exec logutil-service /dev/shm/logs/certsync
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
# logutil-service drops to nobody and applies S6_LOGGING_SCRIPT
|
||||
exec logutil-service /dev/shm/logs/certsync
|
||||
fi
|
||||
|
||||
# Non-root (--user) fallback: logutil-service cannot change UID, so run
|
||||
# s6-log directly with the same directives S6_LOGGING_SCRIPT configures.
|
||||
# shellcheck disable=SC2086
|
||||
exec s6-log ${S6_LOGGING_SCRIPT:-T 1 n0 s10000000 T} /dev/shm/logs/certsync
|
||||
|
||||
@@ -1,4 +1,12 @@
|
||||
#!/command/with-contenv bash
|
||||
# shellcheck shell=bash
|
||||
|
||||
exec logutil-service /dev/shm/logs/frigate
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
# logutil-service drops to nobody and applies S6_LOGGING_SCRIPT
|
||||
exec logutil-service /dev/shm/logs/frigate
|
||||
fi
|
||||
|
||||
# Non-root (--user) fallback: logutil-service cannot change UID, so run
|
||||
# s6-log directly with the same directives S6_LOGGING_SCRIPT configures.
|
||||
# shellcheck disable=SC2086
|
||||
exec s6-log ${S6_LOGGING_SCRIPT:-T 1 n0 s10000000 T} /dev/shm/logs/frigate
|
||||
|
||||
@@ -1,4 +1,12 @@
|
||||
#!/command/with-contenv bash
|
||||
# shellcheck shell=bash
|
||||
|
||||
exec logutil-service /dev/shm/logs/go2rtc
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
# logutil-service drops to nobody and applies S6_LOGGING_SCRIPT
|
||||
exec logutil-service /dev/shm/logs/go2rtc
|
||||
fi
|
||||
|
||||
# Non-root (--user) fallback: logutil-service cannot change UID, so run
|
||||
# s6-log directly with the same directives S6_LOGGING_SCRIPT configures.
|
||||
# shellcheck disable=SC2086
|
||||
exec s6-log ${S6_LOGGING_SCRIPT:-T 1 n0 s10000000 T} /dev/shm/logs/go2rtc
|
||||
|
||||
@@ -0,0 +1,61 @@
|
||||
#!/command/with-contenv bash
|
||||
# shellcheck shell=bash
|
||||
# Remap the frigate user to PUID/PGID and register EXTRA_GROUPS.
|
||||
# No-op when: started with --user (euid != 0), FRIGATE_RUN_AS_ROOT=true,
|
||||
# or PUID/PGID already match.
|
||||
|
||||
set -o errexit -o nounset -o pipefail
|
||||
|
||||
if [[ "$(id -u)" -ne 0 ]]; then
|
||||
# Started with docker --user; the host owns UID mapping entirely.
|
||||
exit 0
|
||||
fi
|
||||
|
||||
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then
|
||||
echo "[INFO] FRIGATE_RUN_AS_ROOT=true: skipping user remapping"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
puid="${PUID:-1000}"
|
||||
pgid="${PGID:-1000}"
|
||||
|
||||
if ! [[ "$puid" =~ ^[0-9]+$ && "$pgid" =~ ^[0-9]+$ ]]; then
|
||||
echo "[ERROR] PUID and PGID must be numeric, got '${puid}' and '${pgid}'" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Remapping to 0 would make the frigate user root, so every service would keep
|
||||
# full privilege while reporting a successful migration.
|
||||
if [[ "$puid" -eq 0 || "$pgid" -eq 0 ]]; then
|
||||
echo "[ERROR] PUID/PGID 0 would run the services as root and defeat the privilege separation." >&2
|
||||
echo "[ERROR] Set FRIGATE_RUN_AS_ROOT=true if you want to keep running as root." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
current_uid="$(id -u frigate)"
|
||||
current_gid="$(id -g frigate)"
|
||||
|
||||
if [[ "$puid" != "$current_uid" || "$pgid" != "$current_gid" ]]; then
|
||||
if [[ ! -w /etc/passwd ]]; then
|
||||
echo "[ERROR] PUID/PGID remapping needs a writable /etc and is not compatible with read_only: true." >&2
|
||||
echo "[ERROR] Either remove read_only and keep PUID, or drop PUID/PGID and use docker's user: ${puid}:${pgid} instead." >&2
|
||||
echo "[ERROR] See https://docs.frigate.video/configuration/non_root for the compatibility matrix." >&2
|
||||
exit 1
|
||||
fi
|
||||
echo "[INFO] Remapping frigate user to ${puid}:${pgid}"
|
||||
groupmod -o -g "$pgid" frigate
|
||||
usermod -o -u "$puid" frigate
|
||||
fi
|
||||
|
||||
# EXTRA_GROUPS: numeric host GIDs granting device access (e.g. host render/video)
|
||||
if [[ -n "${EXTRA_GROUPS:-}" ]]; then
|
||||
for gid in ${EXTRA_GROUPS//,/ }; do
|
||||
if ! getent group "$gid" >/dev/null; then
|
||||
groupadd -o -g "$gid" "frigate-extra-${gid}"
|
||||
fi
|
||||
group_name="$(getent group "$gid" | cut -d: -f1)"
|
||||
usermod -aG "$group_name" frigate
|
||||
usermod -aG "$group_name" go2rtc
|
||||
echo "[INFO] Added frigate and go2rtc to supplementary group ${group_name} (gid ${gid})"
|
||||
done
|
||||
fi
|
||||
@@ -0,0 +1 @@
|
||||
oneshot
|
||||
@@ -0,0 +1 @@
|
||||
/etc/s6-overlay/s6-rc.d/init-usermod/run
|
||||
@@ -7,5 +7,12 @@ set -o errexit -o nounset -o pipefail
|
||||
dirs=(/dev/shm/logs/frigate /dev/shm/logs/go2rtc /dev/shm/logs/nginx /dev/shm/logs/certsync)
|
||||
|
||||
mkdir -p "${dirs[@]}"
|
||||
chown nobody:nogroup "${dirs[@]}"
|
||||
|
||||
# logutil-service drops s6-log to nobody, so the dirs must stay nobody-owned
|
||||
# in root mode. Under docker --user we are already the (only) target user,
|
||||
# chown would fail, and the plain s6-log fallback in the *-log services
|
||||
# writes as us (the mkdir above is sufficient, /dev/shm is 1777).
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
chown nobody:nogroup "${dirs[@]}"
|
||||
fi
|
||||
chmod 02755 "${dirs[@]}"
|
||||
|
||||
@@ -1,4 +1,12 @@
|
||||
#!/command/with-contenv bash
|
||||
# shellcheck shell=bash
|
||||
|
||||
exec logutil-service /dev/shm/logs/nginx
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
# logutil-service drops to nobody and applies S6_LOGGING_SCRIPT
|
||||
exec logutil-service /dev/shm/logs/nginx
|
||||
fi
|
||||
|
||||
# Non-root (--user) fallback: logutil-service cannot change UID, so run
|
||||
# s6-log directly with the same directives S6_LOGGING_SCRIPT configures.
|
||||
# shellcheck disable=SC2086
|
||||
exec s6-log ${S6_LOGGING_SCRIPT:-T 1 n0 s10000000 T} /dev/shm/logs/nginx
|
||||
|
||||
@@ -144,3 +144,16 @@ rm -f /dev/shm/.frigate-is-stopping
|
||||
|
||||
migrate_addon_config_dir
|
||||
migrate_db_from_media_to_config
|
||||
|
||||
# Align volume ownership with the runtime user (one sweep per PUID/schema
|
||||
# change, guarded by the sentinel; see fix-ownership). The escape hatch
|
||||
# deletes the sentinel instead: ownership is never mutated while it is on,
|
||||
# so the next non-root boot must re-sweep whatever root created meanwhile.
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then
|
||||
rm -f /config/.permissions_version
|
||||
else
|
||||
/usr/local/bin/fix-ownership --sentinel /config/.permissions_version \
|
||||
"${PUID:-1000}" "${PGID:-1000}" /config /media/frigate
|
||||
fi
|
||||
fi
|
||||
|
||||
Reference in New Issue
Block a user