discard stdout for the unprivileged smoke nginx -t

This commit is contained in:
Josh Hawkins
2026-08-27 07:47:58 -05:00
parent e72657b53e
commit 624d2a7ca9
2 changed files with 6 additions and 3 deletions
+5 -2
View File
@@ -97,8 +97,11 @@ jobs:
exit 1
fi
# -t must NOT run as root: ngx_create_paths would chown the live cache
# and temp dirs to the `user root` directive user, breaking the workers
docker exec frigate /command/s6-setuidgid frigate /usr/local/nginx/sbin/nginx -e stderr -t -c /tmp/nginx/conf/nginx.conf
# and temp dirs to the `user root` directive user, breaking the workers.
# stdout goes to /dev/null because -t reopens the config's
# error_log/access_log /dev/stdout by path, and the docker exec pipe
# is root-owned; -t reports on stderr, so nothing is lost
docker exec frigate /command/s6-setuidgid frigate bash -c '/usr/local/nginx/sbin/nginx -e stderr -t -c /tmp/nginx/conf/nginx.conf >/dev/null'
docker exec frigate stat -c %a /etc/letsencrypt/live/frigate/privkey.pem | grep -qx 600
docker exec frigate stat -c %a /dev/shm/go2rtc.yaml | grep -qx 640
- name: Assert services run as non-root
+1 -1
View File
@@ -77,4 +77,4 @@ go2rtc's ffmpeg processes no longer appear in Intel GPU stats. Frigate reads per
If you mount your own TLS certificate at `/etc/letsencrypt/live/frigate`, the private key has to be readable by the runtime user. Frigate won't change ownership of a certificate you supplied, since the mount may be read-only.
If you're debugging nginx, run the config check as the runtime user: `docker exec frigate /command/s6-setuidgid frigate nginx -t -c /tmp/nginx/conf/nginx.conf`. Running `nginx -t` as root hands nginx's runtime directories to root as a side effect, which breaks the running workers until the service restarts.
If you're debugging nginx, run the config check as the runtime user with stdout discarded: `docker exec frigate /command/s6-setuidgid frigate bash -c 'nginx -t -c /tmp/nginx/conf/nginx.conf >/dev/null'`. Running `nginx -t` as root hands nginx's runtime directories to root as a side effect, which breaks the running workers until the service restarts, and the config's `/dev/stdout` logs can't be reopened through a root-owned `docker exec` pipe (the results print on stderr either way).