From 774bba415eb43eb94223f978342e522cc9347495 Mon Sep 17 00:00:00 2001 From: Josh Hawkins <32435876+hawkeye217@users.noreply.github.com> Date: Sun, 23 Aug 2026 17:59:19 -0500 Subject: [PATCH] Run the frigate service as the frigate user --- .github/workflows/ci.yml | 2 +- docker/main/rootfs/etc/s6-overlay/s6-rc.d/frigate/run | 6 +++++- docker/main/rootfs/usr/local/bin/fix-ownership | 2 +- 3 files changed, 7 insertions(+), 3 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 608a6093b9..076b6e32d4 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -110,7 +110,7 @@ jobs: if [ "$up" -ne 1 ]; then echo "PUID container never became healthy"; docker logs frigate-puid; exit 1; fi docker exec frigate-puid id -u frigate | grep -qx 1500 docker exec frigate-puid id -g frigate | grep -qx 1500 - docker exec frigate-puid cat /config/.permissions_version | grep -qx "1:1500:1500" + docker exec frigate-puid cat /config/.permissions_version | grep -qx "2:1500:1500" # second boot must skip the sweep (sentinel hit). Poll rather than # sleep: the string can only come from the second boot (the first # had no sentinel), so grepping the full log is unambiguous. diff --git a/docker/main/rootfs/etc/s6-overlay/s6-rc.d/frigate/run b/docker/main/rootfs/etc/s6-overlay/s6-rc.d/frigate/run index 9c84c20d5c..8bf6d5f528 100755 --- a/docker/main/rootfs/etc/s6-overlay/s6-rc.d/frigate/run +++ b/docker/main/rootfs/etc/s6-overlay/s6-rc.d/frigate/run @@ -30,4 +30,8 @@ cd /opt/frigate || echo "[ERROR] Failed to change working directory to /opt/frig # Replace the bash process with the Frigate process, redirecting stderr to stdout exec 2>&1 -exec python3 -u -m frigate +if [[ "$(id -u)" -ne 0 || "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then + exec python3 -u -m frigate +else + exec s6-setuidgid frigate python3 -u -m frigate +fi diff --git a/docker/main/rootfs/usr/local/bin/fix-ownership b/docker/main/rootfs/usr/local/bin/fix-ownership index 1df73b36c5..07f21c3f1a 100755 --- a/docker/main/rootfs/usr/local/bin/fix-ownership +++ b/docker/main/rootfs/usr/local/bin/fix-ownership @@ -22,7 +22,7 @@ set -o errexit -o nounset -o pipefail # Permissions-layout epoch. Bump to force a one-time re-sweep on upgrade # (e.g. when the privilege-drop release must capture files created as root # since the previous sweep). -schema=1 +schema=2 dry_run=0 sentinel=""