hand /tmp/cache to the runtime user before services start

This commit is contained in:
Josh Hawkins
2026-08-29 15:59:23 -05:00
parent 9e356f1d3f
commit 93470c4ea5
2 changed files with 12 additions and 0 deletions
+5
View File
@@ -68,6 +68,7 @@ jobs:
docker run -d --name frigate --shm-size 256m \
-v /tmp/frigate-config:/config \
-v /tmp/frigate-media:/media/frigate \
--mount type=tmpfs,target=/tmp/cache,tmpfs-size=100000000 \
-p 5000:5000 -p 8971:8971 \
${{ steps.setup.outputs.image-name }}-amd64
- name: Wait for API
@@ -134,6 +135,10 @@ jobs:
# runtime user can write recordings storage
docker exec frigate /command/s6-setuidgid frigate touch /media/frigate/.write-probe
docker exec frigate rm /media/frigate/.write-probe
# /tmp/cache is a tmpfs mount here, as the docs recommend: it arrives
# root-owned, and the ZMQ IPC sockets live in it
docker exec frigate /command/s6-setuidgid frigate touch /tmp/cache/.write-probe
docker exec frigate rm /tmp/cache/.write-probe
- name: Assert escape hatch restores root
run: |
mkdir -p /tmp/frigate-config-root
@@ -174,3 +174,10 @@ if [[ "$(id -u)" -eq 0 && ! -d /media/frigate ]]; then
chown "${PUID:-1000}:${PGID:-1000}" /media/frigate
fi
fi
# Usually a tmpfs mount, so it arrives root-owned and is outside the swept
# volumes. The runtime user binds its ZMQ IPC sockets in here.
if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then
mkdir -p /tmp/cache
chown "${PUID:-1000}:${PGID:-1000}" /tmp/cache
fi