mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-10-06 23:02:49 +03:00
Run the frigate service as the frigate user
This commit is contained in:
@@ -110,7 +110,7 @@ jobs:
|
|||||||
if [ "$up" -ne 1 ]; then echo "PUID container never became healthy"; docker logs frigate-puid; exit 1; fi
|
if [ "$up" -ne 1 ]; then echo "PUID container never became healthy"; docker logs frigate-puid; exit 1; fi
|
||||||
docker exec frigate-puid id -u frigate | grep -qx 1500
|
docker exec frigate-puid id -u frigate | grep -qx 1500
|
||||||
docker exec frigate-puid id -g frigate | grep -qx 1500
|
docker exec frigate-puid id -g frigate | grep -qx 1500
|
||||||
docker exec frigate-puid cat /config/.permissions_version | grep -qx "1:1500:1500"
|
docker exec frigate-puid cat /config/.permissions_version | grep -qx "2:1500:1500"
|
||||||
# second boot must skip the sweep (sentinel hit). Poll rather than
|
# second boot must skip the sweep (sentinel hit). Poll rather than
|
||||||
# sleep: the string can only come from the second boot (the first
|
# sleep: the string can only come from the second boot (the first
|
||||||
# had no sentinel), so grepping the full log is unambiguous.
|
# had no sentinel), so grepping the full log is unambiguous.
|
||||||
|
|||||||
@@ -30,4 +30,8 @@ cd /opt/frigate || echo "[ERROR] Failed to change working directory to /opt/frig
|
|||||||
|
|
||||||
# Replace the bash process with the Frigate process, redirecting stderr to stdout
|
# Replace the bash process with the Frigate process, redirecting stderr to stdout
|
||||||
exec 2>&1
|
exec 2>&1
|
||||||
exec python3 -u -m frigate
|
if [[ "$(id -u)" -ne 0 || "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then
|
||||||
|
exec python3 -u -m frigate
|
||||||
|
else
|
||||||
|
exec s6-setuidgid frigate python3 -u -m frigate
|
||||||
|
fi
|
||||||
|
|||||||
@@ -22,7 +22,7 @@ set -o errexit -o nounset -o pipefail
|
|||||||
# Permissions-layout epoch. Bump to force a one-time re-sweep on upgrade
|
# Permissions-layout epoch. Bump to force a one-time re-sweep on upgrade
|
||||||
# (e.g. when the privilege-drop release must capture files created as root
|
# (e.g. when the privilege-drop release must capture files created as root
|
||||||
# since the previous sweep).
|
# since the previous sweep).
|
||||||
schema=1
|
schema=2
|
||||||
|
|
||||||
dry_run=0
|
dry_run=0
|
||||||
sentinel=""
|
sentinel=""
|
||||||
|
|||||||
Reference in New Issue
Block a user