mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-10-05 22:32:50 +03:00
reload nginx by signaling the master instead of parsing its config as root
This commit is contained in:
@@ -6,6 +6,26 @@ set -o errexit -o nounset -o pipefail
|
|||||||
|
|
||||||
# Logs should be sent to stdout so that s6 can collect them
|
# Logs should be sent to stdout so that s6 can collect them
|
||||||
|
|
||||||
|
# Signal the master directly rather than running `nginx -s reload`. That would
|
||||||
|
# have root parse /tmp/nginx/conf, which the unprivileged nginx user can
|
||||||
|
# rewrite, and nginx acts on path directives while loading a config: it creates
|
||||||
|
# them and chowns them to the configured user.
|
||||||
|
function reload_nginx() {
|
||||||
|
local pid
|
||||||
|
|
||||||
|
if ! pid=$(cat /tmp/nginx/nginx.pid 2>/dev/null); then
|
||||||
|
echo "[ERROR] No nginx pid file found, not reloading"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
if [[ ! "$pid" =~ ^[0-9]+$ ]] || [[ "$(cat "/proc/${pid}/comm" 2>/dev/null)" != "nginx" ]]; then
|
||||||
|
echo "[ERROR] nginx pid file does not name a running nginx process, not reloading"
|
||||||
|
return 0
|
||||||
|
fi
|
||||||
|
|
||||||
|
kill -HUP "$pid"
|
||||||
|
}
|
||||||
|
|
||||||
echo "[INFO] Starting certsync..."
|
echo "[INFO] Starting certsync..."
|
||||||
|
|
||||||
lefile="/etc/letsencrypt/live/frigate/fullchain.pem"
|
lefile="/etc/letsencrypt/live/frigate/fullchain.pem"
|
||||||
@@ -49,7 +69,7 @@ do
|
|||||||
then
|
then
|
||||||
echo "[INFO] Reloading nginx to refresh TLS certificate"
|
echo "[INFO] Reloading nginx to refresh TLS certificate"
|
||||||
echo "$lefile: $leprint"
|
echo "$lefile: $leprint"
|
||||||
/usr/local/nginx/sbin/nginx -c /tmp/nginx/conf/nginx.conf -s reload
|
reload_nginx
|
||||||
fi
|
fi
|
||||||
|
|
||||||
sleep 60
|
sleep 60
|
||||||
|
|||||||
@@ -157,7 +157,7 @@ if [[ "$(id -u)" -eq 0 ]]; then
|
|||||||
# sweep blessed against the container-local dir created below would let
|
# sweep blessed against the container-local dir created below would let
|
||||||
# a volume attached later skip the sweep forever
|
# a volume attached later skip the sweep forever
|
||||||
sentinel_args=(--sentinel /config/.permissions_version)
|
sentinel_args=(--sentinel /config/.permissions_version)
|
||||||
if ! awk '$2 == "/media" || $2 ~ /^\/media\//' /proc/mounts | grep -q .; then
|
if ! awk '$2 == "/media" || $2 == "/media/frigate" || $2 ~ /^\/media\/frigate\//' /proc/mounts | grep -q .; then
|
||||||
sentinel_args=()
|
sentinel_args=()
|
||||||
fi
|
fi
|
||||||
/usr/local/bin/fix-ownership "${sentinel_args[@]}" \
|
/usr/local/bin/fix-ownership "${sentinel_args[@]}" \
|
||||||
|
|||||||
Reference in New Issue
Block a user