mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-10-01 04:16:50 +03:00
run smoke nginx -t and the write probe as the runtime user
This commit is contained in:
@@ -96,7 +96,9 @@ jobs:
|
|||||||
echo "response carries frame-ancestors, which breaks cross-origin iframe embedding"
|
echo "response carries frame-ancestors, which breaks cross-origin iframe embedding"
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
docker exec frigate /usr/local/nginx/sbin/nginx -t -c /tmp/nginx/conf/nginx.conf
|
# -t must NOT run as root: ngx_create_paths would chown the live cache
|
||||||
|
# and temp dirs to the `user root` directive user, breaking the workers
|
||||||
|
docker exec frigate /command/s6-setuidgid frigate /usr/local/nginx/sbin/nginx -e stderr -t -c /tmp/nginx/conf/nginx.conf
|
||||||
docker exec frigate stat -c %a /etc/letsencrypt/live/frigate/privkey.pem | grep -qx 600
|
docker exec frigate stat -c %a /etc/letsencrypt/live/frigate/privkey.pem | grep -qx 600
|
||||||
docker exec frigate stat -c %a /dev/shm/go2rtc.yaml | grep -qx 640
|
docker exec frigate stat -c %a /dev/shm/go2rtc.yaml | grep -qx 640
|
||||||
- name: Assert services run as non-root
|
- name: Assert services run as non-root
|
||||||
@@ -119,8 +121,15 @@ jobs:
|
|||||||
code=$(curl -s -o /dev/null -w '%{http_code}' -X POST http://127.0.0.1:5000/api/login \
|
code=$(curl -s -o /dev/null -w '%{http_code}' -X POST http://127.0.0.1:5000/api/login \
|
||||||
-H 'content-type: application/json' -d '{"user":"admin","password":"definitely-wrong"}')
|
-H 'content-type: application/json' -d '{"user":"admin","password":"definitely-wrong"}')
|
||||||
[ "$code" = "401" ] || { echo "login endpoint returned $code"; exit 1; }
|
[ "$code" = "401" ] || { echo "login endpoint returned $code"; exit 1; }
|
||||||
|
# nginx runtime state must belong to the runtime user (a root nginx -t
|
||||||
|
# in the step above would have chowned it to root)
|
||||||
|
owners=$(docker exec frigate stat -c %U /tmp/nginx /dev/shm/nginx_cache)
|
||||||
|
echo "$owners"
|
||||||
|
if echo "$owners" | grep -qvx frigate; then
|
||||||
|
echo "nginx runtime dirs are not owned by frigate"; exit 1
|
||||||
|
fi
|
||||||
# runtime user can write recordings storage
|
# runtime user can write recordings storage
|
||||||
docker exec frigate s6-setuidgid frigate touch /media/frigate/.write-probe
|
docker exec frigate /command/s6-setuidgid frigate touch /media/frigate/.write-probe
|
||||||
docker exec frigate rm /media/frigate/.write-probe
|
docker exec frigate rm /media/frigate/.write-probe
|
||||||
- name: Assert escape hatch restores root
|
- name: Assert escape hatch restores root
|
||||||
run: |
|
run: |
|
||||||
|
|||||||
@@ -76,3 +76,5 @@ Use `group_add` in compose (`--group-add` with `docker run`) to give the runtime
|
|||||||
go2rtc's ffmpeg processes no longer appear in Intel GPU stats. Frigate reads per-process GPU usage from `/proc/<pid>/fdinfo`, which the kernel won't let one user read for another user's processes, so anything go2rtc spawns is invisible to it. Overall GPU utilization is unaffected.
|
go2rtc's ffmpeg processes no longer appear in Intel GPU stats. Frigate reads per-process GPU usage from `/proc/<pid>/fdinfo`, which the kernel won't let one user read for another user's processes, so anything go2rtc spawns is invisible to it. Overall GPU utilization is unaffected.
|
||||||
|
|
||||||
If you mount your own TLS certificate at `/etc/letsencrypt/live/frigate`, the private key has to be readable by the runtime user. Frigate won't change ownership of a certificate you supplied, since the mount may be read-only.
|
If you mount your own TLS certificate at `/etc/letsencrypt/live/frigate`, the private key has to be readable by the runtime user. Frigate won't change ownership of a certificate you supplied, since the mount may be read-only.
|
||||||
|
|
||||||
|
If you're debugging nginx, run the config check as the runtime user: `docker exec frigate /command/s6-setuidgid frigate nginx -t -c /tmp/nginx/conf/nginx.conf`. Running `nginx -t` as root hands nginx's runtime directories to root as a side effect, which breaks the running workers until the service restarts.
|
||||||
|
|||||||
Reference in New Issue
Block a user