Run nginx as the frigate user with writable state in /tmp/nginx

This commit is contained in:
Josh Hawkins
2026-08-29 15:59:23 -05:00
parent 7530590066
commit b7368197a2
5 changed files with 41 additions and 11 deletions
@@ -49,7 +49,7 @@ do
then
echo "[INFO] Reloading nginx to refresh TLS certificate"
echo "$lefile: $leprint"
/usr/local/nginx/sbin/nginx -s reload
/usr/local/nginx/sbin/nginx -c /tmp/nginx/conf/nginx.conf -s reload
fi
sleep 60
@@ -2,4 +2,4 @@
set -e
# Wait for PID file to exist.
while ! test -f /run/nginx.pid; do sleep 1; done
while ! test -f /tmp/nginx/nginx.pid; do sleep 1; done
@@ -59,10 +59,14 @@ function set_worker_processes() {
cpus=4
fi
# we need to catch any errors because sed will fail if user has bind mounted a custom nginx file
sed -i "s/worker_processes auto;/worker_processes ${cpus};/" /usr/local/nginx/conf/nginx.conf || true
sed -i "s/worker_processes auto;/worker_processes ${cpus};/" /tmp/nginx/conf/nginx.conf
}
# copied whole so the conf tree's relative includes still resolve
mkdir -p /tmp/nginx/conf /tmp/nginx/client_body /tmp/nginx/proxy \
/tmp/nginx/fastcgi /tmp/nginx/uwsgi /tmp/nginx/scgi
cp -r /usr/local/nginx/conf/. /tmp/nginx/conf/
set_worker_processes
# ensure the directory for ACME challenges exists
@@ -87,15 +91,29 @@ nginx_settings=$(python3 /usr/local/nginx/get_nginx_settings.py)
# build templates for optional FRIGATE_BASE_PATH environment variable
echo "$nginx_settings" | \
tempio -template /usr/local/nginx/templates/base_path.gotmpl \
-out /usr/local/nginx/conf/base_path.conf
-out /tmp/nginx/conf/base_path.conf
# build templates for additional network settings
echo "$nginx_settings" | \
tempio -template /usr/local/nginx/templates/listen.gotmpl \
-out /usr/local/nginx/conf/listen.conf
-out /tmp/nginx/conf/listen.conf
if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then
chown -R frigate:frigate /tmp/nginx
# only the self-signed key we just generated; user-mounted certs may be :ro
if [ -f "$letsencrypt_path/privkey.pem" ]; then
chown frigate:frigate "$letsencrypt_path/privkey.pem" "$letsencrypt_path/fullchain.pem" 2>/dev/null || true
fi
fi
# Replace the bash process with the NGINX process, redirecting stderr to stdout
exec 2>&1
exec \
s6-notifyoncheck -t 30000 -n 1 \
nginx
if [[ "$(id -u)" -ne 0 || "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then
exec \
s6-notifyoncheck -t 30000 -n 1 \
nginx -c /tmp/nginx/conf/nginx.conf
else
exec \
s6-notifyoncheck -t 30000 -n 1 \
s6-setuidgid frigate nginx -c /tmp/nginx/conf/nginx.conf
fi