let services listed in FRIGATE_ROOT_SERVICES skip the privilege drop

This commit is contained in:
Josh Hawkins
2026-08-28 07:28:47 -05:00
parent 9ef7f57cad
commit cdd5d3ecff
3 changed files with 28 additions and 6 deletions
@@ -4,10 +4,18 @@
set -o errexit -o nounset -o pipefail set -o errexit -o nounset -o pipefail
runs_as_root=0
if [[ "$(id -u)" -eq 0 ]]; then
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]] || /usr/local/bin/service-runs-as-root frigate; then
runs_as_root=1
fi
fi
# $HOME is /root from the container env and survives s6-setuidgid, so cache # $HOME is /root from the container env and survives s6-setuidgid, so cache
# and telemetry writes (huggingface, openvino) fail after the drop. Set it # and telemetry writes (huggingface, openvino) fail after the drop. Set it
# before opt_in_out so the opt-out marker lands where the service will look. # before opt_in_out so the opt-out marker lands where the service will look.
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then # When the service keeps root, /root stays correct.
if [[ "$runs_as_root" -eq 0 ]]; then
export HOME=/config export HOME=/config
fi fi
@@ -37,7 +45,7 @@ cd /opt/frigate || echo "[ERROR] Failed to change working directory to /opt/frig
# Replace the bash process with the Frigate process, redirecting stderr to stdout # Replace the bash process with the Frigate process, redirecting stderr to stdout
exec 2>&1 exec 2>&1
if [[ "$(id -u)" -ne 0 || "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then if [[ "$(id -u)" -ne 0 || "$runs_as_root" -eq 1 ]]; then
exec python3 -u -m frigate exec python3 -u -m frigate
else else
exec s6-setuidgid frigate python3 -u -m frigate exec s6-setuidgid frigate python3 -u -m frigate
@@ -4,6 +4,13 @@
set -o errexit -o nounset -o pipefail set -o errexit -o nounset -o pipefail
runs_as_root=0
if [[ "$(id -u)" -eq 0 ]]; then
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]] || /usr/local/bin/service-runs-as-root go2rtc; then
runs_as_root=1
fi
fi
# Logs should be sent to stdout so that s6 can collect them # Logs should be sent to stdout so that s6 can collect them
function get_ip_and_port_from_supervisor() { function get_ip_and_port_from_supervisor() {
@@ -110,7 +117,7 @@ fi
readonly homekit_config_path="/config/go2rtc_homekit.yml" readonly homekit_config_path="/config/go2rtc_homekit.yml"
setup_homekit_config "${homekit_config_path}" setup_homekit_config "${homekit_config_path}"
if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then if [[ "$(id -u)" -eq 0 && "$runs_as_root" -eq 0 ]]; then
chown go2rtc:go2rtc /dev/shm/go2rtc.yaml 2>/dev/null || true chown go2rtc:go2rtc /dev/shm/go2rtc.yaml 2>/dev/null || true
# go2rtc rewrites this in place (os.WriteFile, no rename), so owning the # go2rtc rewrites this in place (os.WriteFile, no rename), so owning the
# file is enough; /config grants frigate-data traverse only. Tolerated so # file is enough; /config grants frigate-data traverse only. Tolerated so
@@ -135,7 +142,7 @@ echo "[INFO] Starting go2rtc..."
# Use HomeKit config as the primary config so writebacks go there # Use HomeKit config as the primary config so writebacks go there
# The main config from Frigate will be loaded as a secondary config # The main config from Frigate will be loaded as a secondary config
exec 2>&1 exec 2>&1
if [[ "$(id -u)" -ne 0 || "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then if [[ "$(id -u)" -ne 0 || "$runs_as_root" -eq 1 ]]; then
exec "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml exec "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml
else else
exec s6-setuidgid go2rtc "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml exec s6-setuidgid go2rtc "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml
@@ -4,6 +4,13 @@
set -o errexit -o nounset -o pipefail set -o errexit -o nounset -o pipefail
runs_as_root=0
if [[ "$(id -u)" -eq 0 ]]; then
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]] || /usr/local/bin/service-runs-as-root nginx; then
runs_as_root=1
fi
fi
# Logs should be sent to stdout so that s6 can collect them # Logs should be sent to stdout so that s6 can collect them
echo "[INFO] Starting NGINX..." echo "[INFO] Starting NGINX..."
@@ -104,7 +111,7 @@ echo "$nginx_settings" | \
tempio -template /usr/local/nginx/templates/listen.gotmpl \ tempio -template /usr/local/nginx/templates/listen.gotmpl \
-out /tmp/nginx/conf/listen.conf -out /tmp/nginx/conf/listen.conf
if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then if [[ "$(id -u)" -eq 0 && "$runs_as_root" -eq 0 ]]; then
chown -R frigate:frigate /tmp/nginx chown -R frigate:frigate /tmp/nginx
# heal the cache if a root `nginx -t` chowned it (ngx_create_paths chowns # heal the cache if a root `nginx -t` chowned it (ngx_create_paths chowns
# every cycle path to the `user` directive user when run as root) # every cycle path to the `user` directive user when run as root)
@@ -125,7 +132,7 @@ fi
exec 2>&1 exec 2>&1
# -e stderr: the compile-time default error log under /usr/local/nginx/logs # -e stderr: the compile-time default error log under /usr/local/nginx/logs
# is not writable by the runtime user and would alert before config load # is not writable by the runtime user and would alert before config load
if [[ "$(id -u)" -ne 0 || "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then if [[ "$(id -u)" -ne 0 || "$runs_as_root" -eq 1 ]]; then
exec \ exec \
s6-notifyoncheck -t 30000 -n 1 \ s6-notifyoncheck -t 30000 -n 1 \
nginx -e stderr -c /tmp/nginx/conf/nginx.conf nginx -e stderr -c /tmp/nginx/conf/nginx.conf