mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-10-03 13:26:48 +03:00
unwrap hard-wrapped prose in the installation docs
This commit is contained in:
@@ -548,9 +548,7 @@ services:
|
|||||||
|
|
||||||
### Recommended security options
|
### Recommended security options
|
||||||
|
|
||||||
Frigate does not need elevated container privileges for most setups. The
|
Frigate does not need elevated container privileges for most setups. The following hardens the container; add the `devices`/`group_add` entries your hardware requires (see the hardware acceleration docs):
|
||||||
following hardens the container; add the `devices`/`group_add` entries your
|
|
||||||
hardware requires (see the hardware acceleration docs):
|
|
||||||
|
|
||||||
```yaml
|
```yaml
|
||||||
services:
|
services:
|
||||||
@@ -564,19 +562,13 @@ services:
|
|||||||
|
|
||||||
:::note
|
:::note
|
||||||
|
|
||||||
`telemetry.stats.network_bandwidth` uses nethogs, which requires root with
|
`telemetry.stats.network_bandwidth` uses nethogs, which requires root with NET_ADMIN/NET_RAW capabilities. If you enable that stat, omit `cap_drop: [ALL]` or add `cap_add: [NET_ADMIN, NET_RAW]`.
|
||||||
NET_ADMIN/NET_RAW capabilities. If you enable that stat, omit `cap_drop: [ALL]`
|
|
||||||
or add `cap_add: [NET_ADMIN, NET_RAW]`.
|
|
||||||
|
|
||||||
Platforms that genuinely require `privileged: true` (MemryX, some QNAP setups)
|
Platforms that genuinely require `privileged: true` (MemryX, some QNAP setups) are called out in their own sections and are unaffected by this guidance.
|
||||||
are called out in their own sections and are unaffected by this guidance.
|
|
||||||
|
|
||||||
:::
|
:::
|
||||||
|
|
||||||
Frigate's services run as an unprivileged user inside the container. See
|
Frigate's services run as an unprivileged user inside the container. See [Running as a non-root user](../configuration/non_root.md) for the run modes, the one time volume ownership migration, and what each accelerator needs on the host.
|
||||||
[Running as a non-root user](../configuration/non_root.md) for the run modes,
|
|
||||||
the one time volume ownership migration, and what each accelerator needs on the
|
|
||||||
host.
|
|
||||||
|
|
||||||
**Docker CLI**
|
**Docker CLI**
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user