From e7a0743ec0ab7fd47ce58732dd485a0c3d91501d Mon Sep 17 00:00:00 2001 From: Josh Hawkins <32435876+hawkeye217@users.noreply.github.com> Date: Mon, 24 Aug 2026 09:52:59 -0500 Subject: [PATCH] chown the s6 log pipe so non-root nginx can reopen /dev/stdout --- docker/main/rootfs/etc/s6-overlay/s6-rc.d/nginx/run | 10 ++++++++-- 1 file changed, 8 insertions(+), 2 deletions(-) diff --git a/docker/main/rootfs/etc/s6-overlay/s6-rc.d/nginx/run b/docker/main/rootfs/etc/s6-overlay/s6-rc.d/nginx/run index 3ac89f7137..8e53d2127a 100755 --- a/docker/main/rootfs/etc/s6-overlay/s6-rc.d/nginx/run +++ b/docker/main/rootfs/etc/s6-overlay/s6-rc.d/nginx/run @@ -100,6 +100,10 @@ echo "$nginx_settings" | \ if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then chown -R frigate:frigate /tmp/nginx + # error_log/access_log /dev/stdout make nginx REOPEN the s6 log pipe by + # path, and s6 created it root-owned 0600; without this the non-root + # master exits with "open() /dev/stdout failed (13: Permission denied)" + chown frigate /dev/stdout # self-signed certs are root-generated; tolerant because mounted certs may be :ro if [ -f "$letsencrypt_path/privkey.pem" ]; then chown frigate:frigate "$letsencrypt_path/privkey.pem" "$letsencrypt_path/fullchain.pem" 2>/dev/null || true @@ -108,12 +112,14 @@ fi # Replace the bash process with the NGINX process, redirecting stderr to stdout exec 2>&1 +# -e stderr: the compile-time default error log under /usr/local/nginx/logs +# is not writable by the runtime user and would alert before config load if [[ "$(id -u)" -ne 0 || "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then exec \ s6-notifyoncheck -t 30000 -n 1 \ - nginx -c /tmp/nginx/conf/nginx.conf + nginx -e stderr -c /tmp/nginx/conf/nginx.conf else exec \ s6-notifyoncheck -t 30000 -n 1 \ - s6-setuidgid frigate nginx -c /tmp/nginx/conf/nginx.conf + s6-setuidgid frigate nginx -e stderr -c /tmp/nginx/conf/nginx.conf fi