diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index dadfd74a66..dd208591b5 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -97,8 +97,11 @@ jobs: exit 1 fi # -t must NOT run as root: ngx_create_paths would chown the live cache - # and temp dirs to the `user root` directive user, breaking the workers - docker exec frigate /command/s6-setuidgid frigate /usr/local/nginx/sbin/nginx -e stderr -t -c /tmp/nginx/conf/nginx.conf + # and temp dirs to the `user root` directive user, breaking the workers. + # stdout goes to /dev/null because -t reopens the config's + # error_log/access_log /dev/stdout by path, and the docker exec pipe + # is root-owned; -t reports on stderr, so nothing is lost + docker exec frigate /command/s6-setuidgid frigate bash -c '/usr/local/nginx/sbin/nginx -e stderr -t -c /tmp/nginx/conf/nginx.conf >/dev/null' docker exec frigate stat -c %a /etc/letsencrypt/live/frigate/privkey.pem | grep -qx 600 docker exec frigate stat -c %a /dev/shm/go2rtc.yaml | grep -qx 640 - name: Assert services run as non-root diff --git a/docs/docs/configuration/non_root.md b/docs/docs/configuration/non_root.md index 49c8499dca..94526286ed 100644 --- a/docs/docs/configuration/non_root.md +++ b/docs/docs/configuration/non_root.md @@ -77,4 +77,4 @@ go2rtc's ffmpeg processes no longer appear in Intel GPU stats. Frigate reads per If you mount your own TLS certificate at `/etc/letsencrypt/live/frigate`, the private key has to be readable by the runtime user. Frigate won't change ownership of a certificate you supplied, since the mount may be read-only. -If you're debugging nginx, run the config check as the runtime user: `docker exec frigate /command/s6-setuidgid frigate nginx -t -c /tmp/nginx/conf/nginx.conf`. Running `nginx -t` as root hands nginx's runtime directories to root as a side effect, which breaks the running workers until the service restarts. +If you're debugging nginx, run the config check as the runtime user with stdout discarded: `docker exec frigate /command/s6-setuidgid frigate bash -c 'nginx -t -c /tmp/nginx/conf/nginx.conf >/dev/null'`. Running `nginx -t` as root hands nginx's runtime directories to root as a side effect, which breaks the running workers until the service restarts, and the config's `/dev/stdout` logs can't be reopened through a root-owned `docker exec` pipe (the results print on stderr either way).