Josh Hawkins
24411fc4ab
link the migration script to the repo
2026-08-29 16:38:05 -05:00
Josh Hawkins
92c4aae7d7
clarify the non-root docs
2026-08-29 16:31:10 -05:00
Josh Hawkins
496327985a
stop telling users device access needs host side setup
2026-08-29 16:16:11 -05:00
Josh Hawkins
3f86876630
document automatic device access grants
2026-08-29 15:59:23 -05:00
Josh Hawkins
3c9e77ffb5
assert device access grants in CI
2026-08-29 15:59:23 -05:00
Josh Hawkins
d5eca09797
grant runtime users access to mapped device nodes at boot
2026-08-29 15:59:23 -05:00
Josh Hawkins
49f520d3e5
install acl for device access grants
2026-08-29 15:59:23 -05:00
Josh Hawkins
b9ce2988d8
clean up
2026-08-29 15:59:23 -05:00
Josh Hawkins
39d2883a87
clarify granular root services docs
2026-08-29 15:59:23 -05:00
Josh Hawkins
a572936d91
skip missing media paths in the per-boot ownership sweep
2026-08-29 15:59:23 -05:00
Josh Hawkins
208f606d5a
clear the cached runtime ids when ownership tests finish
2026-08-29 15:59:23 -05:00
Josh Hawkins
0c366aeace
own every directory level created for a recording segment
2026-08-29 15:59:23 -05:00
Josh Hawkins
9b089c4bcb
document FRIGATE_ROOT_SERVICES
2026-08-29 15:59:23 -05:00
Josh Hawkins
f873933aab
assert granular root services in CI
2026-08-29 15:59:23 -05:00
Josh Hawkins
576949f7c3
recommend FRIGATE_ROOT_SERVICES in the bandwidth stats warning
2026-08-29 15:59:23 -05:00
Josh Hawkins
a2883a6509
chown the database files after init
2026-08-29 15:59:23 -05:00
Josh Hawkins
2f450ea661
chown recordings, previews, and exports to the runtime user at create
2026-08-29 15:59:23 -05:00
Josh Hawkins
e8b2e06323
cache the runtime ids in the ownership helper
2026-08-29 15:59:23 -05:00
Josh Hawkins
903c59ff8c
record the root-services mode in the sentinel and sweep small trees each boot
2026-08-29 15:59:23 -05:00
Josh Hawkins
9d3a38d234
let services listed in FRIGATE_ROOT_SERVICES skip the privilege drop
2026-08-29 15:59:23 -05:00
Josh Hawkins
53ffa72e28
validate FRIGATE_ROOT_SERVICES and fail fast on unknown names
2026-08-29 15:59:23 -05:00
Josh Hawkins
dda3730a76
add a service-runs-as-root helper for granular root services
2026-08-29 15:59:23 -05:00
Josh Hawkins
d2c9f18d49
collapse the duplicated sentinel comment
2026-08-29 15:59:23 -05:00
Josh Hawkins
bc62eb4adc
harden root writes into unprivileged-owned paths
...
Restrict the sweep sentinel to a mount at or below /media/frigate so a
parent /media mount cannot bless a later-shadowed volume. Rebuild
/tmp/nginx root-owned each start so root's cp and tempio writes cannot
follow a symlink an unprivileged nginx planted in the previous run.
2026-08-29 15:59:23 -05:00
Josh Hawkins
17b37a08a9
reload nginx by signaling the master instead of parsing its config as root
2026-08-29 15:59:23 -05:00
Josh Hawkins
2cd51a31a8
make bundled models readable by the runtime user
2026-08-29 15:59:23 -05:00
Josh Hawkins
93470c4ea5
hand /tmp/cache to the runtime user before services start
2026-08-29 15:59:23 -05:00
Josh Hawkins
9e356f1d3f
skip lost+found during the ownership sweep
2026-08-29 15:59:23 -05:00
Josh Hawkins
890cd751ae
document network storage ownership and the remaining detector hardware
2026-08-29 15:59:23 -05:00
Josh Hawkins
69e30ac3b6
expand the non-root device access docs with diagnosis steps and udev rules
2026-08-29 15:59:23 -05:00
Josh Hawkins
11db4a2756
document EXTRA_GROUPS as the only device access path for dropped services
2026-08-29 15:59:23 -05:00
Josh Hawkins
7f175e1a17
report progress during the ownership sweep
2026-08-29 15:59:23 -05:00
Josh Hawkins
f776fffb9e
unwrap hard-wrapped prose in the installation docs
2026-08-29 15:59:23 -05:00
Josh Hawkins
e8987fc22c
discard stdout for the unprivileged smoke nginx -t
2026-08-29 15:59:23 -05:00
Josh Hawkins
04bb2f4ed1
re-own the nginx shm cache on service restart
2026-08-29 15:59:23 -05:00
Josh Hawkins
ab393c2cb2
run smoke nginx -t and the write probe as the runtime user
2026-08-29 15:59:23 -05:00
Josh Hawkins
1f68ba0cd4
set HOME to /config for non-root services
2026-08-29 15:59:23 -05:00
Josh Hawkins
e7a0743ec0
chown the s6 log pipe so non-root nginx can reopen /dev/stdout
2026-08-29 15:59:23 -05:00
Josh Hawkins
8f5c441239
tolerate homekit config chown failures in the go2rtc run script
2026-08-29 15:59:23 -05:00
Josh Hawkins
8119bea0b3
only write the sweep sentinel when a media volume is mounted
2026-08-29 15:59:23 -05:00
Josh Hawkins
b07e36237a
Assert non-root services, JWT migration, and escape hatch in CI
2026-08-29 15:59:23 -05:00
Josh Hawkins
55a8672896
Create /media/frigate after the ownership sweep
2026-08-29 15:59:23 -05:00
Josh Hawkins
cb5bfe1bd7
Document non-root operation and per-hardware device access
2026-08-29 15:59:23 -05:00
Josh Hawkins
944541f41c
Hand TensorRT model cache ownership to the runtime user
2026-08-29 15:59:23 -05:00
Josh Hawkins
5d9f715c35
Disable bandwidth stats gracefully when not running as root
2026-08-29 15:59:23 -05:00
Josh Hawkins
b7368197a2
Run nginx as the frigate user with writable state in /tmp/nginx
2026-08-29 15:59:23 -05:00
Josh Hawkins
7530590066
Run go2rtc as its own restricted user
2026-08-29 15:59:23 -05:00
Josh Hawkins
9ce146fd99
Run the frigate service as the frigate user
2026-08-29 15:59:23 -05:00
Josh Hawkins and GitHub
a1fd978cab
switch nginx-vod-module to the maintained dio-az fork ( #24123 )
...
The `v1.x` line is the same muxed fMP4 code as Kaltura's 1.31 with fixes backported, so the mapping JSON, manifest routes, and ffmpeg consumers are unchanged. The `MAX_CLIPS` patch applies as-is and the HEVC workaround is rewritten for the fork's reformatted source.
`vod_hls_version 6` is now explicit because the fork replaced Kaltura's automatic version calculation with a directive that defaults to 4 and only warns when fmp4 needs 6, so playlists were being stamped `EXT-X-VERSION:4` while carrying `EXT-X-MAP`. The `error_page 502 =404` hack is gone: https://github.com/kaltura/nginx-vod-module/issues/468 is a `vod_mode remote` bug and we're `mapped`, so those 502s were really `_vod_response` returning 404 upstream. The fork maps that through now, and the hack was also turning real 5xx into "no recordings".
2026-08-28 12:48:52 -06:00
Josh Hawkins and GitHub
5de5cee3c6
Fix LPR vehicle message for multiple models ( #24119 )
...
* use the camera's model for the lpr vehicle check
`FrigateConfig.model` became `models[]` in the detector refactor, so this didn't compile on 0.19. Each camera has its own detector/model pair now, so the check resolves the camera's scene with `getModelForCamera` instead of looking at every model.
* use camera config model
* fix export test
2026-08-28 12:26:05 -05:00