mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-10-06 14:52:47 +03:00
Compare commits
65
Commits
ab20815584
..
master
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
cb745d0a50 | ||
|
|
e912d0852b | ||
|
|
321e78e65b | ||
|
|
17a8efa09c | ||
|
|
160d213025 | ||
|
|
b749b0bbc5 | ||
|
|
e37041c879 | ||
|
|
61e50a366f | ||
|
|
4e196516dd | ||
|
|
3941355051 | ||
|
|
1a278630da | ||
|
|
9d0d8a99bb | ||
|
|
bbc412763d | ||
|
|
ac9ac50df5 | ||
|
|
93aa6c4174 | ||
|
|
26e6adee88 | ||
|
|
de416b7ae7 | ||
|
|
06967fec91 | ||
|
|
d69107de33 | ||
|
|
04480a18b6 | ||
|
|
b02aea03cd | ||
|
|
51171319a4 | ||
|
|
b1b725b80a | ||
|
|
77a66e75c6 | ||
|
|
4ac92dac72 | ||
|
|
6ceb370abb | ||
|
|
dfefc5a64b | ||
|
|
97dec9d046 | ||
|
|
ffcadb440e | ||
|
|
a381a88b29 | ||
|
|
9e74adf812 | ||
|
|
287fc42404 | ||
|
|
b4d5035b79 | ||
|
|
7497ef7506 | ||
|
|
0d5038c7a0 | ||
|
|
c71939acc2 | ||
|
|
e983825781 | ||
|
|
25681444d4 | ||
|
|
47d25254e9 | ||
|
|
3e6d60fcac | ||
|
|
77d6b0540d | ||
|
|
632af09f73 | ||
|
|
10eb677e4c | ||
|
|
bc3e4a0b35 | ||
|
|
08a13d955e | ||
|
|
ac16decf05 | ||
|
|
6e106854e4 | ||
|
|
c6688c8ce7 | ||
|
|
149362c77f | ||
|
|
2117b58aba | ||
|
|
a529656a90 | ||
|
|
c1b56b51b0 | ||
|
|
d37dff1b49 | ||
|
|
a745070b76 | ||
|
|
4ffe687c44 | ||
|
|
59269238ed | ||
|
|
02da563712 | ||
|
|
a670972a4f | ||
|
|
c4d46b7ed3 | ||
|
|
baa1ba718c | ||
|
|
359d44fc8f | ||
|
|
80efea2554 | ||
|
|
592775bd19 | ||
|
|
aee6aa1845 | ||
|
|
50a2b6729e |
@@ -42,260 +42,6 @@ jobs:
|
||||
tags: ${{ steps.setup.outputs.image-name }}-amd64
|
||||
cache-from: type=registry,ref=${{ steps.setup.outputs.cache-name }}-amd64
|
||||
cache-to: type=registry,ref=${{ steps.setup.outputs.cache-name }}-amd64,mode=max
|
||||
smoke_test:
|
||||
runs-on: ubuntu-22.04
|
||||
name: AMD64 Smoke Test
|
||||
needs:
|
||||
- amd64_build
|
||||
steps:
|
||||
- name: Check out code
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Set up QEMU and Buildx
|
||||
id: setup
|
||||
uses: ./.github/actions/setup
|
||||
with:
|
||||
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
- name: Start container
|
||||
run: |
|
||||
mkdir -p /tmp/frigate-config /tmp/frigate-media
|
||||
printf 'mqtt:\n enabled: false\ncameras: {}\n' > /tmp/frigate-config/config.yml
|
||||
# simulate a root-era install: root-owned 0600 jwt secret pre-exists
|
||||
docker run --rm -v /tmp/frigate-config:/config --entrypoint bash \
|
||||
${{ steps.setup.outputs.image-name }}-amd64 \
|
||||
-c "python3 -c 'import secrets; open(\"/config/.jwt_secret\",\"w\").write(secrets.token_hex(64))' && chmod 600 /config/.jwt_secret && chown 0:0 /config/.jwt_secret"
|
||||
docker run -d --name frigate --shm-size 256m \
|
||||
-v /tmp/frigate-config:/config \
|
||||
-v /tmp/frigate-media:/media/frigate \
|
||||
--mount type=tmpfs,target=/tmp/cache,tmpfs-size=100000000 \
|
||||
-p 5000:5000 -p 8971:8971 \
|
||||
${{ steps.setup.outputs.image-name }}-amd64
|
||||
- name: Wait for API
|
||||
run: |
|
||||
for i in $(seq 1 60); do
|
||||
curl -fs http://127.0.0.1:5000/api/version && exit 0
|
||||
sleep 5
|
||||
done
|
||||
echo "API never came up"; docker logs frigate; exit 1
|
||||
- name: Assert security headers and permissions
|
||||
run: |
|
||||
headers=$(curl -ksI https://127.0.0.1:8971/)
|
||||
echo "$headers"
|
||||
echo "$headers" | grep -qi "x-content-type-options: nosniff"
|
||||
echo "$headers" | grep -qi "referrer-policy: strict-origin-when-cross-origin"
|
||||
# server_tokens off: Server header must not include a version.
|
||||
# written as an if rather than "! grep", because bash exempts a
|
||||
# negated command from set -e and the assertion would never fail
|
||||
if echo "$headers" | grep -qiE "^server: nginx/[0-9]"; then
|
||||
echo "Server header leaks the nginx version; server_tokens is not off"
|
||||
exit 1
|
||||
fi
|
||||
# Frigate never ships frame-ancestors: HA's Webpage card and iframe
|
||||
# panels frame it cross-origin and it would break them silently
|
||||
if echo "$headers" | grep -qi "frame-ancestors"; then
|
||||
echo "response carries frame-ancestors, which breaks cross-origin iframe embedding"
|
||||
exit 1
|
||||
fi
|
||||
# -t as root would chown the live cache and temp dirs to the `user`
|
||||
# directive user; stdout discarded because -t reopens the config's
|
||||
# /dev/stdout logs and the docker exec pipe is root-owned
|
||||
docker exec frigate /command/s6-setuidgid frigate bash -c '/usr/local/nginx/sbin/nginx -e stderr -t -c /tmp/nginx/conf/nginx.conf >/dev/null'
|
||||
docker exec frigate stat -c %a /etc/letsencrypt/live/frigate/privkey.pem | grep -qx 600
|
||||
docker exec frigate stat -c %a /dev/shm/go2rtc.yaml | grep -qx 640
|
||||
- name: Assert services run as non-root
|
||||
run: |
|
||||
ps_out=$(docker exec frigate ps -eo user=,comm=)
|
||||
echo "$ps_out"
|
||||
assert_nonroot() {
|
||||
# the process must exist AND no instance of it may run as root
|
||||
echo "$ps_out" | grep -qw "$1" || { echo "$1 is not running"; exit 1; }
|
||||
if echo "$ps_out" | grep -w "$1" | grep -q '^root'; then
|
||||
echo "$1 is running as root"; exit 1
|
||||
fi
|
||||
}
|
||||
assert_nonroot python3
|
||||
assert_nonroot go2rtc
|
||||
assert_nonroot nginx
|
||||
# root-era jwt secret must have been captured by the sweep and the
|
||||
# auth stack must be functional: wrong creds => clean 401, not 500
|
||||
docker exec frigate stat -c %u /config/.jwt_secret | grep -qx "$(docker exec frigate id -u frigate)"
|
||||
code=$(curl -s -o /dev/null -w '%{http_code}' -X POST http://127.0.0.1:5000/api/login \
|
||||
-H 'content-type: application/json' -d '{"user":"admin","password":"definitely-wrong"}')
|
||||
[ "$code" = "401" ] || { echo "login endpoint returned $code"; exit 1; }
|
||||
# a root nginx -t above would have chowned the runtime dirs to root
|
||||
owners=$(docker exec frigate stat -c %U /tmp/nginx /dev/shm/nginx_cache)
|
||||
echo "$owners"
|
||||
if echo "$owners" | grep -qvx frigate; then
|
||||
echo "nginx runtime dirs are not owned by frigate"; exit 1
|
||||
fi
|
||||
# runtime user can write recordings storage
|
||||
docker exec frigate /command/s6-setuidgid frigate touch /media/frigate/.write-probe
|
||||
docker exec frigate rm /media/frigate/.write-probe
|
||||
# tmpfs mount per the docs: arrives root-owned, holds the ZMQ IPC sockets
|
||||
docker exec frigate /command/s6-setuidgid frigate touch /tmp/cache/.write-probe
|
||||
docker exec frigate rm /tmp/cache/.write-probe
|
||||
# models are baked in as root and archive members can carry root-only modes
|
||||
docker exec frigate /command/s6-setuidgid frigate sh -c '
|
||||
for f in /cpu_model.tflite /edgetpu_model.tflite /cpu_audio_model.tflite \
|
||||
/labelmap.txt /audio-labelmap.txt /openvino-model/*; do
|
||||
[ -e "$f" ] || continue
|
||||
test -r "$f" || { echo "$f is not readable by the runtime user"; exit 1; }
|
||||
done'
|
||||
- name: Assert device access grants
|
||||
run: |
|
||||
# a fake accelerator node created after boot, then the oneshot re-run
|
||||
docker exec frigate mknod /dev/apex_9 c 120 99
|
||||
docker exec frigate /etc/s6-overlay/s6-rc.d/init-devices/run
|
||||
acl=$(docker exec frigate getfacl -p /dev/apex_9)
|
||||
echo "$acl"
|
||||
echo "$acl" | grep -q "user:frigate:rw-"
|
||||
echo "$acl" | grep -q "user:go2rtc:rw-"
|
||||
# the usb tree gets recursive grants plus a default ACL that
|
||||
# newly created nodes inherit (the Coral re-enumeration path)
|
||||
docker exec frigate sh -c 'mkdir -p /dev/bus/usb/001 && mknod /dev/bus/usb/001/002 c 189 1'
|
||||
docker exec frigate /etc/s6-overlay/s6-rc.d/init-devices/run
|
||||
docker exec frigate getfacl -p /dev/bus/usb/001 | grep -q "user:frigate:rwx"
|
||||
docker exec frigate sh -c 'mknod /dev/bus/usb/001/099 c 189 98 && chmod 664 /dev/bus/usb/001/099'
|
||||
inherited=$(docker exec frigate getfacl -p /dev/bus/usb/001/099)
|
||||
echo "$inherited"
|
||||
echo "$inherited" | grep -q "user:frigate:rw-"
|
||||
# getfacl prints granted perms even when the mask clamps them to
|
||||
# nothing, with a trailing "#effective:" comment; a clamped ACL must
|
||||
# fail this assertion, not sneak past it. The check is scoped to the
|
||||
# runtime users because the inherited group:: entry is always clamped
|
||||
# on a non-directory, so an unscoped grep could never pass.
|
||||
if echo "$inherited" | grep -E "^user:(frigate|go2rtc):" | grep -q "effective"; then
|
||||
echo "inherited ACL is mask-clamped and grants no real access"; exit 1
|
||||
fi
|
||||
# hardware that is absent must stay silent: the literal table entries
|
||||
# are not globs, so nullglob does not drop them and only an existence
|
||||
# check keeps them from warning on every boot
|
||||
out=$(docker exec frigate /etc/s6-overlay/s6-rc.d/init-devices/run)
|
||||
echo "$out"
|
||||
if echo "$out" | grep -q "WARN"; then
|
||||
echo "grant warned about device nodes that do not exist"; exit 1
|
||||
fi
|
||||
- name: Assert escape hatch restores root
|
||||
run: |
|
||||
mkdir -p /tmp/frigate-config-root
|
||||
printf 'mqtt:\n enabled: false\ncameras: {}\n' > /tmp/frigate-config-root/config.yml
|
||||
# pre-seed so the absence check proves the rm -f, not a vacuous pass
|
||||
echo "2:1000:1000" > /tmp/frigate-config-root/.permissions_version
|
||||
docker run -d --name frigate-root --shm-size 256m \
|
||||
-e FRIGATE_RUN_AS_ROOT=true \
|
||||
-v /tmp/frigate-config-root:/config \
|
||||
${{ steps.setup.outputs.image-name }}-amd64
|
||||
up=0
|
||||
for i in $(seq 1 60); do
|
||||
docker exec frigate-root curl -fs http://127.0.0.1:5000/api/version && up=1 && break
|
||||
sleep 5
|
||||
done
|
||||
if [ "$up" -ne 1 ]; then echo "escape hatch container never healthy"; docker logs frigate-root; exit 1; fi
|
||||
ps_out=$(docker exec frigate-root ps -eo user=,comm=)
|
||||
echo "$ps_out"
|
||||
echo "$ps_out" | grep -w python3 | grep -q '^root'
|
||||
echo "$ps_out" | grep -w go2rtc | grep -q '^root'
|
||||
echo "$ps_out" | grep -w nginx | grep -q '^root'
|
||||
# an if, not ! test: bash exempts negated commands from set -e
|
||||
if docker exec frigate-root test -f /config/.permissions_version; then
|
||||
echo "escape hatch did not delete the sweep sentinel"; exit 1
|
||||
fi
|
||||
docker rm -f frigate-root
|
||||
- name: Assert granular root services
|
||||
run: |
|
||||
mkdir -p /tmp/frigate-config-granular /tmp/frigate-media-granular
|
||||
printf 'mqtt:\n enabled: false\ncameras: {}\n' > /tmp/frigate-config-granular/config.yml
|
||||
docker run -d --name frigate-granular --shm-size 256m \
|
||||
-e FRIGATE_ROOT_SERVICES=frigate \
|
||||
-v /tmp/frigate-config-granular:/config \
|
||||
-v /tmp/frigate-media-granular:/media/frigate \
|
||||
${{ steps.setup.outputs.image-name }}-amd64
|
||||
up=0
|
||||
for i in $(seq 1 60); do
|
||||
docker exec frigate-granular curl -fs http://127.0.0.1:5000/api/version && up=1 && break
|
||||
sleep 5
|
||||
done
|
||||
if [ "$up" -ne 1 ]; then echo "granular container never became healthy"; docker logs frigate-granular; exit 1; fi
|
||||
ps_out=$(docker exec frigate-granular ps -eo user=,comm=)
|
||||
echo "$ps_out"
|
||||
# the listed service runs as root
|
||||
echo "$ps_out" | grep -w python3 | grep -q '^root'
|
||||
# unlisted services still drop; ifs because set -e exempts negated commands
|
||||
if echo "$ps_out" | grep -w go2rtc | grep -q '^root'; then
|
||||
echo "go2rtc is unexpectedly running as root"; exit 1
|
||||
fi
|
||||
if echo "$ps_out" | grep -w nginx | grep -q '^root'; then
|
||||
echo "nginx is unexpectedly running as root"; exit 1
|
||||
fi
|
||||
# the sweep still ran and the sentinel records the mode
|
||||
docker exec frigate-granular cat /config/.permissions_version | grep -qx "2:1000:1000:frigate"
|
||||
# the root frigate process chowns the db it creates (first-boot immediacy)
|
||||
docker exec frigate-granular stat -c %u /config/frigate.db | grep -qx 1000
|
||||
# plant a root-owned straggler; the per-boot sweep must reclaim it on restart
|
||||
docker exec frigate-granular sh -c 'mkdir -p /media/frigate/clips && touch /media/frigate/clips/straggler.webp'
|
||||
docker restart frigate-granular
|
||||
up=0
|
||||
for i in $(seq 1 60); do
|
||||
docker exec frigate-granular curl -fs http://127.0.0.1:5000/api/version && up=1 && break
|
||||
sleep 5
|
||||
done
|
||||
if [ "$up" -ne 1 ]; then echo "granular container never came back after restart"; docker logs frigate-granular; exit 1; fi
|
||||
docker exec frigate-granular stat -c %u /media/frigate/clips/straggler.webp | grep -qx 1000
|
||||
docker rm -f frigate-granular
|
||||
- name: Assert unknown root service fails fast
|
||||
run: |
|
||||
mkdir -p /tmp/frigate-config-badsvc
|
||||
printf 'mqtt:\n enabled: false\ncameras: {}\n' > /tmp/frigate-config-badsvc/config.yml
|
||||
docker run -d --name frigate-badsvc --shm-size 256m \
|
||||
-e FRIGATE_ROOT_SERVICES=frigatee \
|
||||
-v /tmp/frigate-config-badsvc:/config \
|
||||
${{ steps.setup.outputs.image-name }}-amd64
|
||||
found=0
|
||||
for i in $(seq 1 12); do
|
||||
if docker logs frigate-badsvc 2>&1 | grep -q "unknown service 'frigatee'"; then found=1; break; fi
|
||||
sleep 5
|
||||
done
|
||||
if [ "$found" -ne 1 ]; then
|
||||
echo "no fail-fast error for an unknown service name"; docker logs frigate-badsvc; exit 1
|
||||
fi
|
||||
# the failed oneshot blocks startup through the dependency chain
|
||||
if docker exec frigate-badsvc curl -fs http://127.0.0.1:5000/api/version; then
|
||||
echo "container came up despite an invalid FRIGATE_ROOT_SERVICES"; exit 1
|
||||
fi
|
||||
docker rm -f frigate-badsvc
|
||||
- name: Assert PUID/PGID remapping
|
||||
run: |
|
||||
mkdir -p /tmp/frigate-config-puid /tmp/frigate-media-puid
|
||||
printf 'mqtt:\n enabled: false\ncameras: {}\n' > /tmp/frigate-config-puid/config.yml
|
||||
docker run -d --name frigate-puid --shm-size 256m \
|
||||
-e PUID=1500 -e PGID=1500 \
|
||||
-v /tmp/frigate-config-puid:/config \
|
||||
-v /tmp/frigate-media-puid:/media/frigate \
|
||||
${{ steps.setup.outputs.image-name }}-amd64
|
||||
up=0
|
||||
for i in $(seq 1 60); do
|
||||
docker exec frigate-puid curl -fs http://127.0.0.1:5000/api/version && up=1 && break
|
||||
sleep 5
|
||||
done
|
||||
if [ "$up" -ne 1 ]; then echo "PUID container never became healthy"; docker logs frigate-puid; exit 1; fi
|
||||
docker exec frigate-puid id -u frigate | grep -qx 1500
|
||||
docker exec frigate-puid id -g frigate | grep -qx 1500
|
||||
docker exec frigate-puid cat /config/.permissions_version | grep -qx "2:1500:1500"
|
||||
# second boot must skip the sweep (sentinel hit). Poll rather than
|
||||
# sleep: the string can only come from the second boot (the first
|
||||
# had no sentinel), so grepping the full log is unambiguous.
|
||||
docker restart frigate-puid
|
||||
ok=0
|
||||
for i in $(seq 1 30); do
|
||||
docker logs frigate-puid 2>&1 | grep -q "already applied" && ok=1 && break
|
||||
sleep 2
|
||||
done
|
||||
if [ "$ok" -ne 1 ]; then echo "sentinel skip never logged"; docker logs frigate-puid; exit 1; fi
|
||||
docker rm -f frigate-puid
|
||||
- name: Teardown
|
||||
if: always()
|
||||
run: docker rm -f frigate || true
|
||||
arm64_build:
|
||||
runs-on: ubuntu-22.04-arm
|
||||
name: ARM Build
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
default_target: local
|
||||
|
||||
COMMIT_HASH := $(shell git log -1 --pretty=format:"%h"|tail -1)
|
||||
VERSION = 0.19.0
|
||||
VERSION = 0.18.1
|
||||
IMAGE_REPO ?= ghcr.io/blakeblackshear/frigate
|
||||
GITHUB_REF_NAME ?= $(shell git rev-parse --abbrev-ref HEAD)
|
||||
BOARDS= #Initialized empty
|
||||
|
||||
+3
-27
@@ -60,10 +60,10 @@ ARG DEBIAN_FRONTEND
|
||||
RUN --mount=type=bind,source=docker/main/build_intel_media_driver.sh,target=/deps/build_intel_media_driver.sh \
|
||||
/deps/build_intel_media_driver.sh
|
||||
|
||||
FROM wget AS go2rtc
|
||||
FROM scratch AS go2rtc
|
||||
ARG TARGETARCH
|
||||
RUN --mount=type=bind,source=docker/main/install_go2rtc.sh,target=/deps/install_go2rtc.sh \
|
||||
/deps/install_go2rtc.sh
|
||||
WORKDIR /rootfs/usr/local/go2rtc/bin
|
||||
ADD --link --chmod=755 "https://github.com/AlexxIT/go2rtc/releases/download/v1.9.14/go2rtc_linux_${TARGETARCH}" go2rtc
|
||||
|
||||
FROM wget AS tempio
|
||||
ARG TARGETARCH
|
||||
@@ -146,8 +146,6 @@ RUN wget -q https://github.com/openvinotoolkit/open_model_zoo/raw/master/data/da
|
||||
RUN wget -qO - https://www.kaggle.com/api/v1/models/google/yamnet/tfLite/classification-tflite/1/download | tar xvz && mv 1.tflite cpu_audio_model.tflite
|
||||
COPY audio-labelmap.txt .
|
||||
|
||||
RUN chmod -R a+rX /rootfs
|
||||
|
||||
|
||||
FROM wget AS s6-overlay
|
||||
ARG TARGETARCH
|
||||
@@ -267,23 +265,6 @@ ENV PATH="/usr/local/go2rtc/bin:/usr/local/tempio/bin:/usr/local/nginx/sbin:${PA
|
||||
RUN --mount=type=bind,source=docker/main/install_deps.sh,target=/deps/install_deps.sh \
|
||||
/deps/install_deps.sh
|
||||
|
||||
# Runtime users. frigate may be remapped at start via PUID/PGID (init-usermod)
|
||||
# or replaced entirely with docker's --user. go2rtc is intentionally separate
|
||||
# and more restricted. frigate-data is the shared group for /config access.
|
||||
# -o tolerates variant base images that already contain uid/gid 1000.
|
||||
RUN groupadd -o --gid 1000 frigate \
|
||||
&& useradd -o --uid 1000 --gid frigate --no-create-home --shell /usr/sbin/nologin frigate \
|
||||
&& groupadd --system go2rtc \
|
||||
&& useradd --system --gid go2rtc --no-create-home --shell /usr/sbin/nologin go2rtc \
|
||||
&& groupadd --system frigate-data \
|
||||
&& usermod -aG frigate-data frigate \
|
||||
&& usermod -aG frigate-data go2rtc \
|
||||
&& for grp in video render plugdev audio; do \
|
||||
if getent group "$grp" >/dev/null; then \
|
||||
usermod -aG "$grp" frigate && usermod -aG "$grp" go2rtc; \
|
||||
fi; \
|
||||
done
|
||||
|
||||
ENV DEFAULT_FFMPEG_VERSION="8.0"
|
||||
ENV INCLUDED_FFMPEG_VERSIONS="${DEFAULT_FFMPEG_VERSION}:7.0:5.0"
|
||||
|
||||
@@ -326,11 +307,6 @@ HEALTHCHECK --start-period=300s --start-interval=5s --interval=15s --timeout=5s
|
||||
# Frigate deps with Node.js and NPM for devcontainer
|
||||
FROM deps AS devcontainer
|
||||
|
||||
# /config here is the developer's bind-mounted checkout, not a data volume, so
|
||||
# the prepare ownership sweep must not run: it would chown the source tree to
|
||||
# the runtime uid and lock out any container user that isn't 1000.
|
||||
ENV FRIGATE_RUN_AS_ROOT=true
|
||||
|
||||
# Do not start the actual Frigate service on devcontainer as it will be started by VS Code
|
||||
# But start a fake service for simulating the logs
|
||||
COPY docker/main/fake_frigate_run /etc/s6-overlay/s6-rc.d/frigate/run
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
set -euxo pipefail
|
||||
|
||||
NGINX_VERSION="1.27.4"
|
||||
VOD_MODULE_VERSION="v1.9.1"
|
||||
VOD_MODULE_VERSION="1.31"
|
||||
SECURE_TOKEN_MODULE_VERSION="1.5"
|
||||
SET_MISC_MODULE_VERSION="v0.33"
|
||||
NGX_DEVEL_KIT_VERSION="v0.3.3"
|
||||
@@ -31,24 +31,24 @@ wget -nv https://nginx.org/download/nginx-${NGINX_VERSION}.tar.gz
|
||||
tar -zxf nginx-${NGINX_VERSION}.tar.gz -C /tmp/nginx --strip-components=1
|
||||
rm nginx-${NGINX_VERSION}.tar.gz
|
||||
mkdir /tmp/nginx-vod-module
|
||||
wget -nv https://github.com/dio-az/nginx-vod-module/archive/refs/tags/${VOD_MODULE_VERSION}.tar.gz
|
||||
wget -nv https://github.com/kaltura/nginx-vod-module/archive/refs/tags/${VOD_MODULE_VERSION}.tar.gz
|
||||
tar -zxf ${VOD_MODULE_VERSION}.tar.gz -C /tmp/nginx-vod-module --strip-components=1
|
||||
rm ${VOD_MODULE_VERSION}.tar.gz
|
||||
# Patch MAX_CLIPS to allow more clips to be added than the default 128
|
||||
sed -i 's/MAX_CLIPS (128)/MAX_CLIPS (1080)/g' /tmp/nginx-vod-module/vod/media_set.h
|
||||
patch -d /tmp/nginx-vod-module/ -p1 << 'EOF'
|
||||
--- a/vod/avc_hevc_parser.c
|
||||
+++ b/vod/avc_hevc_parser.c
|
||||
@@ -2,6 +2,9 @@
|
||||
|
||||
--- a/vod/avc_hevc_parser.c 2022-06-27 11:38:10.000000000 +0000
|
||||
+++ b/vod/avc_hevc_parser.c 2023-01-16 11:25:10.900521298 +0000
|
||||
@@ -3,6 +3,9 @@
|
||||
bool_t
|
||||
avc_hevc_parser_rbsp_trailing_bits(bit_reader_state_t* reader) {
|
||||
avc_hevc_parser_rbsp_trailing_bits(bit_reader_state_t* reader)
|
||||
{
|
||||
+ // https://github.com/blakeblackshear/frigate/issues/4572
|
||||
+ return TRUE;
|
||||
+
|
||||
uint32_t one_bit;
|
||||
|
||||
if (reader->stream.eof_reached) {
|
||||
if (reader->stream.eof_reached)
|
||||
EOF
|
||||
|
||||
|
||||
|
||||
+38
-78
@@ -10,7 +10,7 @@ apt-get -qq install --no-install-recommends -y \
|
||||
gnupg \
|
||||
wget \
|
||||
lbzip2 \
|
||||
procps vainfo acl \
|
||||
procps vainfo \
|
||||
unzip locales tzdata libxml2 xz-utils \
|
||||
python3.11 \
|
||||
curl \
|
||||
@@ -28,13 +28,7 @@ update-alternatives --install /usr/bin/python3 python3 /usr/bin/python3.11 1
|
||||
mkdir -p -m 600 /root/.gnupg
|
||||
|
||||
# install coral runtime
|
||||
# sha256 digests of the release debs; update when bumping the libedgetpu release.
|
||||
declare -A edgetpu_checksums=(
|
||||
["amd64"]="63fd00989d29160fa9894e115156a9abe456e88751fc9be89d26e4696200441b"
|
||||
["arm64"]="eab8aa4576b4dbf738135d8094f32270b24117f77147d25cbe0f49d0144d85f2"
|
||||
)
|
||||
wget -q -O /tmp/libedgetpu1-max.deb "https://github.com/feranick/libedgetpu/releases/download/16.0TF2.17.1-1/libedgetpu1-max_16.0tf2.17.1-1.bookworm_${TARGETARCH}.deb"
|
||||
echo "${edgetpu_checksums[${TARGETARCH}]} /tmp/libedgetpu1-max.deb" | sha256sum -c -
|
||||
unset DEBIAN_FRONTEND
|
||||
yes | dpkg -i /tmp/libedgetpu1-max.deb && export DEBIAN_FRONTEND=noninteractive
|
||||
rm /tmp/libedgetpu1-max.deb
|
||||
@@ -51,41 +45,36 @@ if [[ "${TARGETARCH}" == "arm64" ]]; then
|
||||
fi
|
||||
fi
|
||||
|
||||
# sha256 digests of the ffmpeg builds, keyed "<install dir>-<arch>".
|
||||
# Upstream publishes no checksums; these come from a one-time fetch and guard
|
||||
# against later substitution. Update when bumping a build URL.
|
||||
declare -A ffmpeg_checksums=(
|
||||
["5.0-amd64"]="377abec133f9d9e8014dee1b91c9684ac8bb0b5b7d80100a57116ff837c4c0d4"
|
||||
["7.0-amd64"]="e13860eb90409c8218319c928067834ce450128e86f24cfed5cfe91ce6e31037"
|
||||
["8.0-amd64"]="9bac85054d351cdc89c0a4f45c8ea5c44df94009aabd964b719bbadd56aedae9"
|
||||
["5.0-arm64"]="57ee475407bad49910ba9b946428396e30cf075ea28a7912fbe1aa2578085af0"
|
||||
["7.0-arm64"]="16c8b04e9d0ea9c769ad964c4c453fcf05121a1947237329d2e9d8a5e43e2a3c"
|
||||
["8.0-arm64"]="cd91948468d0f11ce795a2cdaa0c69911bd1db313b49bb19c22512beb88cde69"
|
||||
)
|
||||
|
||||
# the tarballs nest their binaries under a directory named for the arch, which
|
||||
# matches TARGETARCH for both builds we consume
|
||||
install_ffmpeg() {
|
||||
local dir="$1" url="$2"
|
||||
mkdir -p "/usr/lib/ffmpeg/${dir}"
|
||||
wget -qO ffmpeg.tar.xz "${url}"
|
||||
echo "${ffmpeg_checksums[${dir}-${TARGETARCH}]} ffmpeg.tar.xz" | sha256sum -c -
|
||||
tar -xf ffmpeg.tar.xz -C "/usr/lib/ffmpeg/${dir}" --strip-components 1 "${TARGETARCH}/bin/ffmpeg" "${TARGETARCH}/bin/ffprobe"
|
||||
rm -f ffmpeg.tar.xz
|
||||
}
|
||||
|
||||
# ffmpeg -> amd64
|
||||
if [[ "${TARGETARCH}" == "amd64" ]]; then
|
||||
install_ffmpeg 5.0 "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2022-07-31-12-37/ffmpeg-n5.1-2-g915ef932a3-linux64-gpl-5.1.tar.xz"
|
||||
install_ffmpeg 7.0 "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2024-09-19-12-51/ffmpeg-n7.0.2-18-g3e6cec1286-linux64-gpl-7.0.tar.xz"
|
||||
install_ffmpeg 8.0 "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2026-06-02-14-20/ffmpeg-n8.1.1-9-g58d4114d36-linux64-gpl-8.1.tar.xz"
|
||||
mkdir -p /usr/lib/ffmpeg/5.0
|
||||
wget -qO ffmpeg.tar.xz "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2022-07-31-12-37/ffmpeg-n5.1-2-g915ef932a3-linux64-gpl-5.1.tar.xz"
|
||||
tar -xf ffmpeg.tar.xz -C /usr/lib/ffmpeg/5.0 --strip-components 1 amd64/bin/ffmpeg amd64/bin/ffprobe
|
||||
rm -rf ffmpeg.tar.xz
|
||||
mkdir -p /usr/lib/ffmpeg/7.0
|
||||
wget -qO ffmpeg.tar.xz "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2024-09-19-12-51/ffmpeg-n7.0.2-18-g3e6cec1286-linux64-gpl-7.0.tar.xz"
|
||||
tar -xf ffmpeg.tar.xz -C /usr/lib/ffmpeg/7.0 --strip-components 1 amd64/bin/ffmpeg amd64/bin/ffprobe
|
||||
rm -rf ffmpeg.tar.xz
|
||||
mkdir -p /usr/lib/ffmpeg/8.0
|
||||
wget -qO ffmpeg.tar.xz "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2026-06-02-14-20/ffmpeg-n8.1.1-9-g58d4114d36-linux64-gpl-8.1.tar.xz"
|
||||
tar -xf ffmpeg.tar.xz -C /usr/lib/ffmpeg/8.0 --strip-components 1 amd64/bin/ffmpeg amd64/bin/ffprobe
|
||||
rm -rf ffmpeg.tar.xz
|
||||
fi
|
||||
|
||||
# ffmpeg -> arm64
|
||||
if [[ "${TARGETARCH}" == "arm64" ]]; then
|
||||
install_ffmpeg 5.0 "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2022-07-31-12-37/ffmpeg-n5.1-2-g915ef932a3-linuxarm64-gpl-5.1.tar.xz"
|
||||
install_ffmpeg 7.0 "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2024-09-19-12-51/ffmpeg-n7.0.2-18-g3e6cec1286-linuxarm64-gpl-7.0.tar.xz"
|
||||
install_ffmpeg 8.0 "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2026-06-02-14-20/ffmpeg-n8.1.1-9-g58d4114d36-linuxarm64-gpl-8.1.tar.xz"
|
||||
mkdir -p /usr/lib/ffmpeg/5.0
|
||||
wget -qO ffmpeg.tar.xz "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2022-07-31-12-37/ffmpeg-n5.1-2-g915ef932a3-linuxarm64-gpl-5.1.tar.xz"
|
||||
tar -xf ffmpeg.tar.xz -C /usr/lib/ffmpeg/5.0 --strip-components 1 arm64/bin/ffmpeg arm64/bin/ffprobe
|
||||
rm -f ffmpeg.tar.xz
|
||||
mkdir -p /usr/lib/ffmpeg/7.0
|
||||
wget -qO ffmpeg.tar.xz "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2024-09-19-12-51/ffmpeg-n7.0.2-18-g3e6cec1286-linuxarm64-gpl-7.0.tar.xz"
|
||||
tar -xf ffmpeg.tar.xz -C /usr/lib/ffmpeg/7.0 --strip-components 1 arm64/bin/ffmpeg arm64/bin/ffprobe
|
||||
rm -f ffmpeg.tar.xz
|
||||
mkdir -p /usr/lib/ffmpeg/8.0
|
||||
wget -qO ffmpeg.tar.xz "https://github.com/NickM-27/FFmpeg-Builds/releases/download/autobuild-2026-06-02-14-20/ffmpeg-n8.1.1-9-g58d4114d36-linuxarm64-gpl-8.1.tar.xz"
|
||||
tar -xf ffmpeg.tar.xz -C /usr/lib/ffmpeg/8.0 --strip-components 1 arm64/bin/ffmpeg arm64/bin/ffprobe
|
||||
rm -f ffmpeg.tar.xz
|
||||
fi
|
||||
|
||||
# arch specific packages
|
||||
@@ -131,56 +120,27 @@ if [[ "${TARGETARCH}" == "amd64" ]]; then
|
||||
apt-get -qq install -y libtbb12
|
||||
|
||||
# install legacy and standard intel compute packages
|
||||
# sha256 digests of the driver debs, taken from the ww<week>.sum asset
|
||||
# compute-runtime ships per release and the checksum.sha256 on npu-driver
|
||||
# v1.19.0; intel-graphics-compiler and level-zero publish none, so those
|
||||
# five are hash-what-you-get. Refresh after a version bump with
|
||||
# `curl -sL <url> | sha256sum`, cross-checking upstream's sum where the
|
||||
# release still has one. npu-driver stopped publishing them after v1.19.0.
|
||||
declare -A intel_checksums=(
|
||||
["libigdgmm12_22.9.0_amd64.deb"]="9d712f71c18baee076de9961dda71e8089291e1bd0deb5d649ab5ba5de114f97"
|
||||
["intel-opencl-icd-legacy1_24.35.30872.36_amd64.deb"]="bbe71e4f414259e06a10cde72c29a2bd78d41b2bb2f6f8463b1806797fe66e85"
|
||||
["intel-level-zero-gpu-legacy1_1.5.30872.36_amd64.deb"]="40dfbd15ab62de036a00824b304a2aa1fa2d81ad60ef83da09cfe3c5a80c429f"
|
||||
["intel-igc-opencl_1.0.17537.24_amd64.deb"]="dd016400f87fa2b6a9fa9fbcca7eb4a2629174a29de679709f9bec5cede88b0e"
|
||||
["intel-igc-core_1.0.17537.24_amd64.deb"]="c1e1ecdfe2064c047c552651cfdcdafc504f2033afafba65654338b880048b67"
|
||||
["intel-opencl-icd_26.14.37833.4-0_amd64.deb"]="2e15eeb4fe9c1bba467a655967373eec6a20dd04cc7159de53c359f17ab53e41"
|
||||
["libze-intel-gpu1_26.14.37833.4-0_amd64.deb"]="34ce5791160d87ce6d54edb558a4030858ee1dad2afb067b9c5c58d4cde774c6"
|
||||
["intel-igc-opencl-2_2.32.7+21184_amd64.deb"]="3c9bddbfe558279402bbeaabcf9c63b8de46b956b0ad9625415fd35dda53ad52"
|
||||
["intel-igc-core-2_2.32.7+21184_amd64.deb"]="64e5230788e3a31e611e8d815a141b1facb91e5f0ef239233ef3f0614bfe3fd6"
|
||||
["level-zero_1.28.2+u22.04_amd64.deb"]="9015a579abef960166f8e943858d5c81fd4199a960f07260c1da66038257effb"
|
||||
["intel-driver-compiler-npu_1.19.0.20250707-16111289554_ubuntu22.04_amd64.deb"]="8087bfcc0872d7976d0163203c7c783a4176f813c473766587e86c7b34135dff"
|
||||
["intel-fw-npu_1.19.0.20250707-16111289554_ubuntu22.04_amd64.deb"]="740219c03495f8812c03ab74baf8199acf17d13929001105418d4ba226ba2290"
|
||||
["intel-level-zero-npu_1.19.0.20250707-16111289554_ubuntu22.04_amd64.deb"]="f4f5eb97aa7da52c7fec97e4ddfb43aae01703bbadc767bae1f2d4faf342ba42"
|
||||
)
|
||||
|
||||
fetch_intel_deb() {
|
||||
local url="$1" name
|
||||
name=$(basename "$url")
|
||||
wget -q "$url"
|
||||
echo "${intel_checksums[${name}]} ${name}" | sha256sum -c -
|
||||
}
|
||||
|
||||
# see https://github.com/intel/compute-runtime/blob/master/LEGACY_PLATFORMS.md for more info
|
||||
# needed core package
|
||||
fetch_intel_deb https://github.com/intel/compute-runtime/releases/download/26.14.37833.4/libigdgmm12_22.9.0_amd64.deb
|
||||
wget https://github.com/intel/compute-runtime/releases/download/26.14.37833.4/libigdgmm12_22.9.0_amd64.deb
|
||||
dpkg -i libigdgmm12_22.9.0_amd64.deb
|
||||
rm libigdgmm12_22.9.0_amd64.deb
|
||||
|
||||
# legacy compute-runtime packages
|
||||
fetch_intel_deb https://github.com/intel/compute-runtime/releases/download/24.35.30872.36/intel-opencl-icd-legacy1_24.35.30872.36_amd64.deb
|
||||
fetch_intel_deb https://github.com/intel/compute-runtime/releases/download/24.35.30872.36/intel-level-zero-gpu-legacy1_1.5.30872.36_amd64.deb
|
||||
fetch_intel_deb https://github.com/intel/intel-graphics-compiler/releases/download/igc-1.0.17537.24/intel-igc-opencl_1.0.17537.24_amd64.deb
|
||||
fetch_intel_deb https://github.com/intel/intel-graphics-compiler/releases/download/igc-1.0.17537.24/intel-igc-core_1.0.17537.24_amd64.deb
|
||||
wget https://github.com/intel/compute-runtime/releases/download/24.35.30872.36/intel-opencl-icd-legacy1_24.35.30872.36_amd64.deb
|
||||
wget https://github.com/intel/compute-runtime/releases/download/24.35.30872.36/intel-level-zero-gpu-legacy1_1.5.30872.36_amd64.deb
|
||||
wget https://github.com/intel/intel-graphics-compiler/releases/download/igc-1.0.17537.24/intel-igc-opencl_1.0.17537.24_amd64.deb
|
||||
wget https://github.com/intel/intel-graphics-compiler/releases/download/igc-1.0.17537.24/intel-igc-core_1.0.17537.24_amd64.deb
|
||||
# standard compute-runtime packages
|
||||
fetch_intel_deb https://github.com/intel/compute-runtime/releases/download/26.14.37833.4/intel-opencl-icd_26.14.37833.4-0_amd64.deb
|
||||
fetch_intel_deb https://github.com/intel/compute-runtime/releases/download/26.14.37833.4/libze-intel-gpu1_26.14.37833.4-0_amd64.deb
|
||||
fetch_intel_deb https://github.com/intel/intel-graphics-compiler/releases/download/v2.32.7/intel-igc-opencl-2_2.32.7+21184_amd64.deb
|
||||
fetch_intel_deb https://github.com/intel/intel-graphics-compiler/releases/download/v2.32.7/intel-igc-core-2_2.32.7+21184_amd64.deb
|
||||
wget https://github.com/intel/compute-runtime/releases/download/26.14.37833.4/intel-opencl-icd_26.14.37833.4-0_amd64.deb
|
||||
wget https://github.com/intel/compute-runtime/releases/download/26.14.37833.4/libze-intel-gpu1_26.14.37833.4-0_amd64.deb
|
||||
wget https://github.com/intel/intel-graphics-compiler/releases/download/v2.32.7/intel-igc-opencl-2_2.32.7+21184_amd64.deb
|
||||
wget https://github.com/intel/intel-graphics-compiler/releases/download/v2.32.7/intel-igc-core-2_2.32.7+21184_amd64.deb
|
||||
# npu packages
|
||||
fetch_intel_deb https://github.com/oneapi-src/level-zero/releases/download/v1.28.2/level-zero_1.28.2+u22.04_amd64.deb
|
||||
fetch_intel_deb https://github.com/intel/linux-npu-driver/releases/download/v1.19.0/intel-driver-compiler-npu_1.19.0.20250707-16111289554_ubuntu22.04_amd64.deb
|
||||
fetch_intel_deb https://github.com/intel/linux-npu-driver/releases/download/v1.19.0/intel-fw-npu_1.19.0.20250707-16111289554_ubuntu22.04_amd64.deb
|
||||
fetch_intel_deb https://github.com/intel/linux-npu-driver/releases/download/v1.19.0/intel-level-zero-npu_1.19.0.20250707-16111289554_ubuntu22.04_amd64.deb
|
||||
wget https://github.com/oneapi-src/level-zero/releases/download/v1.28.2/level-zero_1.28.2+u22.04_amd64.deb
|
||||
wget https://github.com/intel/linux-npu-driver/releases/download/v1.19.0/intel-driver-compiler-npu_1.19.0.20250707-16111289554_ubuntu22.04_amd64.deb
|
||||
wget https://github.com/intel/linux-npu-driver/releases/download/v1.19.0/intel-fw-npu_1.19.0.20250707-16111289554_ubuntu22.04_amd64.deb
|
||||
wget https://github.com/intel/linux-npu-driver/releases/download/v1.19.0/intel-level-zero-npu_1.19.0.20250707-16111289554_ubuntu22.04_amd64.deb
|
||||
|
||||
dpkg -i *.deb
|
||||
rm *.deb
|
||||
|
||||
@@ -1,19 +0,0 @@
|
||||
#!/bin/bash
|
||||
|
||||
set -euxo pipefail
|
||||
|
||||
go2rtc_version="1.9.14"
|
||||
|
||||
# sha256 digests of the release binaries; update when bumping go2rtc_version.
|
||||
declare -A go2rtc_checksums=(
|
||||
["amd64"]="32d616af226bd731678ffde328b94cfb94e30339bfefc469cfb76323144615a6"
|
||||
["arm64"]="359fabade8a7a51e81a55fe6df6b0ef81764a5e1d63179577534eaaa71904b50"
|
||||
)
|
||||
|
||||
dest_dir="/rootfs/usr/local/go2rtc/bin"
|
||||
mkdir -p "${dest_dir}"
|
||||
|
||||
wget -qO "${dest_dir}/go2rtc" \
|
||||
"https://github.com/AlexxIT/go2rtc/releases/download/v${go2rtc_version}/go2rtc_linux_${TARGETARCH}"
|
||||
echo "${go2rtc_checksums[${TARGETARCH}]} ${dest_dir}/go2rtc" | sha256sum -c -
|
||||
chmod 755 "${dest_dir}/go2rtc"
|
||||
@@ -4,29 +4,11 @@ set -euxo pipefail
|
||||
|
||||
hailo_version="4.21.0"
|
||||
|
||||
# sha256 digests of the release artifacts; update when bumping hailo_version.
|
||||
# The runtime tarball is keyed by TARGETARCH, the wheel by the python arch tag.
|
||||
declare -A hailort_checksums=(
|
||||
["amd64"]="0a57ac5f7cc8c2c3668133189d9285b55f498e8cb219797e203f6f5015fec4b3"
|
||||
["arm64"]="dd840548eb5d0d147c99aee2cb013d39d64be09c5bc63061171fcfacf4547b3f"
|
||||
["x86_64"]="8112a973ab48095399b29d883f31987828df5861b8553f614c89f098a67b3fb6"
|
||||
["aarch64"]="658432a43573280d472f6402d7934669effe7f163ba3dffa31c50bbeeaa7c01d"
|
||||
)
|
||||
|
||||
if [[ "${TARGETARCH}" == "amd64" ]]; then
|
||||
arch="x86_64"
|
||||
elif [[ "${TARGETARCH}" == "arm64" ]]; then
|
||||
arch="aarch64"
|
||||
fi
|
||||
|
||||
# downloaded rather than streamed into tar because streaming and verifying the
|
||||
# digest before extraction are mutually exclusive
|
||||
wget -qO /tmp/hailort.tar.gz "https://github.com/frigate-nvr/hailort/releases/download/v${hailo_version}/hailort-debian12-${TARGETARCH}.tar.gz"
|
||||
echo "${hailort_checksums[${TARGETARCH}]} /tmp/hailort.tar.gz" | sha256sum -c -
|
||||
tar -C / -xzf /tmp/hailort.tar.gz
|
||||
rm -f /tmp/hailort.tar.gz
|
||||
|
||||
wheel="/wheels/hailort-${hailo_version}-cp311-cp311-linux_${arch}.whl"
|
||||
mkdir -p /wheels
|
||||
wget -qO "${wheel}" "https://github.com/frigate-nvr/hailort/releases/download/v${hailo_version}/hailort-${hailo_version}-cp311-cp311-linux_${arch}.whl"
|
||||
echo "${hailort_checksums[${arch}]} ${wheel}" | sha256sum -c -
|
||||
wget -qO- "https://github.com/frigate-nvr/hailort/releases/download/v${hailo_version}/hailort-debian12-${TARGETARCH}.tar.gz" | tar -C / -xzf -
|
||||
wget -P /wheels/ "https://github.com/frigate-nvr/hailort/releases/download/v${hailo_version}/hailort-${hailo_version}-cp311-cp311-linux_${arch}.whl"
|
||||
|
||||
@@ -4,15 +4,6 @@ set -euxo pipefail
|
||||
|
||||
s6_version="3.2.1.0"
|
||||
|
||||
# sha256 digests of the release artifacts, from the .sha256 files published at
|
||||
# https://github.com/just-containers/s6-overlay/releases/tag/v3.2.1.0
|
||||
# Update these when bumping s6_version.
|
||||
declare -A s6_checksums=(
|
||||
["noarch"]="42e038a9a00fc0fef70bf0bc42f625a9c14f8ecdfe77d4ad93281edf717e10c5"
|
||||
["x86_64"]="8bcbc2cada58426f976b159dcc4e06cbb1454d5f39252b3bb0c778ccf71c9435"
|
||||
["aarch64"]="c8fd6b1f0380d399422fc986a1e6799f6a287e2cfa24813ad0b6a4fb4fa755cc"
|
||||
)
|
||||
|
||||
if [[ "${TARGETARCH}" == "amd64" ]]; then
|
||||
s6_arch="x86_64"
|
||||
elif [[ "${TARGETARCH}" == "arm64" ]]; then
|
||||
@@ -21,15 +12,8 @@ fi
|
||||
|
||||
mkdir -p /rootfs/
|
||||
|
||||
download_and_extract() {
|
||||
local arch="$1"
|
||||
local tarball="/tmp/s6-overlay-${arch}.tar.xz"
|
||||
wget -qO "${tarball}" \
|
||||
"https://github.com/just-containers/s6-overlay/releases/download/v${s6_version}/s6-overlay-${arch}.tar.xz"
|
||||
echo "${s6_checksums[${arch}]} ${tarball}" | sha256sum -c -
|
||||
tar -C /rootfs/ -Jxpf "${tarball}"
|
||||
rm -f "${tarball}"
|
||||
}
|
||||
wget -qO- "https://github.com/just-containers/s6-overlay/releases/download/v${s6_version}/s6-overlay-noarch.tar.xz" |
|
||||
tar -C /rootfs/ -Jxpf -
|
||||
|
||||
download_and_extract "noarch"
|
||||
download_and_extract "${s6_arch}"
|
||||
wget -qO- "https://github.com/just-containers/s6-overlay/releases/download/v${s6_version}/s6-overlay-${s6_arch}.tar.xz" |
|
||||
tar -C /rootfs/ -Jxpf -
|
||||
|
||||
@@ -4,14 +4,6 @@ set -euxo pipefail
|
||||
|
||||
tempio_version="2021.09.0"
|
||||
|
||||
# sha256 digests of the release binaries; update when bumping tempio_version.
|
||||
# Upstream publishes no checksums, so these come from a one-time fetch and
|
||||
# guard against later substitution rather than the original download.
|
||||
declare -A tempio_checksums=(
|
||||
["amd64"]="b7b93ebfd24c1161cec7aecfad62ab51f2241149358cef354b86cdbc6a60546f"
|
||||
["aarch64"]="3a5c32981ba68b75ed9b28497429e5a5cecbeb74c3b821b035a48b37609bb895"
|
||||
)
|
||||
|
||||
if [[ "${TARGETARCH}" == "amd64" ]]; then
|
||||
arch="amd64"
|
||||
elif [[ "${TARGETARCH}" == "arm64" ]]; then
|
||||
@@ -21,5 +13,4 @@ fi
|
||||
mkdir -p /rootfs/usr/local/tempio/bin
|
||||
|
||||
wget -q -O /rootfs/usr/local/tempio/bin/tempio "https://github.com/home-assistant/tempio/releases/download/${tempio_version}/tempio_${arch}"
|
||||
echo "${tempio_checksums[${arch}]} /rootfs/usr/local/tempio/bin/tempio" | sha256sum -c -
|
||||
chmod 755 /rootfs/usr/local/tempio/bin/tempio
|
||||
|
||||
@@ -1,12 +1,4 @@
|
||||
#!/command/with-contenv bash
|
||||
# shellcheck shell=bash
|
||||
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
# logutil-service drops to nobody and applies S6_LOGGING_SCRIPT
|
||||
exec logutil-service /dev/shm/logs/certsync
|
||||
fi
|
||||
|
||||
# Non-root (--user) fallback: logutil-service cannot change UID, so run
|
||||
# s6-log directly with the same directives S6_LOGGING_SCRIPT configures.
|
||||
# shellcheck disable=SC2086
|
||||
exec s6-log ${S6_LOGGING_SCRIPT:-T 1 n0 s10000000 T} /dev/shm/logs/certsync
|
||||
exec logutil-service /dev/shm/logs/certsync
|
||||
|
||||
@@ -6,24 +6,6 @@ set -o errexit -o nounset -o pipefail
|
||||
|
||||
# Logs should be sent to stdout so that s6 can collect them
|
||||
|
||||
# Not `nginx -s reload`: that has root parse /tmp/nginx/conf, which the
|
||||
# unprivileged nginx user can rewrite, and nginx chowns path directives on load.
|
||||
function reload_nginx() {
|
||||
local pid
|
||||
|
||||
if ! pid=$(cat /tmp/nginx/nginx.pid 2>/dev/null); then
|
||||
echo "[ERROR] No nginx pid file found, not reloading"
|
||||
return 0
|
||||
fi
|
||||
|
||||
if [[ ! "$pid" =~ ^[0-9]+$ ]] || [[ "$(cat "/proc/${pid}/comm" 2>/dev/null)" != "nginx" ]]; then
|
||||
echo "[ERROR] nginx pid file does not name a running nginx process, not reloading"
|
||||
return 0
|
||||
fi
|
||||
|
||||
kill -HUP "$pid"
|
||||
}
|
||||
|
||||
echo "[INFO] Starting certsync..."
|
||||
|
||||
lefile="/etc/letsencrypt/live/frigate/fullchain.pem"
|
||||
@@ -67,7 +49,7 @@ do
|
||||
then
|
||||
echo "[INFO] Reloading nginx to refresh TLS certificate"
|
||||
echo "$lefile: $leprint"
|
||||
reload_nginx
|
||||
/usr/local/nginx/sbin/nginx -s reload
|
||||
fi
|
||||
|
||||
sleep 60
|
||||
|
||||
@@ -1,12 +1,4 @@
|
||||
#!/command/with-contenv bash
|
||||
# shellcheck shell=bash
|
||||
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
# logutil-service drops to nobody and applies S6_LOGGING_SCRIPT
|
||||
exec logutil-service /dev/shm/logs/frigate
|
||||
fi
|
||||
|
||||
# Non-root (--user) fallback: logutil-service cannot change UID, so run
|
||||
# s6-log directly with the same directives S6_LOGGING_SCRIPT configures.
|
||||
# shellcheck disable=SC2086
|
||||
exec s6-log ${S6_LOGGING_SCRIPT:-T 1 n0 s10000000 T} /dev/shm/logs/frigate
|
||||
exec logutil-service /dev/shm/logs/frigate
|
||||
|
||||
@@ -4,19 +4,6 @@
|
||||
|
||||
set -o errexit -o nounset -o pipefail
|
||||
|
||||
runs_as_root=0
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]] || /usr/local/bin/service-runs-as-root frigate; then
|
||||
runs_as_root=1
|
||||
fi
|
||||
fi
|
||||
|
||||
# /root survives s6-setuidgid and breaks cache writes after the drop; set
|
||||
# before opt_in_out so the opt-out marker lands where the service will look
|
||||
if [[ "$runs_as_root" -eq 0 ]]; then
|
||||
export HOME=/config
|
||||
fi
|
||||
|
||||
# opt out of openvino telemetry
|
||||
if [ -e /usr/local/bin/opt_in_out ]; then
|
||||
/usr/local/bin/opt_in_out --opt_out > /dev/null 2>&1
|
||||
@@ -43,8 +30,4 @@ cd /opt/frigate || echo "[ERROR] Failed to change working directory to /opt/frig
|
||||
|
||||
# Replace the bash process with the Frigate process, redirecting stderr to stdout
|
||||
exec 2>&1
|
||||
if [[ "$(id -u)" -ne 0 || "$runs_as_root" -eq 1 ]]; then
|
||||
exec python3 -u -m frigate
|
||||
else
|
||||
exec s6-setuidgid frigate python3 -u -m frigate
|
||||
fi
|
||||
exec python3 -u -m frigate
|
||||
|
||||
@@ -1,12 +1,4 @@
|
||||
#!/command/with-contenv bash
|
||||
# shellcheck shell=bash
|
||||
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
# logutil-service drops to nobody and applies S6_LOGGING_SCRIPT
|
||||
exec logutil-service /dev/shm/logs/go2rtc
|
||||
fi
|
||||
|
||||
# Non-root (--user) fallback: logutil-service cannot change UID, so run
|
||||
# s6-log directly with the same directives S6_LOGGING_SCRIPT configures.
|
||||
# shellcheck disable=SC2086
|
||||
exec s6-log ${S6_LOGGING_SCRIPT:-T 1 n0 s10000000 T} /dev/shm/logs/go2rtc
|
||||
exec logutil-service /dev/shm/logs/go2rtc
|
||||
|
||||
@@ -4,20 +4,6 @@
|
||||
|
||||
set -o errexit -o nounset -o pipefail
|
||||
|
||||
runs_as_root=0
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]] || /usr/local/bin/service-runs-as-root go2rtc; then
|
||||
runs_as_root=1
|
||||
fi
|
||||
fi
|
||||
|
||||
# Root via FRIGATE_ROOT_SERVICES only; the escape hatch sweeps nothing and
|
||||
# leaves no unprivileged service, so /config/go2rtc stays as safe as pre-drop.
|
||||
granular_root=0
|
||||
if [[ "$runs_as_root" -eq 1 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then
|
||||
granular_root=1
|
||||
fi
|
||||
|
||||
# Logs should be sent to stdout so that s6 can collect them
|
||||
|
||||
function get_ip_and_port_from_supervisor() {
|
||||
@@ -64,6 +50,42 @@ function set_libva_version() {
|
||||
export LIBAVFORMAT_VERSION_MAJOR
|
||||
}
|
||||
|
||||
function setup_homekit_config() {
|
||||
local config_path="$1"
|
||||
|
||||
if [[ ! -f "${config_path}" ]]; then
|
||||
echo "[INFO] Creating empty config file for HomeKit..."
|
||||
: > "${config_path}"
|
||||
fi
|
||||
|
||||
# Convert YAML to JSON for jq processing
|
||||
local temp_json="/tmp/cache/homekit_config.json"
|
||||
yq eval -o=json "${config_path}" > "${temp_json}" 2>/dev/null || {
|
||||
echo "[WARNING] Failed to convert HomeKit config to JSON, skipping cleanup"
|
||||
return 0
|
||||
}
|
||||
|
||||
# Use jq to extract the homekit section, if it exists
|
||||
local homekit_json
|
||||
homekit_json=$(jq '
|
||||
if has("homekit") then {homekit: .homekit} else null end
|
||||
' "${temp_json}" 2>/dev/null) || homekit_json="null"
|
||||
|
||||
# If no homekit section, write an empty config file
|
||||
if [[ "${homekit_json}" == "null" ]]; then
|
||||
: > "${config_path}"
|
||||
else
|
||||
# Convert homekit JSON back to YAML and write to the config file
|
||||
echo "${homekit_json}" | yq eval -P - > "${config_path}" 2>/dev/null || {
|
||||
echo "[WARNING] Failed to convert cleaned config to YAML, creating minimal config"
|
||||
: > "${config_path}"
|
||||
}
|
||||
fi
|
||||
|
||||
# Clean up temp files
|
||||
rm -f "${temp_json}"
|
||||
}
|
||||
|
||||
set_libva_version
|
||||
|
||||
if [[ -f "/dev/shm/go2rtc.yaml" ]]; then
|
||||
@@ -84,23 +106,13 @@ else
|
||||
echo "[WARNING] Unable to remove existing go2rtc config. Changes made to your frigate config file may not be recognized. Please remove the /dev/shm/go2rtc.yaml from your docker host manually."
|
||||
fi
|
||||
|
||||
# HomeKit persistence. The helper is symlink-safe; hand off to go2rtc only when dropping.
|
||||
# HomeKit configuration persistence setup
|
||||
readonly homekit_config_path="/config/go2rtc_homekit.yml"
|
||||
if [[ "$(id -u)" -eq 0 && "$runs_as_root" -eq 0 ]]; then
|
||||
python3 /usr/local/go2rtc/prepare_homekit.py "${homekit_config_path}" --chown
|
||||
chown go2rtc:go2rtc /dev/shm/go2rtc.yaml 2>/dev/null || true
|
||||
else
|
||||
python3 /usr/local/go2rtc/prepare_homekit.py "${homekit_config_path}"
|
||||
fi
|
||||
setup_homekit_config "${homekit_config_path}"
|
||||
|
||||
readonly config_path="/config"
|
||||
|
||||
# the sweep hands /config to uid 1000, so a root service must not exec from it
|
||||
if [[ "$granular_root" -eq 1 && -x "${config_path}/go2rtc" ]]; then
|
||||
echo "[WARN] Ignoring '${config_path}/go2rtc' because FRIGATE_ROOT_SERVICES runs this service as root and /config is owned by the runtime user; using the embedded binary"
|
||||
echo "[WARN] Use FRIGATE_RUN_AS_ROOT=true instead if you need both a custom go2rtc build and root"
|
||||
readonly binary_path="/usr/local/go2rtc/bin/go2rtc"
|
||||
elif [[ -x "${config_path}/go2rtc" ]]; then
|
||||
if [[ -x "${config_path}/go2rtc" ]]; then
|
||||
readonly binary_path="${config_path}/go2rtc"
|
||||
echo "[WARN] Using go2rtc binary from '${binary_path}' instead of the embedded one"
|
||||
else
|
||||
@@ -113,8 +125,4 @@ echo "[INFO] Starting go2rtc..."
|
||||
# Use HomeKit config as the primary config so writebacks go there
|
||||
# The main config from Frigate will be loaded as a secondary config
|
||||
exec 2>&1
|
||||
if [[ "$(id -u)" -ne 0 || "$runs_as_root" -eq 1 ]]; then
|
||||
exec "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml
|
||||
else
|
||||
exec s6-setuidgid go2rtc "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml
|
||||
fi
|
||||
exec "${binary_path}" -config="${homekit_config_path}" -config=/dev/shm/go2rtc.yaml
|
||||
|
||||
@@ -1,104 +0,0 @@
|
||||
#!/command/with-contenv bash
|
||||
# shellcheck shell=bash
|
||||
# Grant the runtime users access to mapped-in device nodes with POSIX ACLs,
|
||||
# so --device works without host-side group or udev setup.
|
||||
# No-op when: started with --user (euid != 0), FRIGATE_RUN_AS_ROOT=true,
|
||||
# or FRIGATE_DEVICE_ACLS=false.
|
||||
|
||||
set -o errexit -o nounset -o pipefail
|
||||
|
||||
if [[ "$(id -u)" -ne 0 ]]; then
|
||||
exit 0
|
||||
fi
|
||||
|
||||
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then
|
||||
exit 0
|
||||
fi
|
||||
|
||||
if [[ "${FRIGATE_DEVICE_ACLS:-true}" == "false" ]]; then
|
||||
echo "[INFO] FRIGATE_DEVICE_ACLS=false: skipping device access grants"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
shopt -s nullglob
|
||||
|
||||
device_globs=(
|
||||
"/dev/dri/*"
|
||||
"/dev/accel/*"
|
||||
"/dev/apex_*"
|
||||
"/dev/hailo*"
|
||||
"/dev/video*"
|
||||
"/dev/kfd"
|
||||
"/dev/rknpu*"
|
||||
"/dev/mpp_service"
|
||||
"/dev/rga"
|
||||
"/dev/dma_heap/*"
|
||||
"/dev/nvhost*"
|
||||
"/dev/nvmap"
|
||||
"/dev/nvidia*"
|
||||
"/dev/memx*"
|
||||
)
|
||||
|
||||
IFS=',' read -ra extra_globs <<< "${DEVICE_ACL_PATHS:-}"
|
||||
for extra in "${extra_globs[@]}"; do
|
||||
extra="${extra//[[:space:]]/}"
|
||||
if [[ -z "$extra" ]]; then
|
||||
continue
|
||||
fi
|
||||
if [[ "$extra" != /dev/* || "$extra" == *..* ]]; then
|
||||
echo "[ERROR] DEVICE_ACL_PATHS entries must be under /dev, got '${extra}'" >&2
|
||||
exit 1
|
||||
fi
|
||||
device_globs+=("$extra")
|
||||
done
|
||||
|
||||
granted=0
|
||||
failed=0
|
||||
|
||||
grant() {
|
||||
local node="$1"
|
||||
# nullglob only drops patterns that hold a metacharacter, so a literal
|
||||
# table entry for absent hardware arrives here verbatim. Warn only about
|
||||
# nodes that exist and could not be granted.
|
||||
if [[ ! -e "$node" ]]; then
|
||||
return 0
|
||||
fi
|
||||
local spec="u:frigate:rw,u:go2rtc:rw"
|
||||
# directories need traverse or nothing under them is reachable
|
||||
if [[ -d "$node" ]]; then
|
||||
spec="u:frigate:rwx,u:go2rtc:rwx"
|
||||
fi
|
||||
if setfacl -m "$spec" "$node" 2>/dev/null; then
|
||||
granted=$((granted + 1))
|
||||
else
|
||||
failed=$((failed + 1))
|
||||
echo "[WARN] could not grant device access on ${node}; see EXTRA_GROUPS in the non-root docs for the fallback"
|
||||
fi
|
||||
}
|
||||
|
||||
for glob in "${device_globs[@]}"; do
|
||||
# shellcheck disable=SC2231
|
||||
for node in $glob; do
|
||||
grant "$node"
|
||||
done
|
||||
done
|
||||
|
||||
# USB devices re-enumerate (the Coral uploads firmware and reattaches as a new
|
||||
# node), so the directories also get a default ACL new nodes inherit. The
|
||||
# inherited grant is clamped by the creating mode's group bits, which is rw on
|
||||
# udev hosts (0664) and nothing on raw devtmpfs (0600); hardware-verified.
|
||||
if [[ -d /dev/bus/usb ]]; then
|
||||
while IFS= read -r -d '' node; do
|
||||
grant "$node"
|
||||
done < <(find /dev/bus/usb -mindepth 1 -print0)
|
||||
while IFS= read -r -d '' dir; do
|
||||
setfacl -d -m "u:frigate:rw,u:go2rtc:rw" "$dir" 2>/dev/null || \
|
||||
echo "[WARN] could not set a default ACL on ${dir}; a re-enumerating USB device may lose access"
|
||||
done < <(find /dev/bus/usb -type d -print0)
|
||||
fi
|
||||
|
||||
if [[ "$failed" -gt 0 ]]; then
|
||||
echo "[INFO] device access: granted ${granted} node(s), ${failed} failed"
|
||||
elif [[ "$granted" -gt 0 ]]; then
|
||||
echo "[INFO] device access: granted ${granted} node(s) to the runtime users"
|
||||
fi
|
||||
@@ -1 +0,0 @@
|
||||
oneshot
|
||||
@@ -1 +0,0 @@
|
||||
/etc/s6-overlay/s6-rc.d/init-devices/run
|
||||
@@ -1,95 +0,0 @@
|
||||
#!/command/with-contenv bash
|
||||
# shellcheck shell=bash
|
||||
# Remap the frigate user to PUID/PGID and register EXTRA_GROUPS.
|
||||
# No-op when: started with --user (euid != 0), FRIGATE_RUN_AS_ROOT=true,
|
||||
# or PUID/PGID already match. FRIGATE_ROOT_SERVICES is validated here too.
|
||||
|
||||
set -o errexit -o nounset -o pipefail
|
||||
|
||||
if [[ "$(id -u)" -ne 0 ]]; then
|
||||
# Started with docker --user; the host owns UID mapping entirely.
|
||||
exit 0
|
||||
fi
|
||||
|
||||
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then
|
||||
if [[ -n "${FRIGATE_ROOT_SERVICES:-}" ]]; then
|
||||
echo "[INFO] FRIGATE_RUN_AS_ROOT=true: ignoring FRIGATE_ROOT_SERVICES"
|
||||
fi
|
||||
echo "[INFO] FRIGATE_RUN_AS_ROOT=true: skipping user remapping"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# a typo must fail the boot, not silently drop a service to non-root
|
||||
if [[ -n "${FRIGATE_ROOT_SERVICES:-}" ]]; then
|
||||
IFS=',' read -ra root_services <<< "${FRIGATE_ROOT_SERVICES}"
|
||||
for entry in "${root_services[@]}"; do
|
||||
entry="${entry//[[:space:]]/}"
|
||||
if [[ -z "$entry" ]]; then
|
||||
continue
|
||||
fi
|
||||
case "$entry" in
|
||||
frigate|go2rtc|nginx) ;;
|
||||
*)
|
||||
echo "[ERROR] FRIGATE_ROOT_SERVICES contains unknown service '${entry}'; valid names are frigate, go2rtc, nginx" >&2
|
||||
exit 1
|
||||
;;
|
||||
esac
|
||||
done
|
||||
fi
|
||||
|
||||
puid="${PUID:-1000}"
|
||||
pgid="${PGID:-1000}"
|
||||
|
||||
if ! [[ "$puid" =~ ^[0-9]+$ && "$pgid" =~ ^[0-9]+$ ]]; then
|
||||
echo "[ERROR] PUID and PGID must be numeric, got '${puid}' and '${pgid}'" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Remapping to 0 would make the frigate user root, so every service would keep
|
||||
# full privilege while reporting a successful migration.
|
||||
if [[ "$puid" -eq 0 || "$pgid" -eq 0 ]]; then
|
||||
echo "[ERROR] PUID/PGID 0 would run the services as root and defeat the privilege separation." >&2
|
||||
echo "[ERROR] Set FRIGATE_RUN_AS_ROOT=true if you want to keep running as root." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# Colliding with the go2rtc ids would merge the two users and collapse the
|
||||
# separation between the main process and the network-facing restreamer.
|
||||
go2rtc_uid="$(id -u go2rtc)"
|
||||
go2rtc_gid="$(id -g go2rtc)"
|
||||
if [[ "$puid" -eq "$go2rtc_uid" || "$pgid" -eq "$go2rtc_gid" ]]; then
|
||||
echo "[ERROR] PUID/PGID must not equal the go2rtc service ids (${go2rtc_uid}:${go2rtc_gid})." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
current_uid="$(id -u frigate)"
|
||||
current_gid="$(id -g frigate)"
|
||||
|
||||
if [[ "$puid" != "$current_uid" || "$pgid" != "$current_gid" ]]; then
|
||||
if [[ ! -w /etc/passwd ]]; then
|
||||
echo "[ERROR] PUID/PGID remapping needs a writable /etc and is not compatible with read_only: true." >&2
|
||||
echo "[ERROR] Either remove read_only and keep PUID, or drop PUID/PGID and use docker's user: ${puid}:${pgid} instead." >&2
|
||||
echo "[ERROR] See https://docs.frigate.video/configuration/non_root for the compatibility matrix." >&2
|
||||
exit 1
|
||||
fi
|
||||
echo "[INFO] Remapping frigate user to ${puid}:${pgid}"
|
||||
groupmod -o -g "$pgid" frigate
|
||||
usermod -o -u "$puid" frigate
|
||||
fi
|
||||
|
||||
# EXTRA_GROUPS: numeric host GIDs granting device access (e.g. host render/video)
|
||||
if [[ -n "${EXTRA_GROUPS:-}" ]]; then
|
||||
for gid in ${EXTRA_GROUPS//,/ }; do
|
||||
if ! [[ "$gid" =~ ^[0-9]+$ ]] || [[ "$gid" -eq 0 ]]; then
|
||||
echo "[ERROR] EXTRA_GROUPS must be nonzero numeric GIDs, got '${gid}'" >&2
|
||||
exit 1
|
||||
fi
|
||||
if ! getent group "$gid" >/dev/null; then
|
||||
groupadd -o -g "$gid" "frigate-extra-${gid}"
|
||||
fi
|
||||
group_name="$(getent group "$gid" | cut -d: -f1)"
|
||||
usermod -aG "$group_name" frigate
|
||||
usermod -aG "$group_name" go2rtc
|
||||
echo "[INFO] Added frigate and go2rtc to supplementary group ${group_name} (gid ${gid})"
|
||||
done
|
||||
fi
|
||||
@@ -1 +0,0 @@
|
||||
oneshot
|
||||
@@ -1 +0,0 @@
|
||||
/etc/s6-overlay/s6-rc.d/init-usermod/run
|
||||
@@ -7,12 +7,5 @@ set -o errexit -o nounset -o pipefail
|
||||
dirs=(/dev/shm/logs/frigate /dev/shm/logs/go2rtc /dev/shm/logs/nginx /dev/shm/logs/certsync)
|
||||
|
||||
mkdir -p "${dirs[@]}"
|
||||
|
||||
# logutil-service drops s6-log to nobody, so the dirs must stay nobody-owned
|
||||
# in root mode. Under docker --user we are already the (only) target user,
|
||||
# chown would fail, and the plain s6-log fallback in the *-log services
|
||||
# writes as us (the mkdir above is sufficient, /dev/shm is 1777).
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
chown nobody:nogroup "${dirs[@]}"
|
||||
fi
|
||||
chown nobody:nogroup "${dirs[@]}"
|
||||
chmod 02755 "${dirs[@]}"
|
||||
|
||||
@@ -1,12 +1,4 @@
|
||||
#!/command/with-contenv bash
|
||||
# shellcheck shell=bash
|
||||
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
# logutil-service drops to nobody and applies S6_LOGGING_SCRIPT
|
||||
exec logutil-service /dev/shm/logs/nginx
|
||||
fi
|
||||
|
||||
# Non-root (--user) fallback: logutil-service cannot change UID, so run
|
||||
# s6-log directly with the same directives S6_LOGGING_SCRIPT configures.
|
||||
# shellcheck disable=SC2086
|
||||
exec s6-log ${S6_LOGGING_SCRIPT:-T 1 n0 s10000000 T} /dev/shm/logs/nginx
|
||||
exec logutil-service /dev/shm/logs/nginx
|
||||
|
||||
@@ -2,4 +2,4 @@
|
||||
set -e
|
||||
|
||||
# Wait for PID file to exist.
|
||||
while ! test -f /tmp/nginx/nginx.pid; do sleep 1; done
|
||||
while ! test -f /run/nginx.pid; do sleep 1; done
|
||||
@@ -4,13 +4,6 @@
|
||||
|
||||
set -o errexit -o nounset -o pipefail
|
||||
|
||||
runs_as_root=0
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]] || /usr/local/bin/service-runs-as-root nginx; then
|
||||
runs_as_root=1
|
||||
fi
|
||||
fi
|
||||
|
||||
# Logs should be sent to stdout so that s6 can collect them
|
||||
|
||||
echo "[INFO] Starting NGINX..."
|
||||
@@ -66,18 +59,10 @@ function set_worker_processes() {
|
||||
cpus=4
|
||||
fi
|
||||
|
||||
sed -i "s/worker_processes auto;/worker_processes ${cpus};/" /tmp/nginx/conf/nginx.conf
|
||||
# we need to catch any errors because sed will fail if user has bind mounted a custom nginx file
|
||||
sed -i "s/worker_processes auto;/worker_processes ${cpus};/" /usr/local/nginx/conf/nginx.conf || true
|
||||
}
|
||||
|
||||
# Rebuilt root-owned every start: a symlink planted by the previously
|
||||
# unprivileged nginx would redirect the root cp/tempio writes below onto any
|
||||
# root file. rm does not traverse symlinks; the bare mkdir fails closed if raced.
|
||||
rm -rf /tmp/nginx
|
||||
mkdir /tmp/nginx
|
||||
mkdir -p /tmp/nginx/conf /tmp/nginx/client_body /tmp/nginx/proxy \
|
||||
/tmp/nginx/fastcgi /tmp/nginx/uwsgi /tmp/nginx/scgi
|
||||
cp -r /usr/local/nginx/conf/. /tmp/nginx/conf/
|
||||
|
||||
set_worker_processes
|
||||
|
||||
# ensure the directory for ACME challenges exists
|
||||
@@ -92,47 +77,20 @@ if [ ! \( -f "$letsencrypt_path/privkey.pem" -a -f "$letsencrypt_path/fullchain.
|
||||
openssl req -new -newkey rsa:4096 -days 365 -nodes -x509 \
|
||||
-subj "/O=FRIGATE DEFAULT CERT/CN=*" \
|
||||
-keyout "$letsencrypt_path/privkey.pem" -out "$letsencrypt_path/fullchain.pem" 2>/dev/null
|
||||
chmod 600 "$letsencrypt_path/privkey.pem"
|
||||
chmod 644 "$letsencrypt_path/fullchain.pem"
|
||||
fi
|
||||
|
||||
# nginx settings are read once; both templates consume them
|
||||
nginx_settings=$(python3 /usr/local/nginx/get_nginx_settings.py)
|
||||
|
||||
# build templates for optional FRIGATE_BASE_PATH environment variable
|
||||
echo "$nginx_settings" | \
|
||||
python3 /usr/local/nginx/get_nginx_settings.py | \
|
||||
tempio -template /usr/local/nginx/templates/base_path.gotmpl \
|
||||
-out /tmp/nginx/conf/base_path.conf
|
||||
-out /usr/local/nginx/conf/base_path.conf
|
||||
|
||||
# build templates for additional network settings
|
||||
echo "$nginx_settings" | \
|
||||
python3 /usr/local/nginx/get_nginx_settings.py | \
|
||||
tempio -template /usr/local/nginx/templates/listen.gotmpl \
|
||||
-out /tmp/nginx/conf/listen.conf
|
||||
|
||||
if [[ "$(id -u)" -eq 0 && "$runs_as_root" -eq 0 ]]; then
|
||||
chown -R frigate:frigate /tmp/nginx
|
||||
# heal the cache: a root `nginx -t` chowns every cycle path to the `user` directive user
|
||||
if [ -d /dev/shm/nginx_cache ]; then
|
||||
chown -R frigate:frigate /dev/shm/nginx_cache
|
||||
fi
|
||||
# nginx reopens /dev/stdout by path for its logs, and s6 made the pipe
|
||||
# root-owned 0600; without this the non-root master exits EACCES
|
||||
chown frigate /dev/stdout
|
||||
# self-signed certs are root-generated; tolerant because mounted certs may be :ro
|
||||
if [ -f "$letsencrypt_path/privkey.pem" ]; then
|
||||
chown frigate:frigate "$letsencrypt_path/privkey.pem" "$letsencrypt_path/fullchain.pem" 2>/dev/null || true
|
||||
fi
|
||||
fi
|
||||
-out /usr/local/nginx/conf/listen.conf
|
||||
|
||||
# Replace the bash process with the NGINX process, redirecting stderr to stdout
|
||||
exec 2>&1
|
||||
# -e stderr: the compiled-in error log path is not writable by the runtime user
|
||||
if [[ "$(id -u)" -ne 0 || "$runs_as_root" -eq 1 ]]; then
|
||||
exec \
|
||||
s6-notifyoncheck -t 30000 -n 1 \
|
||||
nginx -e stderr -c /tmp/nginx/conf/nginx.conf
|
||||
else
|
||||
exec \
|
||||
s6-notifyoncheck -t 30000 -n 1 \
|
||||
s6-setuidgid frigate nginx -e stderr -c /tmp/nginx/conf/nginx.conf
|
||||
fi
|
||||
exec \
|
||||
s6-notifyoncheck -t 30000 -n 1 \
|
||||
nginx
|
||||
|
||||
@@ -144,59 +144,3 @@ rm -f /dev/shm/.frigate-is-stopping
|
||||
|
||||
migrate_addon_config_dir
|
||||
migrate_db_from_media_to_config
|
||||
|
||||
# Align volume ownership with the runtime user (one sweep per PUID/schema
|
||||
# change, guarded by the sentinel; see fix-ownership). The escape hatch
|
||||
# deletes the sentinel instead: ownership is never mutated while it is on,
|
||||
# so the next non-root boot must re-sweep whatever root created meanwhile.
|
||||
if [[ "$(id -u)" -eq 0 ]]; then
|
||||
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then
|
||||
rm -f /config/.permissions_version
|
||||
else
|
||||
# Only when a mount backs /media/frigate itself: under a parent /media
|
||||
# mount, a dedicated volume added later would be shadowed and skipped
|
||||
sentinel_args=(--sentinel /config/.permissions_version)
|
||||
root_services_mode=""
|
||||
if [[ -n "${FRIGATE_ROOT_SERVICES:-}" ]]; then
|
||||
# || true: an all-empty list (",") fails grep -v and errexit would kill the boot
|
||||
root_services_mode=$(tr ',' '\n' <<< "${FRIGATE_ROOT_SERVICES//[[:space:]]/}" | grep -v '^$' | sort -u | paste -sd, - || true)
|
||||
if [[ -n "$root_services_mode" ]]; then
|
||||
sentinel_args+=(--mode "$root_services_mode")
|
||||
fi
|
||||
fi
|
||||
if ! awk '$2 == "/media/frigate" || $2 ~ /^\/media\/frigate\//' /proc/mounts | grep -q .; then
|
||||
sentinel_args=()
|
||||
fi
|
||||
/usr/local/bin/fix-ownership "${sentinel_args[@]}" \
|
||||
"${PUID:-1000}" "${PGID:-1000}" /config /media/frigate
|
||||
|
||||
# Root services write clips stragglers and caches mid-run; realign the
|
||||
# small trees every boot. Recordings are chowned at create instead.
|
||||
if [[ -n "$root_services_mode" ]]; then
|
||||
# only sweep what exists; clips and exports appear after the first run
|
||||
boot_sweep_paths=(/config)
|
||||
for extra in /media/frigate/clips /media/frigate/exports; do
|
||||
if [[ -d "$extra" ]]; then
|
||||
boot_sweep_paths+=("$extra")
|
||||
fi
|
||||
done
|
||||
/usr/local/bin/fix-ownership \
|
||||
"${PUID:-1000}" "${PGID:-1000}" "${boot_sweep_paths[@]}"
|
||||
fi
|
||||
fi
|
||||
fi
|
||||
|
||||
# Must stay after the sweep, which reads an absent /media/frigate as an
|
||||
# unmounted volume rather than a swept one
|
||||
if [[ "$(id -u)" -eq 0 && ! -d /media/frigate ]]; then
|
||||
mkdir -p /media/frigate
|
||||
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then
|
||||
chown "${PUID:-1000}:${PGID:-1000}" /media/frigate
|
||||
fi
|
||||
fi
|
||||
|
||||
# usually a tmpfs mount: root-owned on arrival and outside the swept volumes
|
||||
if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then
|
||||
mkdir -p /tmp/cache
|
||||
chown "${PUID:-1000}:${PGID:-1000}" /tmp/cache
|
||||
fi
|
||||
|
||||
@@ -1,194 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Single source of truth for aligning volume ownership with the runtime user.
|
||||
#
|
||||
# Usage: fix-ownership [--dry-run] [--sentinel FILE] [--mode STRING] UID GID PATH [PATH...]
|
||||
#
|
||||
# --dry-run report what would change, touch nothing
|
||||
# --sentinel skip entirely when FILE already records "SCHEMA:UID:GID";
|
||||
# write it after a successful run (used by the boot path so
|
||||
# multi-TB volumes are swept once per UID/schema change, not
|
||||
# on every boot)
|
||||
# --mode append STRING to the sentinel, so changing it re-sweeps once
|
||||
#
|
||||
# Only files whose uid OR gid differs are touched, so re-runs are cheap.
|
||||
# lost+found is skipped: fsck fills it with root-only recovered fragments.
|
||||
# Top-level /config additionally grants group frigate-data TRAVERSE ONLY
|
||||
# (g+rx) so the separate go2rtc user can reach its pre-created HomeKit file
|
||||
# on hosts where /config is mounted 0700. Never g+w: directory write means
|
||||
# unlink rights over frigate.db/config.yml, and would let a compromised
|
||||
# go2rtc plant /config/go2rtc, which the go2rtc run script executes
|
||||
# preferentially, as root under the escape hatch.
|
||||
|
||||
set -o errexit -o nounset -o pipefail
|
||||
|
||||
# Permissions-layout epoch. Bump to force a one-time re-sweep on upgrade
|
||||
# (e.g. when the privilege-drop release must capture files created as root
|
||||
# since the previous sweep).
|
||||
schema=2
|
||||
|
||||
dry_run=0
|
||||
sentinel=""
|
||||
mode=""
|
||||
|
||||
while [[ "${1:-}" == --* ]]; do
|
||||
case "$1" in
|
||||
--dry-run) dry_run=1; shift ;;
|
||||
--sentinel)
|
||||
if [[ -z "${2:-}" ]]; then
|
||||
echo "[ERROR] fix-ownership: --sentinel requires a file argument" >&2
|
||||
exit 2
|
||||
fi
|
||||
sentinel="$2"; shift 2 ;;
|
||||
--mode)
|
||||
if [[ -z "${2:-}" ]]; then
|
||||
echo "[ERROR] fix-ownership: --mode requires a value" >&2
|
||||
exit 2
|
||||
fi
|
||||
mode="$2"; shift 2 ;;
|
||||
*) echo "[ERROR] fix-ownership: unknown option $1" >&2; exit 2 ;;
|
||||
esac
|
||||
done
|
||||
|
||||
if [[ $# -lt 3 ]]; then
|
||||
echo "Usage: fix-ownership [--dry-run] [--sentinel FILE] [--mode STRING] UID GID PATH..." >&2
|
||||
exit 2
|
||||
fi
|
||||
|
||||
target_uid="$1"
|
||||
target_gid="$2"
|
||||
shift 2
|
||||
|
||||
if [[ "$(id -u)" -ne 0 ]]; then
|
||||
echo "[INFO] fix-ownership: not running as root, skipping (ownership is managed by the host in --user mode)"
|
||||
exit 0
|
||||
fi
|
||||
|
||||
# The list folds into the sentinel so entering or leaving a granular root mode
|
||||
# re-sweeps once, catching whatever the other ownership mechanisms missed.
|
||||
sentinel_content="${schema}:${target_uid}:${target_gid}"
|
||||
if [[ -n "$mode" ]]; then
|
||||
sentinel_content="${sentinel_content}:${mode}"
|
||||
fi
|
||||
|
||||
# safe-sentinel reports only a root-owned regular file, so a forged or
|
||||
# symlinked sentinel in the runtime-user-owned /config can't suppress the sweep
|
||||
if [[ "$dry_run" -eq 0 && -n "$sentinel" ]]; then
|
||||
if existing=$(/usr/local/bin/safe-sentinel read "$sentinel" 2>/dev/null) && \
|
||||
[[ "$existing" == "$sentinel_content" ]]; then
|
||||
echo "[INFO] fix-ownership: ${target_uid}:${target_gid} (schema ${schema}) already applied, skipping"
|
||||
exit 0
|
||||
fi
|
||||
fi
|
||||
|
||||
# A sweep that could not chown everything must not be recorded as complete:
|
||||
# the sentinel would make every later boot skip it and the entries would stay
|
||||
# unreachable once services run unprivileged.
|
||||
swept_clean=1
|
||||
|
||||
# Entries another mechanism deliberately owns. Chowning them undoes that work
|
||||
# and leaves the same "mismatch" waiting for the next boot, so /config could
|
||||
# never report itself clean: /config is chgrp'd to frigate-data below so go2rtc
|
||||
# can traverse it, and the HomeKit file is handed to the go2rtc user by the
|
||||
# go2rtc service. Only the GROUP on /config is exempt; a root-owned /config
|
||||
# must still be chowned or the runtime user cannot write there at all.
|
||||
# Shared by the counting and the chowning walk so the two cannot disagree.
|
||||
mismatch_expr=(
|
||||
"(" -not -uid "$target_uid"
|
||||
-o "(" -not -gid "$target_gid" -a ! -path /config ")"
|
||||
")"
|
||||
-a ! -path /config/go2rtc_homekit.yml
|
||||
)
|
||||
if [[ -n "$sentinel" ]]; then
|
||||
# safe-sentinel keeps the sentinel root-owned on purpose and rejects one
|
||||
# owned by anybody else, so chowning it here would suppress the skip and
|
||||
# make every boot re-sweep. Only the trailing write puts it back today.
|
||||
mismatch_expr+=(-a ! -path "$sentinel")
|
||||
fi
|
||||
|
||||
for path in "$@"; do
|
||||
# An absent root is an incomplete sweep, not a finished one: /media/frigate
|
||||
# is not in the image, so a boot before the volume is mounted would
|
||||
# otherwise record success and the volume would never be swept once added.
|
||||
if [[ ! -d "$path" ]]; then
|
||||
swept_clean=0
|
||||
echo "[WARN] fix-ownership: $path does not exist, skipping; will retry on next boot"
|
||||
continue
|
||||
fi
|
||||
|
||||
echo "[INFO] fix-ownership: scanning ${path} for ownership mismatches; this may take a while on large filesystems"
|
||||
|
||||
# find may fail mid-walk on a live volume (file deleted under it) or on a
|
||||
# stale mount. Tolerate it rather than aborting under errexit, but never
|
||||
# read a failed scan as "nothing to do": that would record the sweep as
|
||||
# complete without having looked.
|
||||
if ! count=$(find "$path" -name lost+found -prune -o "${mismatch_expr[@]}" -printf '.' 2>/dev/null | wc -c); then
|
||||
swept_clean=0
|
||||
echo "[WARN] fix-ownership: could not scan ${path}; will retry on next boot"
|
||||
continue
|
||||
fi
|
||||
|
||||
if [[ "$count" -eq 0 ]]; then
|
||||
echo "[INFO] fix-ownership: $path already owned by ${target_uid}:${target_gid}, nothing to do"
|
||||
continue
|
||||
fi
|
||||
|
||||
# find does not descend symlinks and chown -h retargets the link itself, so
|
||||
# anything behind a symlinked directory is outside this sweep. Following
|
||||
# them is not an option: a link could walk the chown out of the volume.
|
||||
if [[ -n "$(find "$path" -type l -xtype d -print -quit 2>/dev/null)" ]]; then
|
||||
echo "[WARN] fix-ownership: ${path} contains symlinked directories; ownership behind them is not managed and must be aligned by hand"
|
||||
fi
|
||||
|
||||
echo "[WARN] fix-ownership: adjusting ownership of ${count} entries under ${path}"
|
||||
if [[ "$dry_run" -eq 1 ]]; then
|
||||
echo "[INFO] fix-ownership: dry run, not changing ${path}"
|
||||
continue
|
||||
fi
|
||||
|
||||
# -execdir chowns from the entry's own directory, so a parent swapped for a
|
||||
# symlink mid-walk can't redirect the chown out of the volume
|
||||
started=$SECONDS
|
||||
if find "$path" -name lost+found -prune -o "${mismatch_expr[@]}" \
|
||||
-print -execdir chown -h "${target_uid}:${target_gid}" {} + \
|
||||
| awk -v total="$count" -v path="$path" '
|
||||
BEGIN { next_pct = 5 }
|
||||
{
|
||||
pct = int(NR * 100 / total)
|
||||
if (pct > 100) pct = 100
|
||||
if (pct >= next_pct) {
|
||||
printf "[INFO] fix-ownership: %s %d%% (%d/%d entries)\n", path, pct, NR, total
|
||||
# mawk block-buffers to a pipe; without fflush the whole
|
||||
# progress log arrives at once
|
||||
fflush()
|
||||
while (next_pct <= pct) next_pct += 5
|
||||
}
|
||||
}'; then
|
||||
elapsed=$((SECONDS - started))
|
||||
if [[ "$elapsed" -ge 60 ]]; then
|
||||
elapsed="$((elapsed / 60))m $((elapsed % 60))s"
|
||||
else
|
||||
elapsed="${elapsed}s"
|
||||
fi
|
||||
echo "[INFO] fix-ownership: finished ${path} in ${elapsed}"
|
||||
else
|
||||
swept_clean=0
|
||||
echo "[WARN] fix-ownership: some entries under ${path} could not be updated (deleted mid-sweep or chown denied); will retry on next mismatch"
|
||||
fi
|
||||
done
|
||||
|
||||
# go2rtc (separate user) must be able to REACH its HomeKit state in /config.
|
||||
# Write access is per-file, not per-directory: go2rtc's PatchConfig rewrites
|
||||
# the first -config file via os.WriteFile (in-place truncate, no rename,
|
||||
# verified against go2rtc v1.9.14 internal/app/config.go), and the file is
|
||||
# always pre-created by setup_homekit_config before go2rtc starts, so
|
||||
# O_CREATE never needs directory write. See header comment for why g+w is
|
||||
# forbidden here.
|
||||
if [[ "$dry_run" -eq 0 && -d /config ]]; then
|
||||
chgrp frigate-data /config 2>/dev/null || true
|
||||
chmod g+rx /config 2>/dev/null || true
|
||||
fi
|
||||
|
||||
if [[ "$dry_run" -eq 0 && -n "$sentinel" && "$swept_clean" -eq 1 ]]; then
|
||||
/usr/local/bin/safe-sentinel write "$sentinel" "$sentinel_content" || \
|
||||
echo "[WARN] fix-ownership: could not write ${sentinel}; the sweep will run again on next boot"
|
||||
fi
|
||||
@@ -1,74 +0,0 @@
|
||||
#!/usr/bin/env python3
|
||||
"""Read or write the ownership sweep sentinel without following symlinks.
|
||||
|
||||
The sentinel lives in /config, which the unprivileged runtime user owns, so it
|
||||
can be swapped for a symlink. read trusts only a root-owned regular file; write
|
||||
never follows a symlink or fifo onto another file.
|
||||
|
||||
Usage:
|
||||
safe-sentinel read PATH print content, exit 0 only if root-owned regular file
|
||||
safe-sentinel write PATH CONTENT write CONTENT to a regular file at PATH
|
||||
"""
|
||||
|
||||
import errno
|
||||
import os
|
||||
import stat
|
||||
import sys
|
||||
|
||||
MODE = 0o644
|
||||
|
||||
|
||||
def do_read(path: str) -> int:
|
||||
try:
|
||||
fd = os.open(path, os.O_RDONLY | os.O_NOFOLLOW)
|
||||
except OSError:
|
||||
return 1
|
||||
try:
|
||||
st = os.fstat(fd)
|
||||
if not stat.S_ISREG(st.st_mode) or st.st_uid != 0:
|
||||
return 1
|
||||
sys.stdout.buffer.write(os.read(fd, 4096))
|
||||
finally:
|
||||
os.close(fd)
|
||||
return 0
|
||||
|
||||
|
||||
def do_write(path: str, content: str) -> int:
|
||||
# O_NONBLOCK so a fifo fails fast (ENXIO) instead of blocking the open.
|
||||
flags = os.O_WRONLY | os.O_CREAT | os.O_NOFOLLOW | os.O_NONBLOCK
|
||||
replace = (errno.ELOOP, errno.ENXIO)
|
||||
try:
|
||||
fd = os.open(path, flags, MODE)
|
||||
if not stat.S_ISREG(os.fstat(fd).st_mode):
|
||||
os.close(fd)
|
||||
raise OSError(errno.ELOOP, "not a regular file")
|
||||
except OSError as err:
|
||||
if err.errno not in replace:
|
||||
raise
|
||||
os.unlink(path)
|
||||
fd = os.open(path, flags | os.O_EXCL, MODE)
|
||||
try:
|
||||
os.ftruncate(fd, 0)
|
||||
os.write(fd, content.encode())
|
||||
# keep it root-owned so a later sweep that chowned the old sentinel to
|
||||
# the runtime user can't make the next read reject and re-sweep
|
||||
os.fchown(fd, 0, 0)
|
||||
finally:
|
||||
os.close(fd)
|
||||
return 0
|
||||
|
||||
|
||||
def main(argv: list[str]) -> int:
|
||||
if len(argv) == 3 and argv[1] == "read":
|
||||
return do_read(argv[2])
|
||||
if len(argv) == 4 and argv[1] == "write":
|
||||
try:
|
||||
return do_write(argv[2], argv[3])
|
||||
except OSError:
|
||||
return 1
|
||||
print("usage: safe-sentinel read PATH | write PATH CONTENT", file=sys.stderr)
|
||||
return 2
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main(sys.argv))
|
||||
@@ -1,18 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Exit 0 when FRIGATE_ROOT_SERVICES names the given service. Membership only:
|
||||
# the euid and FRIGATE_RUN_AS_ROOT checks stay in the callers.
|
||||
#
|
||||
# Usage: service-runs-as-root SERVICE
|
||||
|
||||
set -o nounset
|
||||
|
||||
service="${1:?usage: service-runs-as-root SERVICE}"
|
||||
|
||||
IFS=',' read -ra entries <<< "${FRIGATE_ROOT_SERVICES:-}"
|
||||
for entry in "${entries[@]}"; do
|
||||
entry="${entry//[[:space:]]/}"
|
||||
if [[ "$entry" == "$service" ]]; then
|
||||
exit 0
|
||||
fi
|
||||
done
|
||||
exit 1
|
||||
@@ -3,12 +3,13 @@
|
||||
import json
|
||||
import os
|
||||
import sys
|
||||
from pathlib import Path
|
||||
from typing import Any
|
||||
|
||||
from ruamel.yaml import YAML
|
||||
|
||||
sys.path.insert(0, "/opt/frigate")
|
||||
from frigate.config.env import apply_config_env_vars, substitute_frigate_vars
|
||||
from frigate.config.env import substitute_frigate_vars
|
||||
from frigate.const import (
|
||||
BIRDSEYE_PIPE,
|
||||
LIBAVFORMAT_VERSION_MAJOR,
|
||||
@@ -24,6 +25,15 @@ sys.path.remove("/opt/frigate")
|
||||
|
||||
yaml = YAML()
|
||||
|
||||
FRIGATE_ENV_VARS = {k: v for k, v in os.environ.items() if k.startswith("FRIGATE_")}
|
||||
# read docker secret files as env vars too
|
||||
if os.path.isdir("/run/secrets"):
|
||||
for secret_file in os.listdir("/run/secrets"):
|
||||
if secret_file.startswith("FRIGATE_"):
|
||||
FRIGATE_ENV_VARS[secret_file] = (
|
||||
Path(os.path.join("/run/secrets", secret_file)).read_text().strip()
|
||||
)
|
||||
|
||||
config_file = find_config_file()
|
||||
|
||||
try:
|
||||
@@ -37,20 +47,6 @@ try:
|
||||
except FileNotFoundError:
|
||||
config: dict[str, Any] = {}
|
||||
|
||||
# No validator runs here, so install environment_vars ourselves. FRIGATE_
|
||||
# names only: anything else lands in os.environ, where the exec gate reads
|
||||
# GO2RTC_ALLOW_ARBITRARY_EXEC.
|
||||
config_env_vars = config.get("environment_vars")
|
||||
apply_config_env_vars(
|
||||
{
|
||||
key: value
|
||||
for key, value in config_env_vars.items()
|
||||
if str(key).startswith("FRIGATE_")
|
||||
}
|
||||
if isinstance(config_env_vars, dict)
|
||||
else {}
|
||||
)
|
||||
|
||||
go2rtc_config: dict[str, Any] = config.get("go2rtc", {})
|
||||
|
||||
# Need to enable CORS for go2rtc so the frigate integration / card work automatically
|
||||
@@ -117,7 +113,7 @@ for name in list(go2rtc_config.get("streams", {})):
|
||||
|
||||
if isinstance(stream, str):
|
||||
try:
|
||||
formatted_stream = substitute_frigate_vars(stream)
|
||||
formatted_stream = stream.format(**FRIGATE_ENV_VARS)
|
||||
if is_restricted_go2rtc_source(formatted_stream):
|
||||
print(
|
||||
f"[ERROR] Stream '{name}' uses a restricted source (echo/expr/exec) which is disabled by default for security. "
|
||||
@@ -126,7 +122,7 @@ for name in list(go2rtc_config.get("streams", {})):
|
||||
del go2rtc_config["streams"][name]
|
||||
continue
|
||||
go2rtc_config["streams"][name] = formatted_stream
|
||||
except ValueError as e:
|
||||
except KeyError as e:
|
||||
print(
|
||||
"[ERROR] Invalid substitution found, see https://docs.frigate.video/configuration/restream#advanced-restream-configurations for more info."
|
||||
)
|
||||
@@ -136,7 +132,7 @@ for name in list(go2rtc_config.get("streams", {})):
|
||||
filtered_streams = []
|
||||
for i, stream_item in enumerate(stream):
|
||||
try:
|
||||
formatted_stream = substitute_frigate_vars(stream_item)
|
||||
formatted_stream = stream_item.format(**FRIGATE_ENV_VARS)
|
||||
if is_restricted_go2rtc_source(formatted_stream):
|
||||
print(
|
||||
f"[ERROR] Stream '{name}' item {i + 1} uses a restricted source (echo/expr/exec) which is disabled by default for security. "
|
||||
@@ -145,7 +141,7 @@ for name in list(go2rtc_config.get("streams", {})):
|
||||
continue
|
||||
|
||||
filtered_streams.append(formatted_stream)
|
||||
except ValueError as e:
|
||||
except KeyError as e:
|
||||
print(
|
||||
"[ERROR] Invalid substitution found, see https://docs.frigate.video/configuration/restream#advanced-restream-configurations for more info."
|
||||
)
|
||||
@@ -189,6 +185,3 @@ if config.get("birdseye", {}).get("restream", False):
|
||||
# Write go2rtc_config to /dev/shm/go2rtc.yaml
|
||||
with open("/dev/shm/go2rtc.yaml", "w") as f:
|
||||
yaml.dump(go2rtc_config, f)
|
||||
|
||||
# config contains camera credentials; do not leave it world-readable
|
||||
os.chmod("/dev/shm/go2rtc.yaml", 0o640)
|
||||
|
||||
@@ -1,97 +0,0 @@
|
||||
"""Normalize the go2rtc HomeKit file and hand it to go2rtc, as root.
|
||||
|
||||
Runs before the drop. The file is in the runtime-user-owned /config, so a
|
||||
planted symlink could redirect the root write or chown onto another file;
|
||||
every operation goes through an O_NOFOLLOW fd to prevent that.
|
||||
|
||||
Usage: prepare_homekit.py PATH [--chown]
|
||||
"""
|
||||
|
||||
import errno
|
||||
import grp
|
||||
import io
|
||||
import os
|
||||
import pwd
|
||||
import stat
|
||||
import sys
|
||||
|
||||
from ruamel.yaml import YAML
|
||||
|
||||
RUNTIME_OWNER = "go2rtc"
|
||||
SHARED_GROUP = "frigate-data"
|
||||
MODE = 0o664
|
||||
MAX_BYTES = 10 * 1024 * 1024
|
||||
|
||||
|
||||
def open_nofollow(path: str) -> int:
|
||||
"""Return an fd to a regular file at path, never following a symlink."""
|
||||
flags = os.O_RDWR | os.O_CREAT | os.O_NOFOLLOW
|
||||
try:
|
||||
fd = os.open(path, flags, MODE)
|
||||
except OSError as err:
|
||||
if err.errno != errno.ELOOP:
|
||||
raise
|
||||
os.unlink(path)
|
||||
return os.open(path, flags | os.O_EXCL, MODE)
|
||||
|
||||
# A fifo or other non-regular file would hang or misbehave on read; replace it.
|
||||
if not stat.S_ISREG(os.fstat(fd).st_mode):
|
||||
os.close(fd)
|
||||
os.unlink(path)
|
||||
return os.open(path, flags | os.O_EXCL, MODE)
|
||||
return fd
|
||||
|
||||
|
||||
def normalize(content: str) -> str:
|
||||
"""Keep only the homekit section, matching the previous yq/jq behavior."""
|
||||
yaml = YAML(typ="safe")
|
||||
try:
|
||||
data = yaml.load(content)
|
||||
except Exception:
|
||||
return ""
|
||||
|
||||
if not isinstance(data, dict) or "homekit" not in data:
|
||||
return ""
|
||||
|
||||
buf = io.StringIO()
|
||||
yaml.dump({"homekit": data["homekit"]}, buf)
|
||||
return buf.getvalue()
|
||||
|
||||
|
||||
def main() -> int:
|
||||
if len(sys.argv) < 2:
|
||||
print("[ERROR] prepare_homekit: PATH is required", file=sys.stderr)
|
||||
return 2
|
||||
|
||||
path = sys.argv[1]
|
||||
do_chown = "--chown" in sys.argv[2:]
|
||||
|
||||
fd = open_nofollow(path)
|
||||
try:
|
||||
content = os.read(fd, MAX_BYTES).decode("utf-8", "replace")
|
||||
normalized = normalize(content)
|
||||
os.ftruncate(fd, 0)
|
||||
os.lseek(fd, 0, os.SEEK_SET)
|
||||
os.write(fd, normalized.encode("utf-8"))
|
||||
|
||||
if do_chown:
|
||||
# tolerate a chown-refusing mount (NFS root_squash): pairing
|
||||
# persistence degrades, the service does not
|
||||
try:
|
||||
uid = pwd.getpwnam(RUNTIME_OWNER).pw_uid
|
||||
gid = grp.getgrnam(SHARED_GROUP).gr_gid
|
||||
os.fchown(fd, uid, gid)
|
||||
os.fchmod(fd, MODE)
|
||||
except (KeyError, OSError):
|
||||
print(
|
||||
f"[WARN] Could not hand {path} to the go2rtc user; "
|
||||
"HomeKit pairing changes may not persist"
|
||||
)
|
||||
finally:
|
||||
os.close(fd)
|
||||
|
||||
return 0
|
||||
|
||||
|
||||
if __name__ == "__main__":
|
||||
sys.exit(main())
|
||||
@@ -1,13 +1,9 @@
|
||||
# Loaded with -c from the /tmp/nginx/conf copy: relative includes follow the -c
|
||||
# file, all other path directives follow --prefix and must stay absolute.
|
||||
|
||||
daemon off;
|
||||
# ignored by a non-root master; keeps workers root under FRIGATE_RUN_AS_ROOT
|
||||
user root;
|
||||
worker_processes auto;
|
||||
|
||||
error_log /dev/stdout warn;
|
||||
pid /tmp/nginx/nginx.pid;
|
||||
pid /var/run/nginx.pid;
|
||||
|
||||
events {
|
||||
worker_connections 1024;
|
||||
@@ -15,13 +11,6 @@ events {
|
||||
|
||||
http {
|
||||
map_hash_bucket_size 256;
|
||||
server_tokens off;
|
||||
|
||||
client_body_temp_path /tmp/nginx/client_body;
|
||||
proxy_temp_path /tmp/nginx/proxy;
|
||||
fastcgi_temp_path /tmp/nginx/fastcgi;
|
||||
uwsgi_temp_path /tmp/nginx/uwsgi;
|
||||
scgi_temp_path /tmp/nginx/scgi;
|
||||
|
||||
include mime.types;
|
||||
default_type application/octet-stream;
|
||||
@@ -73,7 +62,6 @@ http {
|
||||
|
||||
server {
|
||||
include listen.conf;
|
||||
include security_headers.conf;
|
||||
|
||||
# enable HTTP/2 for TLS connections to eliminate browser 6-connection limit
|
||||
http2 on;
|
||||
@@ -87,12 +75,6 @@ http {
|
||||
vod_align_segments_to_key_frames on;
|
||||
vod_manifest_segment_durations_mode accurate;
|
||||
vod_ignore_edit_list on;
|
||||
# short leading segments at each playlist start; sources start at
|
||||
# the seek target, so the ladder applies to every seek. Only
|
||||
# effective when clips declare real keyFrameDurations
|
||||
vod_bootstrap_segment_durations 1000;
|
||||
vod_bootstrap_segment_durations 2000;
|
||||
vod_bootstrap_segment_durations 4000;
|
||||
vod_segment_duration 10000;
|
||||
|
||||
# MPEG-TS settings (not used when fMP4 is enabled, kept for reference)
|
||||
@@ -132,23 +114,25 @@ http {
|
||||
# Smaller segments, faster generation, better browser compatibility
|
||||
vod_hls_container_format fmp4;
|
||||
|
||||
# fMP4 playlists use EXT-X-MAP, which requires HLS protocol
|
||||
# version 6 (RFC 8216 section 7); the module default is 4
|
||||
vod_hls_version 6;
|
||||
|
||||
secure_token $args;
|
||||
secure_token_types application/vnd.apple.mpegurl;
|
||||
|
||||
include security_headers.conf;
|
||||
add_header Cache-Control "no-store";
|
||||
expires off;
|
||||
|
||||
keepalive_disable safari;
|
||||
|
||||
# vod module returns 502 for non-existent media
|
||||
# https://github.com/kaltura/nginx-vod-module/issues/468
|
||||
error_page 502 =404 /vod-not-found;
|
||||
}
|
||||
|
||||
location = /vod-not-found {
|
||||
return 404;
|
||||
}
|
||||
|
||||
location /stream/ {
|
||||
include auth_request.conf;
|
||||
include security_headers.conf;
|
||||
add_header Cache-Control "no-store";
|
||||
expires off;
|
||||
|
||||
@@ -166,11 +150,12 @@ http {
|
||||
include auth_request.conf;
|
||||
types {
|
||||
video/mp4 mp4;
|
||||
image/jpeg jpg;
|
||||
image/jpeg jpg jpeg;
|
||||
image/png png;
|
||||
image/webp webp;
|
||||
}
|
||||
|
||||
expires 7d;
|
||||
include security_headers.conf;
|
||||
add_header Cache-Control "public";
|
||||
autoindex on;
|
||||
root /media/frigate;
|
||||
@@ -263,7 +248,6 @@ http {
|
||||
|
||||
location /api/ {
|
||||
include auth_request.conf;
|
||||
include security_headers.conf;
|
||||
add_header Cache-Control "no-store";
|
||||
expires off;
|
||||
proxy_pass http://frigate_api/;
|
||||
@@ -330,34 +314,29 @@ http {
|
||||
|
||||
location / {
|
||||
# do not require auth for static assets
|
||||
include security_headers.conf;
|
||||
add_header Cache-Control "no-store";
|
||||
expires off;
|
||||
|
||||
location /assets/ {
|
||||
access_log off;
|
||||
expires 1y;
|
||||
include security_headers.conf;
|
||||
add_header Cache-Control "public";
|
||||
}
|
||||
|
||||
location /fonts/ {
|
||||
access_log off;
|
||||
expires 1y;
|
||||
include security_headers.conf;
|
||||
add_header Cache-Control "public";
|
||||
}
|
||||
|
||||
location /locales/ {
|
||||
access_log off;
|
||||
include security_headers.conf;
|
||||
add_header Cache-Control "public";
|
||||
}
|
||||
|
||||
location ~ ^/.*-([A-Za-z0-9]+)\.webmanifest$ {
|
||||
access_log off;
|
||||
expires 1y;
|
||||
include security_headers.conf;
|
||||
add_header Cache-Control "public";
|
||||
default_type application/json;
|
||||
proxy_set_header Accept-Encoding "";
|
||||
|
||||
@@ -1,5 +0,0 @@
|
||||
# Deliberately no X-Frame-Options or CSP frame-ancestors: HA's Webpage card and
|
||||
# iframe panels frame Frigate cross-origin, and either would break them
|
||||
# silently. Bind-mount this file to add your own.
|
||||
add_header X-Content-Type-Options "nosniff" always;
|
||||
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
|
||||
@@ -1,55 +0,0 @@
|
||||
#!/bin/bash
|
||||
# Ahead-of-time volume ownership migration for switching Frigate to non-root.
|
||||
# Run from the host BEFORE enabling PUID/PGID or --user:
|
||||
#
|
||||
# ./fix-permissions.sh [--dry-run] <config_dir> <media_dir> [PUID] [PGID]
|
||||
#
|
||||
# Wraps the image's fix-ownership helper so there is exactly one
|
||||
# implementation of the chown logic. Requires an image that contains the
|
||||
# helper (any release that includes non-root support).
|
||||
|
||||
set -o errexit -o nounset -o pipefail
|
||||
|
||||
IMAGE="${FRIGATE_IMAGE:-ghcr.io/blakeblackshear/frigate:stable}"
|
||||
|
||||
dry_run_flag=""
|
||||
if [[ "${1:-}" == "--dry-run" ]]; then
|
||||
dry_run_flag="--dry-run"
|
||||
shift
|
||||
fi
|
||||
|
||||
if [[ $# -lt 2 ]]; then
|
||||
echo "Usage: $0 [--dry-run] <config_dir> <media_dir> [PUID] [PGID]" >&2
|
||||
exit 2
|
||||
fi
|
||||
|
||||
config_dir="$1"
|
||||
media_dir="$2"
|
||||
puid="${3:-1000}"
|
||||
pgid="${4:-1000}"
|
||||
|
||||
# The ids are interpolated into the container's bash -c source below, so
|
||||
# anything but digits would be reparsed as shell rather than passed through
|
||||
if ! [[ "$puid" =~ ^[0-9]+$ && "$pgid" =~ ^[0-9]+$ ]]; then
|
||||
echo "[ERROR] PUID and PGID must be numeric, got '${puid}' and '${pgid}'" >&2
|
||||
exit 2
|
||||
fi
|
||||
|
||||
echo "[INFO] Using image ${IMAGE} (override with FRIGATE_IMAGE=...)"
|
||||
if ! docker image inspect "${IMAGE}" >/dev/null 2>&1; then
|
||||
echo "[INFO] ${IMAGE} is not present locally and has to be pulled first; this may take a while"
|
||||
fi
|
||||
|
||||
if [[ -n "$dry_run_flag" ]]; then
|
||||
echo "[INFO] Dry run: reporting what would change under ${config_dir} and ${media_dir}, changing nothing"
|
||||
else
|
||||
echo "[INFO] Aligning ${config_dir} and ${media_dir} to ${puid}:${pgid}; this may take a while on large filesystems"
|
||||
fi
|
||||
|
||||
# shellcheck disable=SC2086
|
||||
docker run --rm \
|
||||
-v "${config_dir}:/config" \
|
||||
-v "${media_dir}:/media/frigate" \
|
||||
--entrypoint bash \
|
||||
"${IMAGE}" \
|
||||
-c "command -v fix-ownership >/dev/null || { echo '[ERROR] this Frigate image predates non-root support; set FRIGATE_IMAGE to a release that includes it' >&2; exit 1; }; exec fix-ownership ${dry_run_flag} ${puid} ${pgid} /config /media/frigate"
|
||||
@@ -13,16 +13,6 @@ TRT_VER=${TRT_VER:-$(cat /etc/TENSORRT_VER)}
|
||||
OUTPUT_FOLDER="${MODEL_CACHE_DIR}/${TRT_VER}"
|
||||
YOLO_MODELS=${YOLO_MODELS:-""}
|
||||
|
||||
# This runs as root after prepare's sentinel-guarded sweep, so the dirs and
|
||||
# engines it creates below are the runtime user's to fix up, on every exit path
|
||||
function hand_off_ownership() {
|
||||
if [[ "$(id -u)" -eq 0 && "${FRIGATE_RUN_AS_ROOT:-false}" != "true" ]]; then
|
||||
/usr/local/bin/fix-ownership "${PUID:-1000}" "${PGID:-1000}" \
|
||||
/config/model_cache "${MODEL_CACHE_DIR}"
|
||||
fi
|
||||
}
|
||||
trap hand_off_ownership EXIT
|
||||
|
||||
# Create output folder
|
||||
mkdir -p ${OUTPUT_FOLDER}
|
||||
|
||||
|
||||
File diff suppressed because it is too large
Load Diff
@@ -56,6 +56,17 @@ mqtt:
|
||||
# 2 = exactly once
|
||||
qos: 0
|
||||
|
||||
# Optional: Detectors configuration. Defaults to a single CPU detector
|
||||
detectors:
|
||||
# Required: name of the detector
|
||||
detector_name:
|
||||
# Required: type of the detector
|
||||
# Frigate provides many types, see https://docs.frigate.video/configuration/object_detectors for more details (default: shown below)
|
||||
# Additional detector types can also be plugged in.
|
||||
# Detectors may require additional configuration.
|
||||
# Refer to the Detectors configuration page for more information.
|
||||
type: cpu
|
||||
|
||||
# Optional: Database configuration
|
||||
database:
|
||||
# The path to store the SQLite DB (default: shown below)
|
||||
@@ -146,56 +157,44 @@ auth:
|
||||
- front_door
|
||||
- back_yard
|
||||
|
||||
# Optional: object detection models. Defaults to a single model on a CPU detector.
|
||||
# Optional: model modifications
|
||||
# NOTE: The default values are for the EdgeTPU detector.
|
||||
# Other detectors will require the model config to be set.
|
||||
models:
|
||||
# Optional: the camera environment this model is for (default: shown below)
|
||||
# Cameras select a model by setting detect -> scene to a matching value, and
|
||||
# a model with a scene of all is used by any camera that does not set one.
|
||||
# Valid values are all, indoor, outdoor, indoor_thermal, outdoor_thermal
|
||||
- scene: all
|
||||
# Required: hardware this model runs on, as <detector> or <detector>:<device>
|
||||
# See https://docs.frigate.video/configuration/object_detectors for the
|
||||
# detectors available and the devices each one accepts. All of a model's
|
||||
# devices must use the same detector. Listing the same device more than once
|
||||
# runs additional inference processes on it.
|
||||
devices:
|
||||
- edgetpu:pci:0
|
||||
# Required: path to the model. Frigate+ models use plus://<model_id> (default: automatic based on detector)
|
||||
path: /edgetpu_model.tflite
|
||||
# Required: path to the labelmap (default: shown below)
|
||||
labelmap_path: /labelmap.txt
|
||||
# Required: Object detection model input width (default: shown below)
|
||||
width: 320
|
||||
# Required: Object detection model input height (default: shown below)
|
||||
height: 320
|
||||
# Required: Object detection model input colorspace
|
||||
# Valid values are rgb, bgr, or yuv. (default: shown below)
|
||||
input_pixel_format: rgb
|
||||
# Required: Object detection model input tensor format
|
||||
# Valid values are nhwc, nchw, hwnc, or hwcn (default: shown below)
|
||||
input_tensor: nhwc
|
||||
# Optional: Data type of the model input tensor
|
||||
# Valid values are float, float_denorm, or int (default: shown below)
|
||||
input_dtype: int
|
||||
# Required: Object detection model architecture, used by detectors that support more
|
||||
# than one model type (openvino, onnx, rknn, memryx, axengine, synaptics, and others)
|
||||
# Valid values are ssd, yolox, yolonas, yolo-generic, rfdetr, dfine (default: shown below)
|
||||
model_type: ssd
|
||||
# Required: Label name modifications. These are merged into the standard labelmap.
|
||||
labelmap:
|
||||
2: vehicle
|
||||
# Optional: Map of object labels to their attribute labels (default: depends on model)
|
||||
attributes_map:
|
||||
person:
|
||||
- amazon
|
||||
- face
|
||||
car:
|
||||
- amazon
|
||||
- fedex
|
||||
- license_plate
|
||||
- ups
|
||||
model:
|
||||
# Required: path to the model. Frigate+ models use plus://<model_id> (default: automatic based on detector)
|
||||
path: /edgetpu_model.tflite
|
||||
# Required: path to the labelmap (default: shown below)
|
||||
labelmap_path: /labelmap.txt
|
||||
# Required: Object detection model input width (default: shown below)
|
||||
width: 320
|
||||
# Required: Object detection model input height (default: shown below)
|
||||
height: 320
|
||||
# Required: Object detection model input colorspace
|
||||
# Valid values are rgb, bgr, or yuv. (default: shown below)
|
||||
input_pixel_format: rgb
|
||||
# Required: Object detection model input tensor format
|
||||
# Valid values are nhwc, nchw, hwnc, or hwcn (default: shown below)
|
||||
input_tensor: nhwc
|
||||
# Optional: Data type of the model input tensor
|
||||
# Valid values are float, float_denorm, or int (default: shown below)
|
||||
input_dtype: int
|
||||
# Required: Object detection model architecture, used by detectors that support more
|
||||
# than one model type (openvino, onnx, rknn, memryx, axengine, synaptics, and others)
|
||||
# Valid values are ssd, yolox, yolonas, yolo-generic, rfdetr, dfine (default: shown below)
|
||||
model_type: ssd
|
||||
# Required: Label name modifications. These are merged into the standard labelmap.
|
||||
labelmap:
|
||||
2: vehicle
|
||||
# Optional: Map of object labels to their attribute labels (default: depends on model)
|
||||
attributes_map:
|
||||
person:
|
||||
- amazon
|
||||
- face
|
||||
car:
|
||||
- amazon
|
||||
- fedex
|
||||
- license_plate
|
||||
- ups
|
||||
|
||||
# Optional: Audio Events Configuration
|
||||
# NOTE: Can be overridden at the camera level
|
||||
@@ -218,8 +217,6 @@ audio:
|
||||
- fire_alarm
|
||||
- speech
|
||||
- yell
|
||||
# Optional: Audio label name modifications. These are merged into the standard audio labelmap.
|
||||
labelmap: {}
|
||||
# Optional: Filters to configure detection.
|
||||
filters:
|
||||
# Label that matches label in listen config.
|
||||
@@ -254,15 +251,11 @@ birdseye:
|
||||
# Optional: Encoding quality of the mpeg1 feed (default: shown below)
|
||||
# 1 is the highest quality, and 31 is the lowest. Lower quality feeds utilize less CPU resources.
|
||||
quality: 8
|
||||
# Optional: Activity types that include cameras in Birdseye (default: shown below)
|
||||
# Multiple activity types can be listed at the same time.
|
||||
# continuous: all cameras are included always
|
||||
# motion: included if motion was detected within the inactivity threshold
|
||||
# all_objects: included if a tracked object was present within the inactivity threshold
|
||||
# alerts: included while an alert review item is in progress
|
||||
# detections: included while a detection review item is in progress
|
||||
modes:
|
||||
- all_objects
|
||||
# Optional: Mode of the view. Available options are: objects, motion, and continuous
|
||||
# objects - cameras are included if they have had a tracked object within the last 30 seconds
|
||||
# motion - cameras are included if motion was detected in the last 30 seconds
|
||||
# continuous - all cameras are included always
|
||||
mode: objects
|
||||
# Optional: Threshold for camera activity to stop showing camera (default: shown below)
|
||||
inactivity_threshold: 30
|
||||
# Optional: Configure the birdseye layout
|
||||
@@ -293,9 +286,7 @@ ffmpeg:
|
||||
# Optional: output args for detect streams (default: shown below)
|
||||
detect: -threads 2 -f rawvideo -pix_fmt yuv420p
|
||||
# Optional: output args for record streams (default: shown below)
|
||||
record: preset-record-generic
|
||||
# Optional: output args for sub stream record streams (default: the record output args above)
|
||||
# record_sub: preset-record-generic
|
||||
record: preset-record-generic-audio-aac
|
||||
# Optional: Time in seconds to wait before ffmpeg retries connecting to the camera. (default: shown below)
|
||||
# If set too low, frigate will retry a connection to the camera's stream too frequently, using up the limited streams some cameras can allow at once
|
||||
# If set too high, then if a ffmpeg crash or camera stream timeout occurs, you could potentially lose up to a maximum of retry_interval second(s) of footage
|
||||
@@ -315,10 +306,6 @@ detect:
|
||||
width: 1280
|
||||
# Optional: height of the frame for the input with the detect role (default: use native stream resolution)
|
||||
height: 720
|
||||
# Optional: the environment this camera looks at, which picks the model it runs on
|
||||
# (default: the model with a scene of all)
|
||||
# Valid values are all, indoor, outdoor, indoor_thermal, outdoor_thermal
|
||||
scene: outdoor
|
||||
# Optional: desired fps for your camera for the input with the detect role (default: shown below)
|
||||
# NOTE: Recommended value of 5. Ideally, try and reduce your FPS on the camera.
|
||||
fps: 5
|
||||
@@ -650,42 +637,6 @@ record:
|
||||
# For example, if the camera retain mode is "motion", the segments without motion are
|
||||
# never stored, so setting the mode to "all" here won't bring them back.
|
||||
mode: motion
|
||||
# Optional: Sub stream recording settings
|
||||
# Records a second, lower quality stream for quality selection during playback
|
||||
# and extended low quality retention. Requires the record_sub role to be assigned
|
||||
# to one of the camera's inputs.
|
||||
sub:
|
||||
# Optional: Enable sub stream recording (default: shown below)
|
||||
# NOTE: Recording must also be enabled for sub stream recording to run.
|
||||
enabled: False
|
||||
# Optional: Continuous retention settings for sub stream recordings
|
||||
continuous:
|
||||
# Optional: Number of days to retain sub stream recordings regardless of tracked objects or motion (default: shown below)
|
||||
days: 0
|
||||
# Optional: Motion retention settings for sub stream recordings
|
||||
motion:
|
||||
# Optional: Number of days to retain sub stream recordings triggered by motion (default: shown below)
|
||||
days: 0
|
||||
# Optional: Retention settings for sub stream recordings of alerts
|
||||
# NOTE: Pre and post capture windows are taken from the main alerts config above.
|
||||
alerts:
|
||||
# Required: Retention days (default: shown below)
|
||||
days: 10
|
||||
# Optional: Mode for retention. (default: shown below)
|
||||
# all - save all sub stream recording segments for alerts regardless of activity
|
||||
# motion - save all sub stream recording segments for alerts with any detected motion
|
||||
# active_objects - save all sub stream recording segments for alerts with active/moving objects
|
||||
mode: motion
|
||||
# Optional: Retention settings for sub stream recordings of detections
|
||||
# NOTE: Pre and post capture windows are taken from the main detections config above.
|
||||
detections:
|
||||
# Required: Retention days (default: shown below)
|
||||
days: 10
|
||||
# Optional: Mode for retention. (default: shown below)
|
||||
# all - save all sub stream recording segments for detections regardless of activity
|
||||
# motion - save all sub stream recording segments for detections with any detected motion
|
||||
# active_objects - save all sub stream recording segments for detections with active/moving objects
|
||||
mode: motion
|
||||
|
||||
# Optional: Configuration for the snapshots written to the clips directory for each tracked object
|
||||
# Timestamp, bounding_box, crop and height settings are applied by default to API requests for snapshots.
|
||||
@@ -937,7 +888,7 @@ cameras:
|
||||
# Required: the path to the stream
|
||||
# NOTE: path may include environment variables or docker secrets, which must begin with 'FRIGATE_' and be referenced in {}
|
||||
- path: rtsp://viewer:{FRIGATE_RTSP_PASSWORD}@10.0.10.10:554/cam/realmonitor?channel=1&subtype=2
|
||||
# Required: list of roles for this stream. valid values are: audio,detect,record,record_sub
|
||||
# Required: list of roles for this stream. valid values are: audio,detect,record
|
||||
# NOTICE: In addition to assigning the audio, detect, and record roles
|
||||
# they must also be enabled in the camera config.
|
||||
roles:
|
||||
|
||||
@@ -63,9 +63,15 @@ go2rtc:
|
||||
|
||||
### `environment_vars`
|
||||
|
||||
This section sets environment variables in the Frigate process for those unable to modify the environment of the container, like within Home Assistant OS. It's meant for process settings such as `LIBVA_DRIVER_NAME` or the TensorFlow thread counts below. Docker users should set environment variables in their `docker run` command (`-e LIBVA_DRIVER_NAME=i965`) or `docker-compose.yml` file (`environment:` section) instead. Values set here are stored in plain text in your config file, so credentials belong in `secrets.yaml`, Docker environment variables, or Docker secrets instead.
|
||||
This section can be used to set environment variables for those unable to modify the environment of the container, like within Home Assistant OS. Docker users should set environment variables in their `docker run` command (`-e FRIGATE_MQTT_PASSWORD=secret`) or `docker-compose.yml` file (`environment:` section) instead. Note that values set here are stored in plain text in your config file, so if the goal is to keep credentials out of your configuration, use Docker environment variables or Docker secrets instead.
|
||||
|
||||
Names prefixed with `FRIGATE_` set here also take part in `{FRIGATE_VARIABLE_NAME}` substitution (see [below](#substitution-sources-and-precedence)), but `secrets.yaml` is the better home for them.
|
||||
Variables prefixed with `FRIGATE_` can be referenced in config fields that support environment variable substitution (such as MQTT host and credentials, camera stream URLs, and ONVIF host and credentials) using the `{FRIGATE_VARIABLE_NAME}` syntax.
|
||||
|
||||
:::note
|
||||
|
||||
The `go2rtc` section is an exception. go2rtc runs as a separate process, so its stream definitions can only be substituted with variables that exist in the container's environment (set via Docker `-e`, the `environment:` section of `docker-compose.yml`, or Docker secrets). Variables defined in the `environment_vars` block above are not available to go2rtc streams. Home Assistant app users, who cannot set container environment variables, must instead put credentials directly in their go2rtc stream URLs.
|
||||
|
||||
:::
|
||||
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
@@ -74,17 +80,23 @@ Navigate to <NavPath path="Settings > System > Environment variables" /> to add
|
||||
|
||||
| Field | Description |
|
||||
| ----------------- | --------------------------------------------------------- |
|
||||
| **Variable name** | The environment variable name (e.g., `LIBVA_DRIVER_NAME`) |
|
||||
| **Variable name** | The environment variable name (e.g., `FRIGATE_MQTT_USER`) |
|
||||
| **Value** | The value for the variable |
|
||||
|
||||
Names prefixed with `FRIGATE_` can also be referenced elsewhere in your configuration using the `{FRIGATE_VARIABLE_NAME}` syntax.
|
||||
Variables defined here can be referenced elsewhere in your configuration using the `{FRIGATE_VARIABLE_NAME}` syntax.
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
|
||||
```yaml
|
||||
environment_vars:
|
||||
LIBVA_DRIVER_NAME: i965
|
||||
FRIGATE_MQTT_USER: my_mqtt_user
|
||||
FRIGATE_MQTT_PASSWORD: my_mqtt_password
|
||||
|
||||
mqtt:
|
||||
host: "{FRIGATE_MQTT_HOST}"
|
||||
user: "{FRIGATE_MQTT_USER}"
|
||||
password: "{FRIGATE_MQTT_PASSWORD}"
|
||||
```
|
||||
|
||||
</TabItem>
|
||||
@@ -118,51 +130,6 @@ environment_vars:
|
||||
</TabItem>
|
||||
</ConfigTabs>
|
||||
|
||||
### `secrets.yaml`
|
||||
|
||||
A `secrets.yaml` file next to your `config.yml` is an additional source of `FRIGATE_` variables, for installs that can't set container environment variables or mount Docker secrets. It's a flat map of names to values, and it is never read or written by the Frigate UI:
|
||||
|
||||
```yaml
|
||||
FRIGATE_CAM_USER: viewer
|
||||
FRIGATE_CAM_PASS: "p@ss w0rd"
|
||||
FRIGATE_MQTT_HOST: mqtt.internal.example
|
||||
```
|
||||
|
||||
For Docker this is `/config/secrets.yaml` inside the container, so it lives in whatever host directory you mounted at `/config`. For the Home Assistant App it's `/addon_configs/<addon_directory>/secrets.yaml`, in the same folder as your `config.yml`; see [the App config directory](../config.md#accessing-app-config-dir) for the directory name for your variant.
|
||||
|
||||
Names must start with `FRIGATE_`, and nesting is not supported. `secrets.yaml` feeds `{FRIGATE_VARIABLE_NAME}` substitution, so the handful of variables Frigate reads straight from the process environment, such as `FRIGATE_JWT_SECRET`, still need a container environment variable or a Docker secret.
|
||||
|
||||
### Substitution sources and precedence
|
||||
|
||||
The same `{FRIGATE_VARIABLE_NAME}` placeholder resolves from four sources. When a name is defined in more than one, the higher one wins and a warning at startup names which source was used.
|
||||
|
||||
| Priority | Source | Where it's set | Who can use it |
|
||||
| ----------- | --------------------- | -------------------------------------------------------------------------- | ------------------------------ |
|
||||
| 1 (highest) | Docker secrets | Files in `/run/secrets`, or the directory named by `CREDENTIALS_DIRECTORY` | Docker, systemd |
|
||||
| 2 | Container environment | `docker run -e`, the `environment:` section of `docker-compose.yml` | Docker |
|
||||
| 3 | `secrets.yaml` | Next to `config.yml`, see above | Everyone, including the HA App |
|
||||
| 4 (lowest) | `environment_vars` | The block in `config.yml` described above | Everyone, including the HA App |
|
||||
|
||||
For example, with this `secrets.yaml`:
|
||||
|
||||
```yaml
|
||||
FRIGATE_MQTT_PASSWORD: from_secrets
|
||||
```
|
||||
|
||||
and this `config.yml`:
|
||||
|
||||
```yaml
|
||||
environment_vars:
|
||||
FRIGATE_MQTT_PASSWORD: from_config
|
||||
|
||||
mqtt:
|
||||
password: "{FRIGATE_MQTT_PASSWORD}"
|
||||
```
|
||||
|
||||
the password resolves to `from_secrets`, and the log shows `FRIGATE_MQTT_PASSWORD is defined in more than one place, using the value from secrets.yaml`. Add `-e FRIGATE_MQTT_PASSWORD=from_env` to the container and it resolves to `from_env` instead.
|
||||
|
||||
Referencing a name that no source defines is a config validation error naming the field.
|
||||
|
||||
### `database`
|
||||
|
||||
Tracked object and recording information is managed in a sqlite database at `/config/frigate.db`. If that database is deleted, recordings will be orphaned and will need to be cleaned up manually. They also won't show up in the Media Browser within Home Assistant.
|
||||
@@ -210,7 +177,7 @@ Custom models may also require different input tensor formats. The colorspace co
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
Navigate to <NavPath path="Settings > System > Detection models" /> and, on the model you want to change, open the **Custom Model** tab to configure the model path, dimensions, and input format.
|
||||
Navigate to <NavPath path="Settings > System > Detectors and model" /> and open the **Custom Model** tab to configure the model path, dimensions, and input format.
|
||||
|
||||
| Field | Description |
|
||||
| --------------------------------------------- | ------------------------------------ |
|
||||
@@ -225,14 +192,12 @@ Navigate to <NavPath path="Settings > System > Detection models" /> and, on the
|
||||
|
||||
```yaml
|
||||
# Optional: model config
|
||||
models:
|
||||
- devices:
|
||||
- openvino:GPU
|
||||
path: /path/to/model
|
||||
width: 320
|
||||
height: 320
|
||||
input_tensor: "nhwc"
|
||||
input_pixel_format: "bgr"
|
||||
model:
|
||||
path: /path/to/model
|
||||
width: 320
|
||||
height: 320
|
||||
input_tensor: "nhwc"
|
||||
input_pixel_format: "bgr"
|
||||
```
|
||||
|
||||
</TabItem>
|
||||
@@ -249,15 +214,15 @@ If the labelmap is customized then the labels used for alerts will need to be ad
|
||||
The labelmap can be customized to your needs. A common reason to do this is to combine multiple object types that are easily confused when you don't need to be as granular such as car/truck. By default, truck is renamed to car because they are often confused. You cannot add new object types, but you can change the names of existing objects in the model.
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- labelmap:
|
||||
2: vehicle
|
||||
3: vehicle
|
||||
5: vehicle
|
||||
7: vehicle
|
||||
15: animal
|
||||
16: animal
|
||||
17: animal
|
||||
model:
|
||||
labelmap:
|
||||
2: vehicle
|
||||
3: vehicle
|
||||
5: vehicle
|
||||
7: vehicle
|
||||
15: animal
|
||||
16: animal
|
||||
17: animal
|
||||
```
|
||||
|
||||
Note that if you rename objects in the labelmap, you will also need to update your `objects -> track` list as well.
|
||||
@@ -397,10 +362,6 @@ To do this:
|
||||
2. Update the `ffmpeg.path` in your Frigate config to `/config/custom-ffmpeg`.
|
||||
3. Restart Frigate and the custom version will be used if the steps above were done correctly.
|
||||
|
||||
Both binaries have to be executable by Frigate's unprivileged runtime user, so `chmod 755` them after extracting. The startup ownership sweep runs only once, so anything you add to `/config` later keeps whatever ownership and mode you gave it.
|
||||
|
||||
There is one exception, and it only affects [`FRIGATE_ROOT_SERVICES`](/configuration/non_root#keeping-individual-services-root) listing `frigate`. That mode runs Frigate as root while still handing `/config` to the unprivileged runtime user, so anything running as that user could swap the binary and gain root. A build inside any of Frigate's writable volumes (`/config`, `/media/frigate`, the cache and shm dirs) is ignored there and the bundled one is used, with a warning in the log. Keep the build somewhere root-owned (any absolute `ffmpeg.path` works, so a read-only bind mount such as `/opt/custom-ffmpeg` is enough) if you need both. The default mode and `FRIGATE_RUN_AS_ROOT=true` are unaffected and behave exactly as they always have.
|
||||
|
||||
### Custom go2rtc version
|
||||
|
||||
Frigate currently includes go2rtc v1.9.14, there may be certain cases where you want to run a different version of go2rtc.
|
||||
@@ -409,11 +370,9 @@ To do this:
|
||||
|
||||
1. Download the go2rtc build to the `/config` folder.
|
||||
2. Rename the build to `go2rtc`.
|
||||
3. Give `go2rtc` execute permission for all users (`chmod 755`). It runs as its own `go2rtc` user, which doesn't own the file, so owner-only execute permission isn't enough.
|
||||
3. Give `go2rtc` execute permission.
|
||||
4. Restart Frigate and the custom version will be used, you can verify by checking go2rtc logs.
|
||||
|
||||
The same exception applies, and again only to [`FRIGATE_ROOT_SERVICES`](/configuration/non_root#keeping-individual-services-root) listing `go2rtc`: the binary is ignored there and the embedded one is used, with a warning in the log. Unlike `ffmpeg.path`, the go2rtc binary location is not configurable, so there is no outside-`/config` alternative. Use `FRIGATE_RUN_AS_ROOT=true` instead if you need both a custom go2rtc build and root. The default mode and the escape hatch both honor `/config/go2rtc` exactly as they always have.
|
||||
|
||||
## Validating your config.yml file updates
|
||||
|
||||
When frigate starts up, it checks whether your config file is valid, and if it is not, the process exits. To minimize interruptions when updating your config, you have three options -- you can edit the config via the WebUI which has built in validation, use the config API, or you can validate on the command line using the frigate docker container.
|
||||
|
||||
@@ -114,30 +114,6 @@ audio:
|
||||
</TabItem>
|
||||
</ConfigTabs>
|
||||
|
||||
#### Grouping Audio Labels
|
||||
|
||||
Related audio classes can be grouped under one label by mapping their numeric
|
||||
class IDs to the same name. Add the grouped name to `listen` and use it for any
|
||||
corresponding filter:
|
||||
|
||||
```yaml
|
||||
audio:
|
||||
listen:
|
||||
- dogs
|
||||
labelmap:
|
||||
69: dogs # dog
|
||||
70: dogs # bark
|
||||
75: dogs # whimper_dog
|
||||
filters:
|
||||
dogs:
|
||||
threshold: 0.8
|
||||
```
|
||||
|
||||
Class IDs are zero-based indices in
|
||||
[`audio-labelmap.txt`](https://github.com/blakeblackshear/frigate/blob/dev/audio-labelmap.txt),
|
||||
so each ID is one less than the displayed file line number.
|
||||
Audio label mappings are separate from the object detector's `model.labelmap`.
|
||||
|
||||
### Common Audio Labels
|
||||
|
||||
The labelmap includes hundreds of sound types. The labels below are the ones most users may find practical, grouped by what they're typically used for. Use the exact label string from the left column in your `listen` config, or search for the label in the Frigate UI directly.
|
||||
|
||||
@@ -22,9 +22,7 @@ The following ports are available to access the Frigate web UI.
|
||||
|
||||
## Onboarding
|
||||
|
||||
On startup, an admin user and password are generated and printed in the logs. It is recommended to set a new password for the admin account after logging in for the first time.
|
||||
|
||||
On a new install the [setup wizard](../guides/getting_started.md#configuring-frigate) offers this as its first step, along with creating accounts for anyone else who needs access. You can also do both at any time under <NavPath path="Settings > Users" />.
|
||||
On startup, an admin user and password are generated and printed in the logs. It is recommended to set a new password for the admin account after logging in for the first time under Settings > Users.
|
||||
|
||||
## Resetting admin password
|
||||
|
||||
|
||||
@@ -18,17 +18,13 @@ Each camera tile in Birdseye is composed from the frames of the stream assigned
|
||||
|
||||
## Birdseye Behavior
|
||||
|
||||
### Birdseye Activity Types
|
||||
### Birdseye Modes
|
||||
|
||||
Birdseye offers independent activity types that control when cameras are shown. Multiple activity types can be listed together.
|
||||
Birdseye offers different modes to customize which cameras show under which circumstances.
|
||||
|
||||
- **continuous:** The camera is always included
|
||||
- **motion:** The camera is included when motion was detected within the last 30 seconds
|
||||
- **all_objects:** The camera is included when a tracked object is present, active or stationary
|
||||
- **alerts:** The camera is included while an alert review item is in progress
|
||||
- **detections:** The camera is included while a detection review item is in progress
|
||||
|
||||
`alerts` and `detections` follow the review item's own lifetime, so the camera is removed as soon as the review item ends. Which objects qualify for each is set in [review configuration](./review.md).
|
||||
- **continuous:** All cameras are always included
|
||||
- **motion:** Cameras that have detected motion within the last 30 seconds are included
|
||||
- **objects:** Cameras that have tracked an active object within the last 30 seconds are included
|
||||
|
||||
### Custom Birdseye Icon
|
||||
|
||||
@@ -43,29 +39,27 @@ To include a camera in Birdseye view only for specific circumstances, or exclude
|
||||
|
||||
**Global settings:** Navigate to <NavPath path="Settings > System > Birdseye" /> to configure the default Birdseye behavior for all cameras.
|
||||
|
||||
**Per-camera overrides:** Navigate to <NavPath path="Settings > Camera configuration > Birdseye" /> to override the activity types or disable Birdseye for a specific camera.
|
||||
**Per-camera overrides:** Navigate to <NavPath path="Settings > Camera configuration > Birdseye" /> to override the mode or disable Birdseye for a specific camera.
|
||||
|
||||
| Field | Description |
|
||||
| ---------------------- | ---------------------------------------------------------- |
|
||||
| **Enable Birdseye** | Whether this camera appears in Birdseye view |
|
||||
| **Activity types** | Conditions that determine when to show the camera |
|
||||
| Field | Description |
|
||||
| ------------------- | ------------------------------------------------------------- |
|
||||
| **Enable Birdseye** | Whether this camera appears in Birdseye view |
|
||||
| **Tracking mode** | When to show the camera: `continuous`, `motion`, or `objects` |
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
|
||||
```yaml {10-12,15-16}
|
||||
```yaml {8-10,12-14}
|
||||
# Include all cameras by default in Birdseye view
|
||||
birdseye:
|
||||
enabled: True
|
||||
modes:
|
||||
- continuous
|
||||
mode: continuous
|
||||
|
||||
cameras:
|
||||
front:
|
||||
# Only include the "front" camera in Birdseye view when an alert is in progress
|
||||
# Only include the "front" camera in Birdseye view when objects are detected
|
||||
birdseye:
|
||||
modes:
|
||||
- alerts
|
||||
mode: objects
|
||||
back:
|
||||
# Exclude the "back" camera from Birdseye view
|
||||
birdseye:
|
||||
@@ -77,7 +71,7 @@ cameras:
|
||||
|
||||
### Birdseye Inactivity
|
||||
|
||||
By default birdseye shows all cameras that have had the configured activity in the last 30 seconds. This threshold can be configured, and applies to the `motion` and `all_objects` activity types only.
|
||||
By default birdseye shows all cameras that have had the configured activity in the last 30 seconds. This threshold can be configured.
|
||||
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
@@ -146,8 +140,7 @@ Navigate to <NavPath path="Settings > System > Birdseye" /> and in the **Camera
|
||||
# Include all cameras by default in Birdseye view
|
||||
birdseye:
|
||||
enabled: True
|
||||
modes:
|
||||
- continuous
|
||||
mode: continuous
|
||||
|
||||
cameras:
|
||||
front:
|
||||
|
||||
@@ -9,7 +9,7 @@ import NavPath from "@site/src/components/NavPath";
|
||||
|
||||
## Adding a camera with the Add Camera Wizard
|
||||
|
||||
The Add Camera Wizard is the recommended way to add a camera. Click **Add Camera** in <NavPath path="Settings > Global configuration > Camera management" />, or use it from the [setup wizard](../guides/getting_started.md#configuring-frigate) on a new install. The wizard connects to your camera, tests each stream, and writes the camera's configuration for you, including the [go2rtc](go2rtc.md) restream and the live view stream mapping, so a standard setup needs no hand-written YAML.
|
||||
The Add Camera Wizard is the recommended way to add a camera. Click **Add Camera** in <NavPath path="Settings > Global configuration > Camera management" />. The wizard connects to your camera, tests each stream, and writes the camera's configuration for you, including the [go2rtc](go2rtc.md) restream and the live view stream mapping, so a standard setup needs no hand-written YAML.
|
||||
|
||||
### Step 1: Name and connection
|
||||
|
||||
@@ -83,12 +83,11 @@ A camera is enabled by default but can be disabled by using `enabled: False`. Ca
|
||||
|
||||
Each role can only be assigned to one input per camera. The options for roles are as follows:
|
||||
|
||||
| Role | Description |
|
||||
| ------------ | ------------------------------------------------------------------------------------------------------------ |
|
||||
| `detect` | Main feed for object detection. [docs](object_detectors.md) |
|
||||
| `record` | Saves segments of the video feed based on configuration settings. [docs](record.md) |
|
||||
| `record_sub` | Saves segments of a second, lower quality stream with its own retention. [docs](record.md#sub-stream-recording) |
|
||||
| `audio` | Feed for audio based detection. [docs](audio_detectors.md) |
|
||||
| Role | Description |
|
||||
| -------- | ----------------------------------------------------------------------------------- |
|
||||
| `detect` | Main feed for object detection. [docs](object_detectors.md) |
|
||||
| `record` | Saves segments of the video feed based on configuration settings. [docs](record.md) |
|
||||
| `audio` | Feed for audio based detection. [docs](audio_detectors.md) |
|
||||
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
@@ -100,7 +100,7 @@ VS Code supports JSON schemas for automatically validating configuration files.
|
||||
|
||||
## Environment Variable Substitution
|
||||
|
||||
Frigate supports the use of environment variables starting with `FRIGATE_` **only** where specifically indicated in the [reference config](./advanced/reference.md). See [substitution sources and precedence](./advanced/system.md#substitution-sources-and-precedence) for where those values can come from, including `secrets.yaml`. For example, the following values can be replaced at runtime by using environment variables:
|
||||
Frigate supports the use of environment variables starting with `FRIGATE_` **only** where specifically indicated in the [reference config](./advanced/reference.md). For example, the following values can be replaced at runtime by using environment variables:
|
||||
|
||||
```yaml
|
||||
mqtt:
|
||||
@@ -154,7 +154,7 @@ Here are some common starter configuration examples. These can be configured thr
|
||||
|
||||
1. Navigate to <NavPath path="Settings > System > MQTT" /> and configure the MQTT connection to your Home Assistant Mosquitto broker
|
||||
2. Navigate to <NavPath path="Settings > Global configuration > FFmpeg" /> and set **Hardware acceleration arguments** to `Raspberry Pi (H.264)`
|
||||
3. Navigate to <NavPath path="Settings > System > Detection models" /> and select **Coral EdgeTPU (USB)** from the **Hardware** dropdown
|
||||
3. Navigate to <NavPath path="Settings > System > Detectors and model" /> and add a detector with **Type** `EdgeTPU` and **Device** `usb`
|
||||
4. Navigate to <NavPath path="Settings > Global configuration > Recording" /> and set **Enable recording** to on, **Motion retention > Retention days** to `7`, **Alert retention > Event retention > Retention days** to `30`, **Alert retention > Event retention > Retention mode** to `motion`, **Detection retention > Event retention > Retention days** to `30`, **Detection retention > Event retention > Retention mode** to `motion`
|
||||
5. Navigate to <NavPath path="Settings > Global configuration > Snapshots" /> and set **Enable snapshots** to on, **Snapshot retention > Default retention** to `30`
|
||||
6. Navigate to <NavPath path="Settings > Global configuration > Camera management" /> and add your camera with the appropriate RTSP stream URL
|
||||
@@ -172,9 +172,10 @@ mqtt:
|
||||
ffmpeg:
|
||||
hwaccel_args: preset-rpi-64-h264
|
||||
|
||||
models:
|
||||
- devices:
|
||||
- edgetpu:usb
|
||||
detectors:
|
||||
coral:
|
||||
type: edgetpu
|
||||
device: usb
|
||||
|
||||
record:
|
||||
enabled: True
|
||||
@@ -232,7 +233,7 @@ cameras:
|
||||
|
||||
1. Navigate to <NavPath path="Settings > System > MQTT" /> and set **Enable MQTT** to off
|
||||
2. Navigate to <NavPath path="Settings > Global configuration > FFmpeg" /> and set **Hardware acceleration arguments** to `VAAPI (Intel/AMD GPU)`
|
||||
3. Navigate to <NavPath path="Settings > System > Detection models" /> and select **Coral EdgeTPU (USB)** from the **Hardware** dropdown
|
||||
3. Navigate to <NavPath path="Settings > System > Detectors and model" /> and add a detector with **Type** `EdgeTPU` and **Device** `usb`
|
||||
4. Navigate to <NavPath path="Settings > Global configuration > Recording" /> and set **Enable recording** to on, **Motion retention > Retention days** to `7`, **Alert retention > Event retention > Retention days** to `30`, **Alert retention > Event retention > Retention mode** to `motion`, **Detection retention > Event retention > Retention days** to `30`, **Detection retention > Event retention > Retention mode** to `motion`
|
||||
5. Navigate to <NavPath path="Settings > Global configuration > Snapshots" /> and set **Enable snapshots** to on, **Snapshot retention > Default retention** to `30`
|
||||
6. Navigate to <NavPath path="Settings > Global configuration > Camera management" /> and add your camera with the appropriate RTSP stream URL
|
||||
@@ -248,9 +249,10 @@ mqtt:
|
||||
ffmpeg:
|
||||
hwaccel_args: preset-vaapi
|
||||
|
||||
models:
|
||||
- devices:
|
||||
- edgetpu:usb
|
||||
detectors:
|
||||
coral:
|
||||
type: edgetpu
|
||||
device: usb
|
||||
|
||||
record:
|
||||
enabled: True
|
||||
@@ -308,8 +310,8 @@ cameras:
|
||||
|
||||
1. Navigate to <NavPath path="Settings > System > MQTT" /> and configure the connection to your MQTT broker
|
||||
2. Navigate to <NavPath path="Settings > Global configuration > FFmpeg" /> and set **Hardware acceleration arguments** to `VAAPI (Intel/AMD GPU)`
|
||||
3. Navigate to <NavPath path="Settings > System > Detection models" /> and select **Intel GPU** from the **Hardware** dropdown
|
||||
4. On the same model, open the **Custom Model** tab and configure the OpenVINO model path and settings
|
||||
3. Navigate to <NavPath path="Settings > System > Detectors and model" /> and add a detector with **Type** `openvino` and **Device** `AUTO`
|
||||
4. On the same page, in the **Custom Model** tab, configure the OpenVINO model path and settings
|
||||
5. Navigate to <NavPath path="Settings > Global configuration > Recording" /> and set **Enable recording** to on, **Motion retention > Retention days** to `7`, **Alert retention > Event retention > Retention days** to `30`, **Alert retention > Event retention > Retention mode** to `motion`, **Detection retention > Event retention > Retention days** to `30`, **Detection retention > Event retention > Retention mode** to `motion`
|
||||
6. Navigate to <NavPath path="Settings > Global configuration > Snapshots" /> and set **Enable snapshots** to on, **Snapshot retention > Default retention** to `30`
|
||||
7. Navigate to <NavPath path="Settings > Global configuration > Camera management" /> and add your camera with the appropriate RTSP stream URL
|
||||
@@ -327,12 +329,15 @@ mqtt:
|
||||
ffmpeg:
|
||||
hwaccel_args: preset-vaapi
|
||||
|
||||
models:
|
||||
- devices:
|
||||
- openvino:AUTO
|
||||
width: 300
|
||||
height: 300
|
||||
input_tensor: nhwc
|
||||
detectors:
|
||||
ov:
|
||||
type: openvino
|
||||
device: AUTO
|
||||
|
||||
model:
|
||||
width: 300
|
||||
height: 300
|
||||
input_tensor: nhwc
|
||||
input_pixel_format: bgr
|
||||
path: /openvino-model/ssdlite_mobilenet_v2.xml
|
||||
labelmap_path: /openvino-model/coco_91cl_bkgr.txt
|
||||
|
||||
@@ -106,5 +106,3 @@ Output arguments are passed to FFmpeg after your camera source and control how r
|
||||
| preset-record-mjpeg | Record - MJPEG Cameras | Record an MJPEG stream | Restreaming the MJPEG stream is recommended instead |
|
||||
| preset-record-jpeg | Record - JPEG Cameras | Record a live JPEG | Restreaming the live JPEG is recommended instead |
|
||||
| preset-record-ubiquiti | Record - Ubiquiti Cameras | Record a Ubiquiti stream with audio | Handles Ubiquiti's non-standard audio format |
|
||||
|
||||
These presets apply to the `record` output args. If [sub stream recording](/configuration/record#sub-stream-recording) is enabled, the same args are used for the `record_sub` role unless `output_args.record_sub` is set, which accepts the same presets and manual args.
|
||||
|
||||
@@ -312,9 +312,8 @@ ffmpeg:
|
||||
|
||||
:::note
|
||||
|
||||
If running Frigate through Docker, map the relevant `/dev/video*` devices into
|
||||
the container. Running in privileged mode also works but grants far more access
|
||||
than needed. With Docker Compose add:
|
||||
If running Frigate through Docker, you either need to run in privileged mode or
|
||||
map the `/dev/video*` devices to Frigate. With Docker Compose add:
|
||||
|
||||
```yaml {4-5}
|
||||
services:
|
||||
@@ -499,7 +498,7 @@ cameras:
|
||||
|
||||
## Synaptics
|
||||
|
||||
Hardware accelerated video de-/encoding is supported on Synpatics SL-series SoC.
|
||||
Hardware accelerated video de-/encoding is supported on Synaptics SL-series SoC.
|
||||
|
||||
### Prerequisites
|
||||
|
||||
|
||||
@@ -378,10 +378,10 @@ Navigate to <NavPath path="Settings > Camera configuration > Object detection" /
|
||||
|
||||
Navigate to <NavPath path="Settings > Camera configuration > Objects" />.
|
||||
|
||||
| Field | Description |
|
||||
| ---------------------------------------------- | ------------------- |
|
||||
| **Objects to track** | Add `license_plate` |
|
||||
| **Object filters > License Plate > Threshold** | Set to `0.7` |
|
||||
| Field | Description |
|
||||
| --------------------------------------------------------- | ------------------- |
|
||||
| **Objects to track** | Add `license_plate` |
|
||||
| **Object filters > License Plate > Confidence threshold** | Set to `0.7` |
|
||||
|
||||
Navigate to <NavPath path="Settings > Camera configuration > Motion detection" />.
|
||||
|
||||
|
||||
@@ -1,280 +0,0 @@
|
||||
---
|
||||
id: non_root
|
||||
title: Running as a non-root user
|
||||
---
|
||||
|
||||
# Running as a non-root user
|
||||
|
||||
Frigate's services run as an unprivileged user inside the container. The main Frigate process and nginx run as `frigate`, and go2rtc runs as its own more restricted `go2rtc` user. Only the s6 init system and the certsync helper stay root.
|
||||
|
||||
The runtime user is uid/gid `1000:1000` by default. You can change it with `PUID`/`PGID`, or bypass Frigate's user handling entirely with Docker's own `user:`.
|
||||
|
||||
Most upgrades need nothing. Frigate aligns your volume ownership on the first boot and grants access to your hardware at startup. The sections below cover the cases that need attention: large storage volumes, network storage, and hardware the automatic grant can't reach.
|
||||
|
||||
## Run modes
|
||||
|
||||
| Mode | How to enable | Ownership of `/config` and `/media/frigate` | `read_only: true` |
|
||||
| ------------------- | ------------------------------- | ------------------------------------------------------ | ----------------- |
|
||||
| Default | nothing, this is the default | Aligned to `1000:1000` on first boot | Not supported |
|
||||
| `PUID`/`PGID` | `PUID=1001`, `PGID=1001` | Aligned to the values you set, on first boot | Not supported |
|
||||
| Docker-native user | `user: "1001:1001"` | You own it, Frigate never changes ownership | Not supported |
|
||||
| Root (escape hatch) | `FRIGATE_RUN_AS_ROOT=true` | Never touched | Not supported |
|
||||
| Granular root | `FRIGATE_ROOT_SERVICES=frigate` | Aligned at boot; recordings and exports also at create | Not supported |
|
||||
|
||||
`PUID`/`PGID` remapping runs `usermod` at startup, which writes to `/etc/passwd`, so it can't work with a read-only root filesystem. That combination stops at startup with a message pointing here.
|
||||
|
||||
`FRIGATE_RUN_AS_ROOT` is matched against the exact lowercase string `true`. `True`, `TRUE`, and `1` are all ignored. `FRIGATE_DEVICE_ACLS` works the same way: only the lowercase string `false` turns off the automatic device grants.
|
||||
|
||||
### Keeping individual services root
|
||||
|
||||
`FRIGATE_ROOT_SERVICES` takes a comma separated list of `frigate`, `go2rtc`, and `nginx`. A listed service keeps running as root, and everything else about non-root operation still applies: `PUID`/`PGID` remapping, the ownership sweep, and ownership of the files those services create.
|
||||
|
||||
There are two reasons to use it:
|
||||
|
||||
- Your detector hardware won't work as an unprivileged user, even after reading [Hardware device access](#hardware-device-access). `FRIGATE_ROOT_SERVICES=frigate` keeps the main process and its detectors as root while nginx and go2rtc stay unprivileged.
|
||||
- You want everything to run as root but still want your files owned by `PUID`/`PGID` instead of root. `FRIGATE_ROOT_SERVICES=frigate,go2rtc,nginx` does that.
|
||||
|
||||
Try the device grants and `EXTRA_GROUPS` first. The `frigate` service runs the API and every ffmpeg process that decodes your camera streams, so listing it puts those back on root as well, not just your detectors.
|
||||
|
||||
A listed service also stops honoring a [custom ffmpeg or go2rtc build](/configuration/advanced/system#custom-dependencies) kept in `/config`, since that directory stays owned by the unprivileged user and a binary there would run as root. `FRIGATE_RUN_AS_ROOT=true` has no such restriction.
|
||||
|
||||
Recordings and exports are owned by `PUID`/`PGID` as soon as they're written, even by a root service. Snapshots, thumbnails, and other files under `clips/` are corrected on each restart, so they can show as root-owned from the host until then. A listed service also keeps root's home directory, so library caches go to the container layer instead of `/config`.
|
||||
|
||||
Listing all three services is not the same as `FRIGATE_RUN_AS_ROOT=true`. The escape hatch never touches ownership; the list keeps the ownership handling active. A few more details:
|
||||
|
||||
- An unknown name in the list stops the container at startup, rather than silently leaving a service unprivileged.
|
||||
- Changing the list runs the full ownership sweep once on the next boot.
|
||||
- If both are set, `FRIGATE_RUN_AS_ROOT=true` wins and the list is ignored.
|
||||
- With Docker's `user:`, the list does nothing, since the container never has root to keep.
|
||||
|
||||
## Migrating an existing install
|
||||
|
||||
Volumes from earlier versions of Frigate are owned by root, so ownership has to be aligned with the runtime user once. This happens automatically on the first boot after upgrading.
|
||||
|
||||
On large recordings volumes, do it from the host beforehand instead. The boot sweep runs before any service starts, so a multi-terabyte `/media/frigate` can hold the container in startup long enough for Docker's healthcheck to mark it unhealthy, and orchestrators that watch health will restart it mid-sweep. If you'd rather not run the script, raise the healthcheck start period instead (`--start-period=1800s`, or `start_period: 1800s` under `healthcheck:` in compose).
|
||||
|
||||
Grab [`fix-permissions.sh`](https://github.com/blakeblackshear/frigate/blob/dev/docker/migration/fix-permissions.sh) from the Frigate repo and dry run it first:
|
||||
|
||||
```bash
|
||||
./fix-permissions.sh --dry-run /path/to/your/config /path/to/your/storage
|
||||
```
|
||||
|
||||
That reports how many entries would change and touches nothing. When it looks right, run it without `--dry-run`:
|
||||
|
||||
```bash
|
||||
./fix-permissions.sh /path/to/your/config /path/to/your/storage
|
||||
```
|
||||
|
||||
Pass `PUID` and `PGID` as the third and fourth arguments if you're not using the default `1000:1000`. The script wraps the same helper the container uses, so the result is identical either way. Override the image it pulls with `FRIGATE_IMAGE=...` if you're not on `stable`.
|
||||
|
||||
Both the script and the boot sweep report progress, so you can tell a slow sweep from a stuck one:
|
||||
|
||||
```
|
||||
[INFO] fix-ownership: scanning /media/frigate for ownership mismatches; this may take a while on large filesystems
|
||||
[WARN] fix-ownership: adjusting ownership of 4823941 entries under /media/frigate
|
||||
[INFO] fix-ownership: /media/frigate 5% (241197/4823941 entries)
|
||||
[INFO] fix-ownership: /media/frigate 10% (482394/4823941 entries)
|
||||
[INFO] fix-ownership: finished /media/frigate in 12m 4s
|
||||
```
|
||||
|
||||
The scan has no percentage because the total isn't known until it finishes. Watch the boot sweep with `docker logs -f frigate`.
|
||||
|
||||
Once the volumes are aligned, start Frigate normally. A file at `/config/.permissions_version` records what was done, so later boots skip the sweep unless you change `PUID`/`PGID`.
|
||||
|
||||
If something under your volumes can't be chowned, a read-only btrfs snapshot directory for example, the sweep warns and names the path and doesn't record the migration as finished. It retries on the next boot instead. Either move those paths outside `/media/frigate` or expect the scan to repeat.
|
||||
|
||||
### Network storage
|
||||
|
||||
Recordings on a NAS behave differently, so check what you have before migrating:
|
||||
|
||||
```bash
|
||||
findmnt -T /path/to/your/storage -o TARGET,FSTYPE,OPTIONS
|
||||
```
|
||||
|
||||
**SMB and CIFS** don't store per-file ownership at all. It's synthesized from the mount options, so a per-file `chown` fails and isn't needed. Mount the share as the uid and gid Frigate runs as, and every file already looks correct to the sweep:
|
||||
|
||||
```
|
||||
//nas/frigate /media/frigate cifs credentials=/root/.smb,uid=1000,gid=1000,file_mode=0664,dir_mode=0775 0 0
|
||||
```
|
||||
|
||||
**NFS** exports default to `root_squash` on most servers, which maps the container's root to `nobody`. The chown then fails, you get `[WARN] fix-ownership: some entries under /media/frigate could not be updated`, and since the sweep didn't finish it doesn't record the migration, so it retries on every boot.
|
||||
|
||||
The best fix is to not chown over NFS at all. Do it on the server, where there's no squash and no network round trip per file:
|
||||
|
||||
```bash
|
||||
# on the NAS itself, against the exported directory
|
||||
chown -R 1000:1000 /export/frigate
|
||||
```
|
||||
|
||||
Frigate's sweep then finds nothing to change and records the migration normally. If you can't get a shell on the server, you can export temporarily with `no_root_squash`, migrate, and put it back, or leave ownership alone and set `PUID`/`PGID` to whichever uid already owns the files.
|
||||
|
||||
Either way the uid has to mean the same thing on both machines. NFS sends numeric uids, so container uid 1000 is uid 1000 on the server no matter what the usernames are.
|
||||
|
||||
Expect the first boot to be slow even when nothing needs changing, because checking ownership costs a round trip per file. That's a one-time cost. **If the sweep runs on every boot rather than once, ownership isn't actually being applied**, and the warning above will say so.
|
||||
|
||||
Keep `/config` on local storage either way. Frigate's database is SQLite and network shares handle its locking poorly. That's a long-standing recommendation, not something running non-root introduces.
|
||||
|
||||
## Rolling back
|
||||
|
||||
Set `FRIGATE_RUN_AS_ROOT=true` and restart. Everything runs as root again, exactly as it did before. This is the fastest way to get a broken install running while you sort out a device permission problem.
|
||||
|
||||
The escape hatch never changes ownership, and it clears the record of the last sweep on startup, so switching back to non-root later corrects whatever root created in the meantime. Toggling in either direction is safe.
|
||||
|
||||
## Hardware device access
|
||||
|
||||
Frigate grants the runtime user access to your devices at startup. Pass your hardware with `--device` (or `devices:` in compose) and detection and hardware acceleration work with no group or udev setup on the host.
|
||||
|
||||
The grant covers the common accelerator and camera nodes: GPU render nodes, Intel/AMD NPUs (`/dev/accel`), Coral, Hailo, Rockchip, Jetson, `/dev/video*`, and the USB bus. For hardware it misses, add your own paths with `DEVICE_ACL_PATHS`, a comma separated list of globs:
|
||||
|
||||
```yaml
|
||||
environment:
|
||||
DEVICE_ACL_PATHS: "/dev/mydev*"
|
||||
```
|
||||
|
||||
Set `FRIGATE_DEVICE_ACLS=false` if you manage device permissions yourself and want Frigate to leave them alone.
|
||||
|
||||
Frigate grants access by adding an ACL entry for the runtime users. The device's owner and mode are unchanged, and nothing is made world accessible. One thing to know: `--device` nodes belong to the container, but a bind mounted `/dev/bus/usb` (the usual Coral USB setup) shares the host's device nodes, so the entry is visible on the host until udev recreates the node.
|
||||
|
||||
### Manual setup
|
||||
|
||||
You only need this for hardware the automatic grant can't reach, or for Docker's `user:` mode, where there's no root startup to do the granting.
|
||||
|
||||
Your accelerator most likely worked in older versions because Frigate ran as root. Device nodes are usually owned by `root:root`, and root either matches the group or skips the check entirely. The runtime user does neither, so a device that worked before can become unreadable with no change to your Frigate config.
|
||||
|
||||
#### Read what your device requires
|
||||
|
||||
Find the node and look at its owner, group, and mode:
|
||||
|
||||
```bash
|
||||
ls -ln /dev/dri/renderD128
|
||||
crw-rw---- 1 0 105 226, 128 Jul 5 10:12 /dev/dri/renderD128
|
||||
# ^ ^ ^
|
||||
# | | group GID 105
|
||||
# | owner UID 0 (root)
|
||||
# mode: owner rw, group rw, other none
|
||||
```
|
||||
|
||||
Then work out which of the three permission sets applies to the runtime user. It isn't the owner, since that's root, so it gets the group bits if it belongs to that GID and otherwise falls through to "other". In the example above "other" is empty, so without membership in group 105 the runtime user can't open the node.
|
||||
|
||||
Watch for a node that looks permissive but isn't. A USB Coral defaults to this:
|
||||
|
||||
```bash
|
||||
ls -ln /dev/bus/usb/004/003
|
||||
crw-rw-r-- 1 0 0 189, 386 Jul 5 10:12 /dev/bus/usb/004/003
|
||||
```
|
||||
|
||||
The group is `0`, so "other" applies to the runtime user, and "other" here is read only. `libedgetpu` needs to write to the node, so detection fails with `No EdgeTPU was detected` as though no Coral were attached. Read access alone isn't enough for most accelerators.
|
||||
|
||||
#### Grant access
|
||||
|
||||
Give the runtime user the GID with `EXTRA_GROUPS`, a comma separated list of numeric host GIDs. They're added to both the `frigate` and `go2rtc` users, which matters because go2rtc needs its own render and video access for hardware accelerated restreams.
|
||||
|
||||
```yaml
|
||||
environment:
|
||||
EXTRA_GROUPS: "105,44" # host render and video GIDs
|
||||
```
|
||||
|
||||
Use numeric GIDs from the host, not names. Group names don't have to match between the host and the container, and the kernel only checks the number. If the GID doesn't exist in the image, Frigate creates a placeholder group for it.
|
||||
|
||||
Two things that look like they should work but don't:
|
||||
|
||||
- Docker's `group_add` has no effect in the default or `PUID` modes. Frigate rebuilds the supplementary group list from `/etc/group` when it drops privileges, which discards what Docker passed in. It is the right tool with Docker's `user:`, where no privilege drop happens and `EXTRA_GROUPS` does nothing.
|
||||
- `privileged: true` doesn't help. It grants capabilities to root, and the runtime user isn't root, so the file permissions on the node still apply.
|
||||
|
||||
If the node's group is `root` or the mode denies the group, no `EXTRA_GROUPS` value will help. You need a udev rule first.
|
||||
|
||||
#### Verify access
|
||||
|
||||
Check the group landed, then check the runtime user can open the node. Test for write, not just read:
|
||||
|
||||
```bash
|
||||
docker exec frigate id frigate
|
||||
docker exec frigate /command/s6-setuidgid frigate sh -c 'test -w /dev/dri/renderD128 && echo ok'
|
||||
docker exec frigate /command/s6-setuidgid go2rtc sh -c 'test -w /dev/dri/renderD128 && echo ok'
|
||||
```
|
||||
|
||||
A permission check is only a proxy for the driver working. These exercise the real libraries as the runtime user:
|
||||
|
||||
```bash
|
||||
docker exec frigate /command/s6-setuidgid frigate vainfo
|
||||
docker exec frigate /command/s6-setuidgid frigate python3 -c "import openvino as ov; print(ov.Core().available_devices)"
|
||||
```
|
||||
|
||||
`vainfo` should reach `va_openDriver() returns 0` and list profiles. Complaints about `XDG_RUNTIME_DIR` or an X server above that are normal. OpenVINO should list `GPU`; if it returns only `CPU`, detection has fallen back and inference will be much slower without an error in the log.
|
||||
|
||||
To tell a permissions problem from anything else, start the container once with `FRIGATE_RUN_AS_ROOT=true`. If the device works as root and not otherwise, it's node permissions and a udev rule is the fix. If it's missing either way, the problem is your device mapping or the host, and isn't related to running non-root.
|
||||
|
||||
#### udev rules by device
|
||||
|
||||
Rules go in `/etc/udev/rules.d/` on the host and take effect after:
|
||||
|
||||
```bash
|
||||
sudo udevadm control --reload-rules && sudo udevadm trigger
|
||||
```
|
||||
|
||||
A device that's already connected sometimes keeps its original ownership through a trigger. If `ls -ln` doesn't show the new group, replug it, or reboot for a built-in device.
|
||||
|
||||
**Coral USB** needs two rules, because the device re-enumerates after loading firmware. It appears as Global Unichip `1a6e` before and Google `18d1` after, with a different node each time. A rule covering only `1a6e` gives you a Coral that starts up once and then disappears mid-run.
|
||||
|
||||
```
|
||||
SUBSYSTEM=="usb", ATTRS{idVendor}=="1a6e", GROUP="plugdev", MODE="0664"
|
||||
SUBSYSTEM=="usb", ATTRS{idVendor}=="18d1", GROUP="plugdev", MODE="0664"
|
||||
```
|
||||
|
||||
Map the whole `/dev/bus/usb` rather than a single node, for the same reason. Most hosts put `plugdev` at GID 46 and the image agrees, so a USB Coral often needs no `EXTRA_GROUPS` entry. Confirm with `getent group plugdev` and add the number if your host differs.
|
||||
|
||||
**Coral PCIe** is often `crw------- root root`, which only root can open:
|
||||
|
||||
```
|
||||
SUBSYSTEM=="apex", MODE="0660", GROUP="apex"
|
||||
```
|
||||
|
||||
Create the group with `sudo groupadd -f apex`, then add its GID to `EXTRA_GROUPS`.
|
||||
|
||||
**Hailo** works the same way. Grant `/dev/hailo0` a group and add that GID:
|
||||
|
||||
```
|
||||
SUBSYSTEM=="hailo_chardev", MODE="0660", GROUP="hailo"
|
||||
```
|
||||
|
||||
**Intel and AMD GPUs** usually need nothing beyond `EXTRA_GROUPS`, since most distributions ship a `render` group that owns `/dev/dri/renderD128`. The GID often differs between the host and the image, so pass the host's number rather than assuming the name resolves. Debian based images have no `render` group at all.
|
||||
|
||||
#### Quick reference
|
||||
|
||||
What each device needs when you're setting it up by hand. The automatic grant covers most of these already, so start here only if it didn't.
|
||||
|
||||
| Hardware | Device(s) | What non-root needs |
|
||||
| ------------------------- | ----------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- |
|
||||
| Intel/AMD GPU (VAAPI/QSV) | `/dev/dri/renderD128` | Host render GID in `EXTRA_GROUPS`, from `getent group render` |
|
||||
| Intel/AMD NPU | `/dev/accel` | udev rule granting a group, then that GID in `EXTRA_GROUPS` |
|
||||
| Coral USB | `/dev/bus/usb` | udev rules for both `1a6e` and `18d1`; usually already covered by `plugdev` 46 |
|
||||
| Coral PCIe | `/dev/apex_0` | udev rule granting a group, then that GID in `EXTRA_GROUPS` |
|
||||
| Hailo | `/dev/hailo0` | udev rule granting a group, then that GID in `EXTRA_GROUPS` |
|
||||
| NVIDIA | nvidia runtime | Nothing, works with the nvidia-container-toolkit defaults |
|
||||
| AMD ROCm | `/dev/kfd`, `/dev/dri` | Host `video` and `render` GIDs in `EXTRA_GROUPS` |
|
||||
| Raspberry Pi | `/dev/video11` | Host `video` GID in `EXTRA_GROUPS` |
|
||||
| Rockchip | `/dev/dri`, `/dev/dma_heap`, `/dev/rga`, `/dev/mpp_service` | Commonly `root:root` `0600`, so all four need udev rules. If you can't grant all four, use `FRIGATE_RUN_AS_ROOT` |
|
||||
| Axera (AXCL) | `/dev/ax_*` per the AXCL driver docs | Unverified. Check node ownership on your hardware before assuming this works |
|
||||
| Synaptics SL1680 | per the Synaptics docs | Unverified |
|
||||
| MemryX | per the MemryX docs | Still requires `privileged: true`, which means root. Out of scope for non-root operation |
|
||||
| Nvidia Jetson | nvidia runtime plus Jetson nodes | Unverified. The nvidia runtime handles mapping, but check `/dev/nvhost-*` ownership on your board |
|
||||
| VeriSilicon NPU (Teflon) | per the driver, commonly `/dev/galcore` | Unverified. Check node ownership on your hardware before assuming this works |
|
||||
| CPU detector | none | Nothing, no device is opened |
|
||||
| ZMQ detector | none | Nothing, inference happens over a socket |
|
||||
| Apple Silicon | none | Nothing, the NPU client runs on the host and Frigate reaches it over the network |
|
||||
|
||||
## Known limitations
|
||||
|
||||
`telemetry.stats.network_bandwidth` uses nethogs, which needs `CAP_NET_ADMIN` and `CAP_NET_RAW` and therefore root. The stat is turned off automatically when Frigate isn't running as root, with one warning in the log. Use `FRIGATE_ROOT_SERVICES=frigate` (or `FRIGATE_RUN_AS_ROOT=true`) if you need it.
|
||||
|
||||
go2rtc's ffmpeg processes no longer appear in Intel GPU stats. Frigate reads per-process GPU usage from `/proc/<pid>/fdinfo`, which the kernel won't let one user read for another user's processes, so anything go2rtc spawns is invisible to it. Overall GPU utilization is unaffected.
|
||||
|
||||
If you mount your own TLS certificate at `/etc/letsencrypt/live/frigate`, the private key has to be readable by the runtime user, which runs nginx. Frigate hands the key to that user at startup if the mount is writable; on a read-only mount, make the key readable by uid 1000 (or your `PUID`) yourself.
|
||||
|
||||
If you're debugging nginx, run the config check as the runtime user with stdout discarded:
|
||||
|
||||
```bash
|
||||
docker exec frigate /command/s6-setuidgid frigate bash -c 'nginx -t -c /tmp/nginx/conf/nginx.conf >/dev/null'
|
||||
```
|
||||
|
||||
Running `nginx -t` as root hands nginx's runtime directories to root as a side effect, which breaks the running workers until the service restarts, and the config's `/dev/stdout` logs can't be reopened through a root-owned `docker exec` pipe. The results print on stderr either way.
|
||||
@@ -29,6 +29,7 @@ Frigate supports multiple different detectors that work on different types of ha
|
||||
|
||||
- [ROCm](#amdrocm-gpu-detector): ROCm can run on AMD Discrete GPUs to provide efficient object detection.
|
||||
- [ONNX](#onnx): ROCm will automatically be detected and used as a detector in the `-rocm` Frigate image when a supported ONNX model is configured.
|
||||
- <CommunityBadge /> [XDNA2](#amd-xdna2): AMD Ryzen AI / XDNA2 NPUs can run object detection through the community-maintained `frigate-xdna` ZMQ sidecar.
|
||||
|
||||
**Apple Silicon**
|
||||
|
||||
@@ -68,66 +69,12 @@ Frigate supports multiple different detectors that work on different types of ha
|
||||
|
||||
:::note
|
||||
|
||||
A single model can not be spread across different detector types (ex: OpenVINO and Coral EdgeTPU can not run the same model at the same time). Configuring more than one model, each on its own detector type, is supported.
|
||||
Multiple detectors can not be mixed for object detection (ex: OpenVINO and Coral EdgeTPU can not be used for object detection at the same time).
|
||||
|
||||
This does not affect using hardware for accelerating other tasks such as [semantic search](./semantic_search.md)
|
||||
|
||||
:::
|
||||
|
||||
### Configuring models and hardware
|
||||
|
||||
Object detection is configured with a `models` list. Each entry describes one model and the hardware it runs on:
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices:
|
||||
- openvino:GPU
|
||||
path: /config/model_cache/yolov9-s.onnx
|
||||
model_type: yolo-generic
|
||||
width: 320
|
||||
height: 320
|
||||
```
|
||||
|
||||
Each entry in `devices` is a detector type, optionally followed by a colon and a device for that detector, such as `edgetpu:pci:0`, `openvino:NPU`, or `tensorrt:0`. The per-detector sections below document the device values each one accepts. Listing several devices runs the model on all of them, and listing the **same** device more than once runs additional inference processes against it, which can improve throughput on hardware that keeps up with more than one stream:
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices:
|
||||
- openvino:GPU
|
||||
- openvino:GPU
|
||||
```
|
||||
|
||||
Coral EdgeTPU and MemryX accelerators can only be opened by one process, so those devices can not be repeated.
|
||||
|
||||
### Running more than one model
|
||||
|
||||
Cameras can be split across models by scene, which is useful when indoor and outdoor cameras benefit from differently trained models. Each model declares the `scene` it is for, and each camera picks one with `detect -> scene`:
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- scene: outdoor
|
||||
path: plus://your-outdoor-model
|
||||
devices:
|
||||
- edgetpu:pci:0
|
||||
- scene: indoor
|
||||
path: /config/model_cache/indoor.onnx
|
||||
model_type: yolo-generic
|
||||
devices:
|
||||
- openvino:GPU
|
||||
|
||||
cameras:
|
||||
driveway:
|
||||
detect:
|
||||
scene: outdoor
|
||||
...
|
||||
hallway:
|
||||
detect:
|
||||
scene: indoor
|
||||
...
|
||||
```
|
||||
|
||||
Available scenes are `all`, `indoor`, `outdoor`, `indoor_thermal`, and `outdoor_thermal`. A model with a scene of `all` is used by every camera that does not set one, and `all` is the default when a model does not declare a scene. Changing a camera's scene requires a restart.
|
||||
|
||||
### Choosing a model size
|
||||
|
||||
Along with picking a detector for your hardware, you will choose a model's **input resolution** (such as `320x320` or `640x640`) and, for model families like YOLOv9, a **variant size** (`tiny`, `small`, etc.). Both affect the balance between accuracy and the inference time your hardware can sustain.
|
||||
@@ -146,11 +93,11 @@ The best detection accuracy comes from a model trained on images that look like
|
||||
|
||||
# Officially Supported Detectors
|
||||
|
||||
Frigate provides a number of builtin detector types. By default, Frigate will use a single CPU detector. Other detectors may require additional configuration as described below. Each of a model's devices runs in a dedicated process, and they pull from a common queue of detection requests from the cameras assigned to that model.
|
||||
Frigate provides a number of builtin detector types. By default, Frigate will use a single CPU detector. Other detectors may require additional configuration as described below. When using multiple detectors they will run in dedicated processes, but pull from a common queue of detection requests from across all cameras.
|
||||
|
||||
## Edge TPU Detector
|
||||
|
||||
The Edge TPU detector type runs TensorFlow Lite models utilizing the Google Coral delegate for hardware acceleration. To use it, prefix a model's device with `edgetpu`.
|
||||
The Edge TPU detector type runs TensorFlow Lite models utilizing the Google Coral delegate for hardware acceleration. To configure an Edge TPU detector, set the `"type"` attribute to `"edgetpu"`.
|
||||
|
||||
The Edge TPU device can be specified using the `"device"` attribute according to the [Documentation for the TensorFlow Lite Python API](https://coral.ai/docs/edgetpu/multiple-edgetpu/#using-the-tensorflow-lite-python-api). If not set, the delegate will use the first device it finds.
|
||||
|
||||
@@ -165,15 +112,16 @@ See [common Edge TPU troubleshooting steps](/troubleshooting/edgetpu) if the Edg
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
Navigate to <NavPath path="Settings > System > Detection models" /> and select **Coral EdgeTPU (USB)** from the **Hardware** dropdown.
|
||||
Navigate to <NavPath path="Settings > System > Detectors and model" /> and select **EdgeTPU** from the detector type dropdown and click **Add**, then set device to `usb`.
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices:
|
||||
- edgetpu:usb
|
||||
detectors:
|
||||
coral:
|
||||
type: edgetpu
|
||||
device: usb
|
||||
```
|
||||
|
||||
</TabItem>
|
||||
@@ -184,16 +132,19 @@ models:
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
Navigate to <NavPath path="Settings > System > Detection models" /> and select **Coral EdgeTPU (USB)** from the **Hardware** dropdown and check each Coral the model should run on.
|
||||
Navigate to <NavPath path="Settings > System > Detectors and model" /> and select **EdgeTPU** from the detector type dropdown and click **Add** to add multiple detectors, specifying `usb:0` and `usb:1` as the device for each.
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices:
|
||||
- edgetpu:usb:0
|
||||
- edgetpu:usb:1
|
||||
detectors:
|
||||
coral1:
|
||||
type: edgetpu
|
||||
device: usb:0
|
||||
coral2:
|
||||
type: edgetpu
|
||||
device: usb:1
|
||||
```
|
||||
|
||||
</TabItem>
|
||||
@@ -206,15 +157,16 @@ _warning: may have [compatibility issues](https://github.com/blakeblackshear/fri
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
Navigate to <NavPath path="Settings > System > Detection models" /> and select the **Coral EdgeTPU** entry from the **Hardware** dropdown.
|
||||
Navigate to <NavPath path="Settings > System > Detectors and model" /> and select **EdgeTPU** from the detector type dropdown and click **Add**, then leave the device field empty.
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices:
|
||||
- 'edgetpu:'
|
||||
detectors:
|
||||
coral:
|
||||
type: edgetpu
|
||||
device: ""
|
||||
```
|
||||
|
||||
</TabItem>
|
||||
@@ -225,15 +177,16 @@ models:
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
Navigate to <NavPath path="Settings > System > Detection models" /> and select **Coral EdgeTPU (PCIe)** from the **Hardware** dropdown.
|
||||
Navigate to <NavPath path="Settings > System > Detectors and model" /> and select **EdgeTPU** from the detector type dropdown and click **Add**, then set device to `pci`.
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices:
|
||||
- edgetpu:pci
|
||||
detectors:
|
||||
coral:
|
||||
type: edgetpu
|
||||
device: pci
|
||||
```
|
||||
|
||||
</TabItem>
|
||||
@@ -244,16 +197,19 @@ models:
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
Navigate to <NavPath path="Settings > System > Detection models" /> and select **Coral EdgeTPU (PCIe)** from the **Hardware** dropdown and check each Coral the model should run on.
|
||||
Navigate to <NavPath path="Settings > System > Detectors and model" /> and select **EdgeTPU** from the detector type dropdown and click **Add** to add multiple detectors, specifying `pci:0` and `pci:1` as the device for each.
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices:
|
||||
- edgetpu:pci:0
|
||||
- edgetpu:pci:1
|
||||
detectors:
|
||||
coral1:
|
||||
type: edgetpu
|
||||
device: pci:0
|
||||
coral2:
|
||||
type: edgetpu
|
||||
device: pci:1
|
||||
```
|
||||
|
||||
</TabItem>
|
||||
@@ -264,16 +220,19 @@ models:
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
Navigate to <NavPath path="Settings > System > Detection models" /> and select **Coral EdgeTPU (USB)** from the **Hardware** dropdown. USB and PCIe Corals are listed as separate hardware, so mixing the two on one model has to be done in YAML.
|
||||
Navigate to <NavPath path="Settings > System > Detectors and model" /> and select **EdgeTPU** from the detector type dropdown and click **Add** to add multiple detectors with different device types (e.g., `usb` and `pci`).
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices:
|
||||
- edgetpu:usb
|
||||
- edgetpu:pci
|
||||
detectors:
|
||||
coral_usb:
|
||||
type: edgetpu
|
||||
device: usb
|
||||
coral_pci:
|
||||
type: edgetpu
|
||||
device: pci
|
||||
```
|
||||
|
||||
</TabItem>
|
||||
@@ -315,7 +274,7 @@ Hailo8 supports all models in the Hailo Model Zoo that include HailoRT post-proc
|
||||
|
||||
## OpenVINO Detector
|
||||
|
||||
The OpenVINO detector type runs an OpenVINO IR model on AMD and Intel CPUs, Intel GPUs and Intel NPUs. To use it, prefix a model's device with `openvino`.
|
||||
The OpenVINO detector type runs an OpenVINO IR model on AMD and Intel CPUs, Intel GPUs and Intel NPUs. To configure an OpenVINO detector, set the `"type"` attribute to `"openvino"`.
|
||||
|
||||
The OpenVINO device to be used is specified using the `"device"` attribute according to the naming conventions in the [Device Documentation](https://docs.openvino.ai/2025/openvino-workflow/running-inference/inference-devices-and-modes.html). The most common devices are `CPU`, `GPU`, or `NPU`.
|
||||
|
||||
@@ -328,18 +287,19 @@ OpenVINO is supported on 6th Gen Intel platforms (Skylake) and newer. It will al
|
||||
When using many cameras one detector may not be enough to keep up. Multiple detectors can be defined assuming GPU resources are available. An example configuration would be:
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices:
|
||||
- openvino:GPU # or NPU
|
||||
- openvino:GPU # or NPU
|
||||
detectors:
|
||||
ov_0:
|
||||
type: openvino
|
||||
device: GPU # or NPU
|
||||
ov_1:
|
||||
type: openvino
|
||||
device: GPU # or NPU
|
||||
```
|
||||
|
||||
:::
|
||||
|
||||
### Intel NPU host requirements {#intel-npu-requirements}
|
||||
|
||||
The NPU device must be passed into the container by adding `/dev/accel:/dev/accel` to the `devices` section of your compose file. Frigate grants the runtime user access to the device automatically; see [hardware device access](/configuration/non_root#hardware-device-access) if you manage device permissions yourself.
|
||||
|
||||
The NPU firmware is loaded by the host kernel and is not part of the Frigate image. Everything else the NPU needs is bundled in the container, so host NPU libraries should never be mounted in.
|
||||
|
||||
Frigate bundles a specific version of Intel's [linux-npu-driver](https://github.com/intel/linux-npu-driver/releases), and the host firmware must come from that release or a newer one. Firmware older than the bundled driver may fail with `MAPPED_INFERENCE_VERSION is NOT compatible with the ELF`, where `Expected` is the version the firmware supports and `received` is the version the bundled compiler produced. Distributions often package older firmware than the driver Frigate ships, so check the build date on the host with `sudo dmesg | grep -i vpu` and update it there if needed.
|
||||
@@ -354,12 +314,6 @@ Intel NPUs cannot be used under Home Assistant OS, which does not include the NP
|
||||
|
||||
## Apple Silicon detector
|
||||
|
||||
:::warning
|
||||
|
||||
The network-based detectors (Deepstack and the Apple Silicon client) are being reworked. Their extra options no longer have a place in the config, so only the endpoint carried in the device string is honored right now: Deepstack ignores `api_key` and `api_timeout`, and the Apple Silicon client ignores `request_timeout_ms` and `linger_ms`. Anything else is dropped when your config is migrated.
|
||||
|
||||
:::
|
||||
|
||||
The NPU in Apple Silicon can't be accessed from within a container, so the [Apple Silicon detector client](https://github.com/frigate-nvr/apple-silicon-detector) must first be setup. It is recommended to use the Frigate docker image with `-standard-arm64` suffix, for example `ghcr.io/blakeblackshear/frigate:stable-standard-arm64`.
|
||||
|
||||
### Setup {#setup-apple-silicon}
|
||||
@@ -500,10 +454,11 @@ If the correct build is used for your GPU then the GPU will be detected and used
|
||||
When using many cameras one detector may not be enough to keep up. Multiple detectors can be defined assuming GPU resources are available. An example configuration would be:
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices:
|
||||
- onnx
|
||||
- onnx
|
||||
detectors:
|
||||
onnx_0:
|
||||
type: onnx
|
||||
onnx_1:
|
||||
type: onnx
|
||||
```
|
||||
|
||||
:::
|
||||
@@ -516,7 +471,7 @@ models:
|
||||
|
||||
## CPU Detector (not recommended)
|
||||
|
||||
The CPU detector type runs a TensorFlow Lite model utilizing the CPU without hardware acceleration. It is recommended to use a hardware accelerated detector type instead for better performance. To use it, set a model's device to `cpu`.
|
||||
The CPU detector type runs a TensorFlow Lite model utilizing the CPU without hardware acceleration. It is recommended to use a hardware accelerated detector type instead for better performance. To configure a CPU based detector, set the `"type"` attribute to `"cpu"`.
|
||||
|
||||
:::danger
|
||||
|
||||
@@ -526,7 +481,7 @@ The CPU detector is not recommended for general use. If you do not have GPU or E
|
||||
|
||||
The number of threads used by the interpreter can be specified using the `"num_threads"` attribute, and defaults to `3.`
|
||||
|
||||
A TensorFlow Lite model is provided in the container at `/cpu_model.tflite` and is used by this detector type by default. To provide your own model, bind mount the file into the container and provide the path with the model's `path`.
|
||||
A TensorFlow Lite model is provided in the container at `/cpu_model.tflite` and is used by this detector type by default. To provide your own model, bind mount the file into the container and provide the path with `model.path`.
|
||||
|
||||
### Configuration {#configuration-cpu}
|
||||
|
||||
@@ -536,12 +491,6 @@ When using CPU detectors, you can add one CPU detector per camera. Adding more d
|
||||
|
||||
## Deepstack / CodeProject.AI Server Detector
|
||||
|
||||
:::warning
|
||||
|
||||
The network-based detectors (Deepstack and the Apple Silicon client) are being reworked. Their extra options no longer have a place in the config, so only the endpoint carried in the device string is honored right now: Deepstack ignores `api_key` and `api_timeout`, and the Apple Silicon client ignores `request_timeout_ms` and `linger_ms`. Anything else is dropped when your config is migrated.
|
||||
|
||||
:::
|
||||
|
||||
The Deepstack / CodeProject.AI Server detector for Frigate allows you to integrate Deepstack and CodeProject.AI object detection capabilities into Frigate. CodeProject.AI and DeepStack are open-source AI platforms that can be run on various devices such as the Raspberry Pi, Nvidia Jetson, and other compatible hardware. It is important to note that the integration is performed over the network, so the inference times may not be as fast as native Frigate detectors, but it still provides an efficient and reliable solution for object detection and tracking.
|
||||
|
||||
### Setup {#setup-deepstack}
|
||||
@@ -560,6 +509,28 @@ To verify that the integration is working correctly, start Frigate and observe t
|
||||
|
||||
# Community Supported Detectors
|
||||
|
||||
## AMD XDNA2
|
||||
|
||||
AMD Ryzen AI / XDNA2 NPUs can be used through the community-maintained
|
||||
[frigate-xdna](https://github.com/mitchins/frigate-xdna) detector sidecar.
|
||||
The sidecar runs separately from Frigate and connects using Frigate's ZMQ
|
||||
detector interface.
|
||||
|
||||
Currently qualified on **Ryzen AI Max 300 / Strix Halo**. Other XDNA2 devices
|
||||
are not yet qualified; XDNA1 is unsupported.
|
||||
|
||||
Follow the frigate-xdna setup instructions to prepare and start the sidecar
|
||||
before starting Frigate.
|
||||
|
||||
### Configuration {#configuration-xdna2}
|
||||
|
||||
Using the detector config below will connect Frigate to the sidecar:
|
||||
|
||||
<ModelConfigDropdown detectorTitle="AMD XDNA2" models={objectDetectorsModels.xdna2.models} />
|
||||
|
||||
The example assumes Frigate and the sidecar share a Docker network where the
|
||||
sidecar is named `xdna`.
|
||||
|
||||
## MemryX MX3
|
||||
|
||||
This detector is available for use with the MemryX MX3 accelerator M.2 module. Frigate supports the MX3 on compatible hardware platforms, providing efficient and high-performance object detection.
|
||||
@@ -604,7 +575,7 @@ For detailed instructions on compiling models, refer to the [MemryX Compiler](ht
|
||||
|
||||
3. Depending on the model, the compiler may also generate a cropped post-processing network. If present, it will be named with the suffix `_post.onnx`.
|
||||
|
||||
4. Bind-mount the `.zip` file into the container and specify its path using the model's `path` in your config.
|
||||
4. Bind-mount the `.zip` file into the container and specify its path using `model.path` in your config.
|
||||
|
||||
5. Update `labelmap_path` to match your custom model's labels.
|
||||
|
||||
@@ -734,10 +705,13 @@ If no custom model is provided, the RKNN detector downloads a default model from
|
||||
When using many cameras one detector may not be enough to keep up. Multiple detectors can be defined assuming NPU resources are available. An example configuration would be:
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices:
|
||||
- rknn:0
|
||||
- rknn:0
|
||||
detectors:
|
||||
rknn_0:
|
||||
type: rknn
|
||||
num_cores: 0
|
||||
rknn_1:
|
||||
type: rknn
|
||||
num_cores: 0
|
||||
```
|
||||
|
||||
:::
|
||||
|
||||
@@ -45,10 +45,10 @@ Any detection below `min_score` will be immediately thrown out and never tracked
|
||||
|
||||
Navigate to <NavPath path="Settings > Global configuration > Objects" /> to set score filters globally.
|
||||
|
||||
| Field | Description |
|
||||
| --------------------------------------- | ---------------------------------------------------------------- |
|
||||
| **Object filters > Person > Min Score** | Minimum score for a single detection to initiate tracking |
|
||||
| **Object filters > Person > Threshold** | Minimum computed (median) score to be considered a true positive |
|
||||
| Field | Description |
|
||||
| -------------------------------------------------- | ---------------------------------------------------------------- |
|
||||
| **Object filters > Person > Minimum confidence** | Minimum score for a single detection to initiate tracking |
|
||||
| **Object filters > Person > Confidence threshold** | Minimum computed (median) score to be considered a true positive |
|
||||
|
||||
To override score filters for a specific camera, navigate to <NavPath path="Settings > Camera configuration > Objects" /> and select the camera.
|
||||
|
||||
@@ -103,12 +103,12 @@ Conceptually, a ratio of 1 is a square, 0.5 is a "tall skinny" box, and 2 is a "
|
||||
|
||||
Navigate to <NavPath path="Settings > Global configuration > Objects" /> to set shape filters globally.
|
||||
|
||||
| Field | Description |
|
||||
| --------------------------------------- | ------------------------------------------------------------------------ |
|
||||
| **Object filters > Person > Min Area** | Minimum bounding box area in pixels (or decimal for percentage of frame) |
|
||||
| **Object filters > Person > Max Area** | Maximum bounding box area in pixels (or decimal for percentage of frame) |
|
||||
| **Object filters > Person > Min Ratio** | Minimum width/height ratio of the bounding box |
|
||||
| **Object filters > Person > Max Ratio** | Maximum width/height ratio of the bounding box |
|
||||
| Field | Description |
|
||||
| -------------------------------------------------- | ------------------------------------------------------------------------ |
|
||||
| **Object filters > Person > Minimum object area** | Minimum bounding box area in pixels (or decimal for percentage of frame) |
|
||||
| **Object filters > Person > Maximum object area** | Maximum bounding box area in pixels (or decimal for percentage of frame) |
|
||||
| **Object filters > Person > Minimum aspect ratio** | Minimum width/height ratio of the bounding box |
|
||||
| **Object filters > Person > Maximum aspect ratio** | Maximum width/height ratio of the bounding box |
|
||||
|
||||
To override shape filters for a specific camera, navigate to <NavPath path="Settings > Camera configuration > Objects" /> and select the camera.
|
||||
|
||||
|
||||
@@ -70,14 +70,14 @@ Object filters help reduce false positives by constraining the size, shape, and
|
||||
|
||||
Navigate to <NavPath path="Settings > Global configuration > Objects" />.
|
||||
|
||||
| Field | Description |
|
||||
| --------------------------------------- | ------------------------------------------------------------------------ |
|
||||
| **Object filters > Person > Min Area** | Minimum bounding box area in pixels (or decimal for percentage of frame) |
|
||||
| **Object filters > Person > Max Area** | Maximum bounding box area in pixels (or decimal for percentage of frame) |
|
||||
| **Object filters > Person > Min Ratio** | Minimum width/height ratio of the bounding box |
|
||||
| **Object filters > Person > Max Ratio** | Maximum width/height ratio of the bounding box |
|
||||
| **Object filters > Person > Min Score** | Minimum score for the object to initiate tracking |
|
||||
| **Object filters > Person > Threshold** | Minimum computed score to be considered a true positive |
|
||||
| Field | Description |
|
||||
| -------------------------------------------------- | ------------------------------------------------------------------------ |
|
||||
| **Object filters > Person > Minimum object area** | Minimum bounding box area in pixels (or decimal for percentage of frame) |
|
||||
| **Object filters > Person > Maximum object area** | Maximum bounding box area in pixels (or decimal for percentage of frame) |
|
||||
| **Object filters > Person > Minimum aspect ratio** | Minimum width/height ratio of the bounding box |
|
||||
| **Object filters > Person > Maximum aspect ratio** | Maximum width/height ratio of the bounding box |
|
||||
| **Object filters > Person > Minimum confidence** | Minimum score for the object to initiate tracking |
|
||||
| **Object filters > Person > Confidence threshold** | Minimum computed score to be considered a true positive |
|
||||
|
||||
To override filters for a specific camera, navigate to <NavPath path="Settings > Camera configuration > Objects" />.
|
||||
|
||||
|
||||
@@ -191,14 +191,12 @@ cameras:
|
||||
detect:
|
||||
enabled: false
|
||||
record:
|
||||
enabled: false
|
||||
enabled: true
|
||||
profiles:
|
||||
away:
|
||||
enabled: true
|
||||
detect:
|
||||
enabled: true
|
||||
record:
|
||||
enabled: true
|
||||
home:
|
||||
enabled: false
|
||||
```
|
||||
@@ -251,6 +249,12 @@ Leaving the `objects` section empty (or omitting `track`) does not clear the lis
|
||||
|
||||
Fields that require a Frigate restart to take effect cannot be overridden by profiles, since profiles are applied at runtime without restarting. Those fields are hidden when editing a profile override and can only be changed on the base configuration.
|
||||
|
||||
### Why can't a profile enable recording when it's disabled in the base config?
|
||||
|
||||
Frigate only sets up a camera's recording stream at startup when recording is enabled in the base config, so enabling it later from a profile has no effect. The same applies to turning recording on from the UI or MQTT.
|
||||
|
||||
To keep recording off by default, leave `record.enabled: true` in the base config and create a profile that sets `record.enabled: false`. Activate that profile and it will be restored automatically when Frigate starts.
|
||||
|
||||
### Can I schedule profiles to be enabled or disabled at certain times?
|
||||
|
||||
Not within Frigate itself. Frigate is an NVR, not an automation platform, so it intentionally does not include a scheduler for activating profiles. Instead, activate profiles from an automation platform that already handles time- and event-based triggers well, such as [Home Assistant](https://www.home-assistant.io/) or [Node-RED](https://nodered.org/). These integrate with Frigate and give you far more robust and flexible scheduling than a built-in scheduler could.
|
||||
|
||||
@@ -275,163 +275,6 @@ record:
|
||||
|
||||
This configuration will retain recording segments that overlap with alerts and detections for 10 days. Because multiple tracked objects can reference the same recording segments, this avoids storing duplicate footage for overlapping tracked objects and reduces overall storage needs.
|
||||
|
||||
## Sub Stream Recording
|
||||
|
||||
In addition to the main recording stream, Frigate can record a second, lower quality stream for each camera. This serves two purposes:
|
||||
|
||||
- **Quality selection during playback**: A quality selector (`Auto`, `Original`, or `Low`) appears in History view for cameras with sub stream recording enabled. `Original` and `Low` play only that stream's recordings. Time ranges where the selected stream has no footage are skipped during playback, and the selector notes when the selected stream has no recordings at all in the viewed time range. With `Auto` (the default), playback prefers the original quality and automatically falls back to the low quality stream when the connection cannot keep up, or for time ranges where the original recordings have expired. The selector shows each stream's video codec and audio details beneath the options; footage recorded by older Frigate versions shows no details.
|
||||
- **Extended retention**: Sub stream recordings have their own retention settings, fully independent of the main recordings. By giving the low quality recordings a longer retention period, you can keep weeks or months of low quality history using a fraction of the storage, and that history remains playable after the main recordings expire. Playback falls back to the low quality recordings automatically, and the timeline shows a muted treatment for time ranges where only low quality footage remains. Timeline previews are kept for as long as either stream still has recordings, so scrubbing works across the whole retained history.
|
||||
|
||||
### Configuring sub stream recording
|
||||
|
||||
Sub stream recording uses the `record_sub` input role. This role can be assigned to the same input as `detect`, so in the common case where detect already uses the camera's sub stream, no additional camera connection is needed. Like the main recording stream, sub stream segments are copied directly from the camera stream without re-encoding, so the recording quality is determined by the source stream.
|
||||
|
||||
The following examples keep 7 days of full quality continuous recordings and 60 days of low quality continuous recordings:
|
||||
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
Navigate to <NavPath path="Settings > Camera configuration > Streams (FFmpeg)" /> and select the camera.
|
||||
|
||||
- In **Camera inputs**, enable the **Record (Sub Stream)** role on the stream you want to record at low quality, commonly the same stream that has the **Detect** role. Only one stream may have this role, and it cannot be assigned to the same stream as the **Record** role.
|
||||
|
||||
Navigate to <NavPath path="Settings > Camera configuration > Recording" /> and select the camera.
|
||||
|
||||
- Set **Enable recording** to on
|
||||
- Set **Continuous retention > Retention days** to `7`
|
||||
- Set **Sub stream recording > Enable sub stream recording** to on
|
||||
- Set **Sub stream recording > Sub stream continuous retention > Retention days** to `60`
|
||||
|
||||
The camera setup wizard also offers the **Record (Sub Stream)** role when assigning stream roles for a newly added camera.
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
|
||||
```yaml
|
||||
cameras:
|
||||
front_door:
|
||||
ffmpeg:
|
||||
inputs:
|
||||
- path: rtsp://camera/main
|
||||
roles:
|
||||
- record
|
||||
- path: rtsp://camera/sub
|
||||
roles:
|
||||
- detect
|
||||
- record_sub
|
||||
record:
|
||||
enabled: true
|
||||
continuous:
|
||||
days: 7
|
||||
sub:
|
||||
enabled: true
|
||||
continuous:
|
||||
days: 60
|
||||
```
|
||||
|
||||
If your camera does not provide a suitable sub stream (or the sub stream is already used at a resolution you don't want to record), you can use a go2rtc transcode as the source for `record_sub` instead:
|
||||
|
||||
```yaml
|
||||
go2rtc:
|
||||
streams:
|
||||
front_door: rtsp://camera/main
|
||||
front_door_lq: ffmpeg:front_door#video=h264#width=854#hardware
|
||||
|
||||
cameras:
|
||||
front_door:
|
||||
ffmpeg:
|
||||
inputs:
|
||||
- path: rtsp://127.0.0.1:8554/front_door
|
||||
input_args: preset-rtsp-restream
|
||||
roles:
|
||||
- detect
|
||||
- record
|
||||
- path: rtsp://127.0.0.1:8554/front_door_lq
|
||||
input_args: preset-rtsp-restream
|
||||
roles:
|
||||
- record_sub
|
||||
record:
|
||||
enabled: true
|
||||
continuous:
|
||||
days: 7
|
||||
sub:
|
||||
enabled: true
|
||||
continuous:
|
||||
days: 60
|
||||
```
|
||||
|
||||
</TabItem>
|
||||
</ConfigTabs>
|
||||
|
||||
The `record.sub` config supports the same retention structure as the main recording config: `continuous`, `motion`, `alerts`, and `detections` each with their own `days` (and `mode` for alerts and detections). The pre-capture and post-capture windows for alerts and detections are taken from the main `record.alerts` and `record.detections` config. Extending `sub.alerts.days` or `sub.detections.days` beyond the main values also keeps those review items visible in the review timeline for the longer window, with playback falling back to the low quality stream once the main recordings expire.
|
||||
|
||||
:::note
|
||||
|
||||
Recording must be enabled (`record.enabled`) for sub stream recording to run, and Frigate will fail to start if `record.sub.enabled` is set without a `record_sub` role assigned to one of the camera's inputs.
|
||||
|
||||
:::
|
||||
|
||||
### How Auto picks a quality
|
||||
|
||||
`Auto` measures throughput on every segment download and compares it against the original stream's bitrate (computed from the recorded footage itself). Playback drops to the low quality stream when any of these happen:
|
||||
|
||||
- A freeze lasts 4 seconds (10 seconds when it starts within 2 seconds of a seek, since the seek target is rarely buffered), or freezes total 7 seconds within the last minute.
|
||||
- 3 downloads in a row measure below the original bitrate plus 10%, dropping quality before a stall ever becomes visible.
|
||||
- No first frame appears within 10 seconds, or loading fails outright.
|
||||
|
||||
Playback returns to full quality only when measured throughput exceeds the original bitrate by 50%, checked continuously while playing the low quality stream and again at each new hour. The asymmetric thresholds (1.1x to drop, 1.5x to return) keep a borderline connection from switching back and forth.
|
||||
|
||||
The most recent measurement is remembered on the device: a connection last measured below the original bitrate (or below 3 Mbps when the bitrate is not yet known) starts playback on the low quality stream so a first frame appears immediately, then upgrades within a few segments if the speed allows.
|
||||
|
||||
The quality selector shows which stream Auto is currently playing and why. A browser with Data Saver enabled stays on the low quality stream, a browser that cannot decode the original stream's codec (for example H.265 without HEVC support) plays the low quality stream for that camera, and pinning `Original` or `Low` bypasses Auto entirely.
|
||||
|
||||
### Sub stream output args
|
||||
|
||||
By default the sub stream is recorded with the same [output args](/configuration/ffmpeg_presets#output-args-presets) as the main recording stream, so it inherits any customization made to `ffmpeg.output_args.record`. Setting `ffmpeg.output_args.record_sub` gives the sub stream its own args instead. Like all `ffmpeg` config, this can be set globally or per camera.
|
||||
|
||||
The most common reason to set this is a pair of streams whose audio differs. Many cameras send AAC on the main stream but PCM on the sub stream, and PCM cannot be copied into an mp4 recording. Copying the main stream's audio avoids re-encoding audio that is already AAC, while the sub stream still needs to be transcoded:
|
||||
|
||||
```yaml
|
||||
ffmpeg:
|
||||
output_args:
|
||||
# main stream audio is already AAC, so copy it
|
||||
record: preset-record-generic-audio-copy
|
||||
# sub stream audio is PCM, so transcode it to AAC
|
||||
record_sub: preset-record-generic-audio-aac
|
||||
```
|
||||
|
||||
Other reasons to set this are recording a sub stream whose codec needs a different preset than the main stream, such as `preset-record-mjpeg`, or forcing a matching audio sample rate across the two streams with manual args ending in `-c:a aac -ar 16000`.
|
||||
|
||||
:::warning
|
||||
|
||||
Avoid removing audio from only one of the two streams (for example with `-an`). When one stream has audio and the other does not, playback of time ranges that combine both qualities is silent, so stripping audio from the sub stream also silences the merged timeline.
|
||||
|
||||
:::
|
||||
|
||||
### Which stream do features use?
|
||||
|
||||
As a general rule, features that read recordings prefer the main stream and fall back to the sub stream for time ranges where the main recordings have expired. Analytics features use only the main stream.
|
||||
|
||||
| Feature | Stream used |
|
||||
| ---------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------- |
|
||||
| Recording playback (History and Review) | Both (main preferred with sub fallback by default), or exactly one stream when a quality is selected manually |
|
||||
| Tracking details and Explore clip playback | Main, falling back to sub where the main recordings have expired |
|
||||
| Exports and clip downloads | Main; sub is used when no main recordings remain in the range (streams are never mixed in one file) |
|
||||
| Frames grabbed from a recording in History (download snapshot, submit frame to Frigate+) | Main preferred, sub fallback |
|
||||
| Audio extraction (e.g., transcription) | Main preferred, sub fallback |
|
||||
| Motion search | Main only |
|
||||
| Review timeline motion data | Main only |
|
||||
| Storage usage statistics | Both streams counted, and listed separately per camera |
|
||||
|
||||
This table covers only features that read recordings from disk. Tracked object snapshots and thumbnails (the images shown in Explore and sent with notifications, and the images submitted to Frigate+ from a tracked object) are captured live from the `detect` stream as the object is tracked, never from recordings, so sub stream recording does not affect them.
|
||||
|
||||
### Trade-offs
|
||||
|
||||
- Recording a second stream increases overall storage use. The increase is typically small relative to the main recordings, since the low quality stream is much smaller. Both streams are cached before being written to disk, so cache use goes up as well. See [the `/tmp/cache` area is separate](#the-tmpcache-area-is-separate) if you start seeing `No space left on device` errors after enabling it.
|
||||
- The go2rtc transcode approach continuously encodes the low quality stream, which uses CPU or GPU resources. This cost only applies to the transcode path; recording the camera's native sub stream does not re-encode. See the [go2rtc hardware acceleration documentation](https://github.com/AlexxIT/go2rtc?tab=readme-ov-file#source-ffmpeg) for accelerating the transcode.
|
||||
- Many camera sub streams do not include audio. If the source stream has no audio, the low quality recordings will not have audio.
|
||||
- **Matching video codecs and audio settings between the two streams gives the smoothest playback.** When playback combines both qualities on one timeline (the default `Auto` behavior: for example original quality during events with low quality in between, or low quality history after the original recordings expire) and the streams use different video codecs or audio settings, for example H.265 on the main stream and H.264 on the sub stream, or 16 kHz audio on one and 8 kHz on the other, playback still works: Frigate inserts a decoder reset at each quality transition, which can cause a barely-perceptible pause there. Configuring both streams in the camera's firmware to use the same video codec, audio codec, and sample rate makes transitions fully seamless, and a mismatched audio sample rate can also be corrected with [sub stream output args](#sub-stream-output-args). If one stream has audio and the other does not, combined time ranges play **without audio**; selecting a single quality with the playback selector always keeps that stream's audio.
|
||||
|
||||
## Can I have "continuous" recordings, but only at certain times?
|
||||
|
||||
Using Frigate UI, Home Assistant, or MQTT, cameras can be automated to only record in certain situations or at certain times.
|
||||
@@ -448,7 +291,7 @@ For advanced use cases, the [custom export HTTP API](../integrations/api/export-
|
||||
POST /export/custom/{camera_name}/start/{start_time}/end/{end_time}
|
||||
```
|
||||
|
||||
The request body accepts `ffmpeg_input_args` and `ffmpeg_output_args` to control encoding, frame rate, filters, and other FFmpeg options. If neither is provided, Frigate defaults to time-lapse output settings (25x speed, 30 FPS).
|
||||
The request body accepts `ffmpeg_input_args` and `ffmpeg_output_args` to control encoding, frame rate, filters, and other FFmpeg options. If neither is provided, Frigate defaults to time-lapse output settings (25x speed, 30 FPS) with audio removed (`-an`). When providing your own `ffmpeg_input_args`, include `-an` if you want audio stripped from the export.
|
||||
|
||||
The following example exports a time-lapse at 60x speed with 25 FPS:
|
||||
|
||||
|
||||
@@ -197,7 +197,7 @@ For cameras that support two-way talk, go2rtc will automatically establish an au
|
||||
To prevent this, you must configure two separate stream instances:
|
||||
|
||||
1. One stream instance with `#backchannel=0` for Frigate's viewing, recording, and detection (prevents go2rtc from establishing the blocking backchannel)
|
||||
2. A second stream instance without `#backchannel=0` for two-way talk functionality (can be used by Frigate's WebRTC viewer or other applications)
|
||||
2. A second stream instance with no `#` parameters at all for two-way talk functionality (can be used by Frigate's WebRTC viewer or other applications)
|
||||
|
||||
Configuration example:
|
||||
|
||||
@@ -215,13 +215,15 @@ In this configuration:
|
||||
- `front_door` stream is used by Frigate for viewing, recording, and detection. The `#backchannel=0` parameter prevents go2rtc from establishing the audio output backchannel, so it won't block two-way talk access.
|
||||
- `front_door_twoway` stream is used for two-way talk functionality. This stream can be used by Frigate's WebRTC viewer when two-way talk is enabled, or by other applications (like Home Assistant Advanced Camera Card) that need access to the camera's audio output channel.
|
||||
|
||||
Any `#` parameter on a bare `rtsp://` source disables the backchannel unless the URL explicitly contains `#backchannel=1`. A two-way talk stream with something like `#video=h264` on it silently loses two-way audio, and Frigate will report that two-way talk is unavailable for that stream.
|
||||
|
||||
## Security: Restricted Stream Sources
|
||||
|
||||
For security reasons, the `echo:`, `expr:`, and `exec:` stream sources are disabled by default in go2rtc. These sources allow arbitrary command execution and can pose security risks if misconfigured.
|
||||
|
||||
If you attempt to use these sources in your configuration, the streams will be removed and an error message will be printed in the logs.
|
||||
|
||||
To enable these sources, you must set the environment variable `GO2RTC_ALLOW_ARBITRARY_EXEC=true`. This can be done in your Docker Compose file or container environment, or for Home Assistant App users with the `go2rtc_allow_arbitrary_exec` option in the App's configuration. The `environment_vars` section of the Frigate config can't enable it:
|
||||
To enable these sources, you must set the environment variable `GO2RTC_ALLOW_ARBITRARY_EXEC=true`. This can be done in your Docker Compose file or container environment:
|
||||
|
||||
```yaml
|
||||
environment:
|
||||
|
||||
@@ -245,8 +245,8 @@ Triggers are best configured through the Frigate UI.
|
||||
1. Navigate to <NavPath path="Settings > Enrichments > Triggers" /> and select a camera from the dropdown menu.
|
||||
2. Click **Add Trigger** to create a new trigger or use the pencil icon to edit an existing one.
|
||||
3. In the **Create Trigger** wizard:
|
||||
- Enter a **Name** for the trigger (e.g., "Red Car Alert").
|
||||
- Enter a descriptive **Friendly Name** for the trigger (e.g., "Red car on the driveway camera").
|
||||
- Enter a **Name** for the trigger (e.g., "Red Car Alert"). Frigate derives the trigger's
|
||||
internal **ID** from this name, which can be revealed and edited with the show/hide toggle.
|
||||
- Select the **Type** (`Thumbnail` or `Description`).
|
||||
- For `Thumbnail`, select an image to trigger this action when a similar thumbnail image is detected, based on the threshold.
|
||||
- For `Description`, enter text to trigger this action when a similar tracked object description is detected.
|
||||
|
||||
@@ -28,7 +28,7 @@ During testing, enable the Zones option for the [Debug view](/usage/live#the-sin
|
||||
1. Navigate to <NavPath path="Settings > Camera configuration > Masks / Zones" /> and select the desired camera.
|
||||
2. Under the **Zones** section, click the plus icon to add a new zone.
|
||||
3. Click on the camera's latest image to create the points for the zone boundary. Click the first point again to close the polygon.
|
||||
4. Configure zone options such as **Friendly name**, **Objects**, **Loitering time**, and **Inertia** in the zone editor.
|
||||
4. Configure zone options such as **Name**, **Objects**, **Loitering Time**, and **Inertia** in the zone editor.
|
||||
5. Press **Save** when finished.
|
||||
|
||||
</TabItem>
|
||||
@@ -200,7 +200,7 @@ When using loitering zones, a review item will behave in the following way:
|
||||
|
||||
1. Navigate to <NavPath path="Settings > Camera configuration > Masks / Zones" /> and select the desired camera.
|
||||
2. Edit or create the zone (e.g., `sidewalk`).
|
||||
- Set **Loitering time** to the desired number of seconds (e.g., `4`)
|
||||
- Set **Loitering Time** to the desired number of seconds (e.g., `4`)
|
||||
- Under **Objects**, add the relevant object types (e.g., `person`)
|
||||
|
||||
</TabItem>
|
||||
@@ -291,7 +291,7 @@ Accurate real-world distance measurements are required to estimate speeds. These
|
||||
|
||||
1. Navigate to <NavPath path="Settings > Camera configuration > Masks / Zones" /> and select the desired camera.
|
||||
2. Create or edit a zone with exactly 4 points aligned to the ground plane.
|
||||
3. In the zone editor, enter the real-world **Distances** between each pair of consecutive points.
|
||||
3. In the zone editor, enable **Speed Estimation** and enter the real-world **Line A distance**, **Line B distance**, **Line C distance**, and **Line D distance** between each pair of consecutive points.
|
||||
- For example, if the distance between the first and second points is 10 meters, between the second and third is 12 meters, etc.
|
||||
4. Distances are measured in meters (metric) or feet (imperial), depending on the **Unit system** setting.
|
||||
|
||||
@@ -358,7 +358,7 @@ Zones can be configured with a minimum speed requirement, meaning an object must
|
||||
|
||||
1. Navigate to <NavPath path="Settings > Camera configuration > Masks / Zones" /> and select the desired camera.
|
||||
2. Edit or create the zone with distances configured.
|
||||
- Set **Speed threshold** to the desired minimum speed (e.g., `20`)
|
||||
- Set **Speed Threshold** to the desired minimum speed (e.g., `20`)
|
||||
- The unit is kph or mph, depending on the **Unit system** setting
|
||||
|
||||
</TabItem>
|
||||
|
||||
@@ -54,7 +54,7 @@ An object filter mask drops any [bounding box](#bounding-box) whose bottom cente
|
||||
|
||||
## Min Score
|
||||
|
||||
The lowest score a detected object can have to be kept during tracking. Anything scoring below the minimum is assumed to be a [false positive](#false-positive) and discarded.
|
||||
The lowest score a detected object can have to be kept during tracking. Anything scoring below the minimum is assumed to be a [false positive](#false-positive) and discarded. Set with `min_score` in the config, shown as **Minimum confidence** in the settings UI.
|
||||
|
||||
## Model
|
||||
|
||||
@@ -86,7 +86,7 @@ A more specific identity assigned to a [tracked object](#tracked-object-event-in
|
||||
|
||||
## Threshold
|
||||
|
||||
The median score an object must reach to be considered a true positive.
|
||||
The median score an object must reach to be considered a true positive. Set with `threshold` in the config, shown as **Confidence threshold** in the settings UI.
|
||||
|
||||
## Top Score
|
||||
|
||||
|
||||
@@ -70,6 +70,9 @@ Frigate supports multiple different detectors that work on different types of ha
|
||||
- [ROCm](#rocm---amd-gpu): ROCm can run on AMD Discrete GPUs to provide efficient object detection
|
||||
- [Supports limited model architectures](../../configuration/object_detectors#amdrocm-gpu-detector)
|
||||
- Runs best on discrete AMD GPUs
|
||||
- <CommunityBadge /> [XDNA2 (Ryzen AI)](#amd-xdna2): AMD XDNA2 NPU (sub-watt power AI/ML processor separate to the GPU) inside Strix and other "AI" branded AMD platforms
|
||||
- Has only been tested with YOLOv9, in theory other graphs may be compiled too.
|
||||
- Runs via ZMQ proxy which adds some latency, only recommended for local connection
|
||||
|
||||
**Apple Silicon**
|
||||
|
||||
@@ -296,6 +299,32 @@ The inference time of a rk3588 with all 3 cores enabled is typically 25-30 ms fo
|
||||
| ---------------- | ----------------------------------- |
|
||||
| yolov9-tiny | ~ 4 ms |
|
||||
|
||||
### AMD Ryzen AI / XDNA2
|
||||
|
||||
Frigate supports AMD XDNA2 NPUs through the community-maintained
|
||||
frigate-xdna ZMQ sidecar. It works with stock Frigate and supports
|
||||
Frigate+ models or compatible local YOLO ONNX models. Models are compiled
|
||||
once on the target system and cached for subsequent use.
|
||||
|
||||
Currently qualified on **Ryzen AI Max 300 / Strix Halo**. Other XDNA2
|
||||
devices are not yet qualified; XDNA1 is unsupported.
|
||||
|
||||
Measured YOLOv9 detector latency on Strix Halo:
|
||||
|
||||
| Model | 320 | 640 |
|
||||
| ----- | ---: | ---: |
|
||||
| YOLOv9-T | ~7.4 ms | unsupported |
|
||||
| YOLOv9-S | ~9.0 ms | ~20.0 ms |
|
||||
| YOLOv9-M | ~13.1 ms | ~34.4 ms |
|
||||
| YOLOv9-C | ~14.1 ms | ~35.2 ms |
|
||||
| YOLOv9-E | ~69.4 ms | ~224.8 ms |
|
||||
|
||||
**YOLOv9-C at 320 is the recommended quality/performance balance.**
|
||||
C at 640 is also usable where the lower throughput is acceptable.
|
||||
|
||||
Setup, model preparation, and compatibility details are available
|
||||
[in the frigate-xdna documentation](https://github.com/mitchins/frigate-xdna).
|
||||
|
||||
## What does Frigate use the CPU for and what does it use a detector for? (ELI5 Version)
|
||||
|
||||
This is taken from a [user question on reddit](https://www.reddit.com/r/homeassistant/comments/q8mgau/comment/hgqbxh5/?utm_source=share&utm_medium=web2x&context=3). Modified slightly for clarity.
|
||||
|
||||
@@ -514,7 +514,7 @@ Generate a Frigate Docker Compose configuration based on your hardware and requi
|
||||
services:
|
||||
frigate:
|
||||
container_name: frigate
|
||||
# privileged: true # ONLY enable if your hardware requires it (see hardware-specific docs); prefer the device mappings below
|
||||
privileged: true # this may not be necessary for all setups
|
||||
restart: unless-stopped
|
||||
stop_grace_period: 30s # allow enough time to shut down the various services
|
||||
image: ghcr.io/blakeblackshear/frigate:stable
|
||||
@@ -546,30 +546,6 @@ services:
|
||||
</TabItem>
|
||||
</Tabs>
|
||||
|
||||
### Recommended security options
|
||||
|
||||
Frigate does not need elevated container privileges for most setups. The following hardens the container; add the `devices`/`group_add` entries your hardware requires (see the hardware acceleration docs):
|
||||
|
||||
```yaml
|
||||
services:
|
||||
frigate:
|
||||
...
|
||||
security_opt:
|
||||
- no-new-privileges:true
|
||||
cap_drop:
|
||||
- ALL
|
||||
```
|
||||
|
||||
:::note
|
||||
|
||||
`telemetry.stats.network_bandwidth` uses nethogs, which requires root with NET_ADMIN/NET_RAW capabilities. If you enable that stat, omit `cap_drop: [ALL]` or add `cap_add: [NET_ADMIN, NET_RAW]`.
|
||||
|
||||
Platforms that genuinely require `privileged: true` (MemryX, some QNAP setups) are called out in their own sections and are unaffected by this guidance.
|
||||
|
||||
:::
|
||||
|
||||
Frigate's services run as an unprivileged user inside the container. See [Running as a non-root user](../configuration/non_root.md) for the run modes, the one time volume ownership migration, and what each accelerator needs on the host.
|
||||
|
||||
**Docker CLI**
|
||||
|
||||
If you can't use Docker Compose, you can run the container with something similar to this:
|
||||
@@ -636,8 +612,6 @@ Home Assistant OS users can install via the App repository.
|
||||
5. Start the App
|
||||
6. Use the _Open Web UI_ button to access the Frigate UI, then click in the _cog icon_ > _Configuration editor_ and configure Frigate to your liking
|
||||
|
||||
App users who can't set container environment variables can put `FRIGATE_` values in a `secrets.yaml` next to `config.yml` in `/addon_configs/<addon_directory>` instead. See [`secrets.yaml`](../configuration/advanced/system.md#secretsyaml).
|
||||
|
||||
There are several variants of the App available:
|
||||
|
||||
| App Variant | Description |
|
||||
|
||||
@@ -4,7 +4,6 @@ title: Getting started
|
||||
---
|
||||
|
||||
import ConfigTabs from "@site/src/components/ConfigTabs";
|
||||
import Tabs from "@theme/Tabs";
|
||||
import TabItem from "@theme/TabItem";
|
||||
import NavPath from "@site/src/components/NavPath";
|
||||
|
||||
@@ -133,68 +132,21 @@ services:
|
||||
- "8554:8554" # RTSP feeds
|
||||
```
|
||||
|
||||
Now you should be able to start Frigate by running `docker compose up -d` from within the folder containing `docker-compose.yml`. On startup, an admin user and password will be created and outputted in the logs. You can see this by running `docker logs frigate`. Frigate should now be accessible at `https://server_ip:8971` where you can login with the `admin` user. With no cameras configured yet, the setup wizard runs on first login and walks you through the rest.
|
||||
Now you should be able to start Frigate by running `docker compose up -d` from within the folder containing `docker-compose.yml`. On startup, an admin user and password will be created and outputted in the logs. You can see this by running `docker logs frigate`. Frigate should now be accessible at `https://server_ip:8971` where you can login with the `admin` user and finish configuration using the Settings UI.
|
||||
|
||||
## Configuring Frigate
|
||||
|
||||
This section assumes that you already have an environment setup as described in [Installation](../frigate/installation.md). You should also configure your cameras according to the [camera setup guide](/frigate/camera_setup). Pay particular attention to the section on choosing a detect resolution.
|
||||
|
||||
<Tabs
|
||||
groupId="setup-method"
|
||||
defaultValue="wizard"
|
||||
values={[
|
||||
{ label: "Setup wizard", value: "wizard" },
|
||||
{ label: "Manual", value: "manual" },
|
||||
]}
|
||||
|
||||
> <TabItem value="wizard">
|
||||
|
||||
The first time you open Frigate with no cameras configured, the setup wizard walks you through the basics. Every step can be skipped, everything it sets can be changed later in Settings, and once you finish or dismiss it, it doesn't come back.
|
||||
|
||||
:::note
|
||||
|
||||
Frigate only sees hardware that has been passed into the container. If you plan to use a GPU, a Coral, or another accelerator, add the device to your `docker-compose.yml` and restart before running the wizard, otherwise it won't appear in the detection or hardware acceleration steps. The Manual tab shows the device entries for an Intel or AMD GPU and for a Coral, and the [hardware acceleration](../configuration/hardware_acceleration_video.md) and [object detectors](../configuration/object_detectors.md) docs cover the rest.
|
||||
|
||||
:::
|
||||
|
||||
**Account**
|
||||
|
||||
Set a password for the `admin` account to replace the generated one from the logs, and add accounts for anyone else who needs access. This step is hidden if you have turned authentication off.
|
||||
|
||||
**Add a camera**
|
||||
|
||||
Opens the [Add Camera Wizard](../configuration/cameras.md#adding-a-camera-with-the-add-camera-wizard), which connects to the camera, tests each stream, and writes its configuration for you. You can add more than one before moving on.
|
||||
|
||||
**Object detection**
|
||||
|
||||
Lists the detection hardware Frigate found on your system, such as a Coral, an Intel GPU or NPU, or a discrete GPU, and configures the one you pick. NVIDIA and AMD GPUs need a model before detection can start, so the wizard offers your Frigate+ models if you have them, or lets you finish setup and add one later under <NavPath path="Settings > System > Detection models" />.
|
||||
|
||||
**Hardware acceleration**
|
||||
|
||||
Offers only the decoding methods your hardware supports. Auto picks one based on that hardware and the codec your camera sends, so a mixed h264 and h265 setup gets the right preset per camera.
|
||||
|
||||
**Recording**
|
||||
|
||||
Choose whether to record only when something is detected or around the clock, and how long to keep it.
|
||||
|
||||
The last screen summarizes what was set up. If a step changed something that needs a restart, the button restarts Frigate and returns you to the Live view once it is back.
|
||||
|
||||
The wizard configures the essentials only. Motion masks are not included and should be set up afterward, once you can identify the areas of the frame that trigger unwanted motion. See the [masks documentation](../configuration/masks.md). Zones, tracked object types, notifications, and MQTT are also configured in Settings.
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="manual">
|
||||
|
||||
On a new install the setup wizard opens first. Click **Skip setup and configure manually** on its welcome screen to dismiss it, and the steps below apply. The wizard won't come back once dismissed.
|
||||
|
||||
**Step 1: Start Frigate**
|
||||
### Step 1: Start Frigate
|
||||
|
||||
At this point you should be able to start Frigate and a basic config will be created automatically.
|
||||
|
||||
**Step 2: Add a camera**
|
||||
### Step 2: Add a camera
|
||||
|
||||
Click the **Add Camera** button in <NavPath path="Settings > Global configuration > Camera management" /> to use the camera setup wizard to get your first camera added into Frigate. See [Adding a camera with the Add Camera Wizard](../configuration/cameras.md#adding-a-camera-with-the-add-camera-wizard) for a walkthrough of each step.
|
||||
|
||||
**Step 3: Configure hardware acceleration (recommended)**
|
||||
### Step 3: Configure hardware acceleration (recommended)
|
||||
|
||||
Now that you have a working camera configuration, set up hardware acceleration to minimize the CPU required to decode your video streams. See the [hardware acceleration](../configuration/hardware_acceleration_video.md) docs for examples applicable to your hardware.
|
||||
|
||||
@@ -238,7 +190,7 @@ cameras:
|
||||
</TabItem>
|
||||
</ConfigTabs>
|
||||
|
||||
**Step 4: Configure detectors**
|
||||
### Step 4: Configure detectors
|
||||
|
||||
By default, Frigate will use a single OpenVINO detector running on the CPU.
|
||||
|
||||
@@ -252,8 +204,8 @@ You need to refer to **Configure hardware acceleration** above to enable the con
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
1. Navigate to <NavPath path="Settings > System > Detection models" /> and select **Intel GPU** from the **Hardware** dropdown
|
||||
2. On the same model, open the **Custom Model** tab and configure the model settings for OpenVINO:
|
||||
1. Navigate to <NavPath path="Settings > System > Detectors and model" /> and add a detector with **Type** `OpenVINO` and **Device** `GPU`
|
||||
2. On the same page, in the **Custom Model** tab, configure the model settings for OpenVINO:
|
||||
|
||||
| Field | Value |
|
||||
| ---------------------------------------- | ------------------------------------------ |
|
||||
@@ -270,12 +222,15 @@ You need to refer to **Configure hardware acceleration** above to enable the con
|
||||
```yaml {3-6,9-15,20-21}
|
||||
mqtt: ...
|
||||
|
||||
models: # <---- add models
|
||||
- devices:
|
||||
- openvino:GPU # <---- use the openvino detector on the GPU
|
||||
# We will use the default MobileNet_v2 model from OpenVINO.
|
||||
width: 300
|
||||
height: 300
|
||||
detectors: # <---- add detectors
|
||||
ov:
|
||||
type: openvino # <---- use openvino detector
|
||||
device: GPU
|
||||
|
||||
# We will use the default MobileNet_v2 model from OpenVINO.
|
||||
model:
|
||||
width: 300
|
||||
height: 300
|
||||
input_tensor: nhwc
|
||||
input_pixel_format: bgr
|
||||
path: /openvino-model/ssdlite_mobilenet_v2.xml
|
||||
@@ -318,7 +273,7 @@ services:
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
Navigate to <NavPath path="Settings > System > Detection models" /> and select **Coral EdgeTPU (USB)** from the **Hardware** dropdown.
|
||||
Navigate to <NavPath path="Settings > System > Detectors and model" /> and add a detector with **Type** `EdgeTPU` and **Device** `usb`.
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
@@ -326,9 +281,10 @@ Navigate to <NavPath path="Settings > System > Detection models" /> and select *
|
||||
```yaml {3-6,11-12}
|
||||
mqtt: ...
|
||||
|
||||
models: # <---- add models
|
||||
- devices:
|
||||
- edgetpu:usb
|
||||
detectors: # <---- add detectors
|
||||
coral:
|
||||
type: edgetpu
|
||||
device: usb
|
||||
|
||||
cameras:
|
||||
name_of_your_camera:
|
||||
@@ -347,7 +303,7 @@ More details on available detectors can be found [here](../configuration/object_
|
||||
|
||||
Restart Frigate and you should start seeing detections for `person`. If you want to track other objects, they can be configured in <NavPath path="Settings > Global configuration > Objects" /> or via the [configuration file reference](../configuration/advanced/reference.md).
|
||||
|
||||
**Step 5: Setup motion masks**
|
||||
### Step 5: Setup motion masks
|
||||
|
||||
Now that you have optimized your configuration for decoding the video stream, you will want to check to see where to implement motion masks. Click on the camera from the main dashboard, then select the gear icon in the top right, enable the [Debug view](/usage/live#the-single-camera-view), and finally enable the switch for Motion Boxes. Watch for areas that continuously trigger unwanted motion to be detected. Common areas to mask include camera timestamps and trees that frequently blow in the wind. The goal is to avoid wasting object detection cycles looking at these areas.
|
||||
|
||||
@@ -365,9 +321,10 @@ If you are using YAML to configure Frigate instead of the UI, your configuration
|
||||
mqtt:
|
||||
enabled: False
|
||||
|
||||
models:
|
||||
- devices:
|
||||
- edgetpu:usb
|
||||
detectors:
|
||||
coral:
|
||||
type: edgetpu
|
||||
device: usb
|
||||
|
||||
cameras:
|
||||
name_of_your_camera:
|
||||
@@ -384,7 +341,7 @@ cameras:
|
||||
coordinates: "0,461,3,0,1919,0,1919,843,1699,492,1344,458,1346,336,973,317,869,375,866,432"
|
||||
```
|
||||
|
||||
**Step 6: Enable recordings**
|
||||
### Step 6: Enable recordings
|
||||
|
||||
In order to review activity in the Frigate UI, recordings need to be enabled.
|
||||
|
||||
@@ -400,7 +357,7 @@ In order to review activity in the Frigate UI, recordings need to be enabled.
|
||||
```yaml {16-17}
|
||||
mqtt: ...
|
||||
|
||||
models: ...
|
||||
detectors: ...
|
||||
|
||||
cameras:
|
||||
name_of_your_camera:
|
||||
@@ -433,10 +390,7 @@ If you only plan to use Frigate for recording, it is still recommended to define
|
||||
|
||||
By default, Frigate will retain video of all tracked objects for 10 days. The full set of options for recording can be found [here](../configuration/advanced/reference.md).
|
||||
|
||||
</TabItem>
|
||||
</Tabs>
|
||||
|
||||
### Complete config
|
||||
### Step 7: Complete config
|
||||
|
||||
At this point you have a complete config with basic functionality.
|
||||
|
||||
|
||||
@@ -11,6 +11,12 @@ MQTT requires a network connection to your broker. This is typically local, but
|
||||
|
||||
:::
|
||||
|
||||
:::note
|
||||
|
||||
Wherever a topic below includes a camera, mask, or zone name, use its `ID` from the config, not its `friendly_name`. For example, a camera with `friendly_name: "Back Yard"` and ID `back_yard` publishes to `frigate/back_yard/...`, not `frigate/Back Yard/...`.
|
||||
|
||||
:::
|
||||
|
||||
## General Frigate Topics
|
||||
|
||||
### `frigate/available`
|
||||
@@ -304,7 +310,7 @@ Topic with current state of notifications. Published values are `ON` and `OFF`.
|
||||
|
||||
### `frigate/<camera_name>/status/<role>`
|
||||
|
||||
Publishes the current health status of each role that is enabled (`audio`, `detect`, `record`, `record_sub`). `record_sub` is only published for cameras with [sub stream recording](/configuration/record#sub-stream-recording) enabled, and is tracked separately from `record` so a healthy main stream can't hide a stalled sub stream. Possible values are:
|
||||
Publishes the current health status of each role that is enabled (`audio`, `detect`, `record`). Possible values are:
|
||||
|
||||
- `online`: Stream is running and being processed
|
||||
- `offline`: Stream is offline and is being restarted
|
||||
@@ -553,25 +559,22 @@ must be enabled in the configuration.
|
||||
|
||||
Topic with current state of Birdseye for a camera. Published values are `ON` and `OFF`.
|
||||
|
||||
### `frigate/<camera_name>/birdseye_modes/set`
|
||||
### `frigate/<camera_name>/birdseye_mode/set`
|
||||
|
||||
Topic to set the Birdseye activity types for a camera. Send one uppercase activity type or combine multiple types with commas, for example `MOTION,ALERTS`.
|
||||
Topic to set Birdseye mode for a camera. Birdseye offers different modes to customize under which circumstances the camera is shown.
|
||||
|
||||
_Note: Changing the value from `CONTINUOUS` to non-continuous activity types will take up to 30 seconds for
|
||||
_Note: Changing the value from `CONTINUOUS` -> `MOTION | OBJECTS` will take up to 30 seconds for
|
||||
the camera to be removed from the view._
|
||||
|
||||
| Command | Description |
|
||||
| ------------- | ---------------------------------------------------------------- |
|
||||
| `CONTINUOUS` | Always included |
|
||||
| `MOTION` | Shown if motion was detected within the last 30 seconds |
|
||||
| `ALL_OBJECTS` | Shown if a tracked object was present within the last 30 seconds |
|
||||
| `ALERTS` | Shown while an alert review item is in progress |
|
||||
| `DETECTIONS` | Shown while a detection review item is in progress |
|
||||
| `NONE` | Never included |
|
||||
| Command | Description |
|
||||
| ------------ | ----------------------------------------------------------------- |
|
||||
| `CONTINUOUS` | Always included |
|
||||
| `MOTION` | Show when detected motion within the last 30 seconds are included |
|
||||
| `OBJECTS` | Shown if an active object tracked within the last 30 seconds |
|
||||
|
||||
### `frigate/<camera_name>/birdseye_modes/state`
|
||||
### `frigate/<camera_name>/birdseye_mode/state`
|
||||
|
||||
Topic with the current Birdseye activity types for a camera. Multiple enabled types are published as a comma-separated value in the order `CONTINUOUS`, `MOTION`, `ALL_OBJECTS`, `ALERTS`, `DETECTIONS`. `NONE` is published when no activity types are enabled.
|
||||
Topic with current state of the Birdseye mode for a camera. Published values are `CONTINUOUS`, `MOTION`, `OBJECTS`.
|
||||
|
||||
### `frigate/<camera_name>/notifications/set`
|
||||
|
||||
|
||||
@@ -59,12 +59,13 @@ You can view all of your submitted images at [https://plus.frigate.video](https:
|
||||
|
||||
Once you have [requested your first model](../plus/first_model.md) and gotten your own model ID, it can be used with a special model path. No other information needs to be configured for Frigate+ models because it fetches the remaining config from Frigate+ automatically.
|
||||
|
||||
You can either choose the new model from the <NavPath path="Settings > System > Detection models" /> pane in the Frigate UI (on the **Frigate+** tab of the model you want to change), or set it on that model in your config:
|
||||
You can either choose the new model from the <NavPath path="Settings > System > Detectors and model" /> pane in the Frigate UI (the **Frigate+ Model** tab), or manually set the model at the root level in your config:
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices: ...
|
||||
path: plus://<your_model_id>
|
||||
detectors: ...
|
||||
|
||||
model:
|
||||
path: plus://<your_model_id>
|
||||
```
|
||||
|
||||
:::note
|
||||
@@ -78,11 +79,10 @@ Models are downloaded into the `/config/model_cache` folder and only downloaded
|
||||
If needed, you can override the labelmap for Frigate+ models. This is not recommended as renaming labels will break the Submit to Frigate+ feature if the labels are not available in Frigate+.
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices: ...
|
||||
path: plus://<your_model_id>
|
||||
labelmap:
|
||||
3: animal
|
||||
4: animal
|
||||
5: animal
|
||||
model:
|
||||
path: plus://<your_model_id>
|
||||
labelmap:
|
||||
3: animal
|
||||
4: animal
|
||||
5: animal
|
||||
```
|
||||
|
||||
@@ -27,6 +27,10 @@ The [Advanced Camera Card](https://card.camera/#/README) is a Home Assistant das
|
||||
It supports automatically setting the sub labels in Frigate for person objects that are detected and recognized.
|
||||
This is a fork (with fixed errors and new features) of [original Double Take](https://github.com/jakowenko/double-take) project which, unfortunately, isn't being maintained by author.
|
||||
|
||||
## [frigate-abr](https://github.com/007hacky007/frigate-abr)
|
||||
|
||||
[frigate-abr](https://github.com/007hacky007/frigate-abr) is a drop-in Docker image of Frigate that adds adaptive bitrate (ABR) playback for recordings: a sidecar transcodes footage to lower quality tiers on demand, for reviewing over slow remote connections. Segments are transcoded when played and cached, so no additional stream is recorded. Frigate itself is not modified.
|
||||
|
||||
## [Frigate Notify](https://github.com/0x2142/frigate-notify)
|
||||
|
||||
[Frigate Notify](https://github.com/0x2142/frigate-notify) is a simple app designed to send notifications from Frigate to your favorite platforms. Intended to be used with standalone Frigate installations - Home Assistant not required, MQTT is optional but recommended.
|
||||
|
||||
@@ -21,7 +21,13 @@ Yes. Models and metadata are stored in the `model_cache` directory within the co
|
||||
|
||||
### Can I keep using my Frigate+ models even if I do not renew my subscription?
|
||||
|
||||
Yes. Subscriptions to Frigate+ provide access to the infrastructure used to train the models. Models trained with your subscription are yours to keep and use forever. However, do note that the terms and conditions prohibit you from sharing, reselling, or creating derivative products from the models.
|
||||
Yes. Subscriptions to Frigate+ provide access to the infrastructure used to train the models. Models you train during an active subscription remain licensed for your continued use even after your subscription ends — models already in your model cache will keep working indefinitely. An active subscription is required to train new models and download new versions.
|
||||
|
||||
### Can I use Frigate+ models commercially?
|
||||
|
||||
A standard subscription covers use on camera systems you own or operate, including for your business. A shop, restaurant, warehouse, or office running Frigate+ at its own locations (including multiple locations) is exactly the kind of use the subscription is for.
|
||||
What the standard subscription does not cover is using Frigate+ models to provide a product or service to others. If you're deploying models at your customers' sites, bundling them with hardware you sell, or running them as part of a hosted or managed service, even if your customers never receive the model files themselves, you'll need a commercial license.
|
||||
Note that professional installers are fine under standard subscriptions when each customer holds their own Frigate+ subscription. The commercial license is for cases where your license powers your customers' sites.
|
||||
|
||||
### Why can't I submit images to Frigate+?
|
||||
|
||||
|
||||
@@ -30,15 +30,16 @@ Models available in Frigate+ can be used with a special model path. No other inf
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
Navigate to <NavPath path="Settings > System > Detection models" />. On the model you want to change, choose the **Frigate+** tab and select your new Frigate+ model from the **Available Frigate+ models** dropdown, then click **Save**. Restart Frigate to apply the change.
|
||||
Navigate to <NavPath path="Settings > System > Detectors and model" />. In the **Detection Model** section, choose the **Frigate+** tab. Select your new Frigate+ model from the **Available Frigate+ models** dropdown, then click **Save**. Restart Frigate to apply the change.
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
|
||||
```yaml
|
||||
models:
|
||||
- devices: ...
|
||||
path: plus://<your_model_id>
|
||||
detectors: ...
|
||||
|
||||
model:
|
||||
path: plus://<your_model_id>
|
||||
```
|
||||
|
||||
:::tip
|
||||
@@ -63,20 +64,20 @@ Frigate+ models generally have much higher scores than the default model provide
|
||||
<ConfigTabs>
|
||||
<TabItem value="ui">
|
||||
|
||||
Navigate to <NavPath path="Settings > Global configuration > Objects" />. Under **Object filters**, set **Min Score** and **Threshold** for each object type, then click **Save**.
|
||||
Navigate to <NavPath path="Settings > Global configuration > Objects" />. Under **Object filters**, set **Minimum confidence** and **Confidence threshold** for each object type, then click **Save**.
|
||||
|
||||
| Object | Min Score | Threshold |
|
||||
| ----------------- | --------- | --------- |
|
||||
| **dog** | .7 | .9 |
|
||||
| **cat** | .65 | .8 |
|
||||
| **face** | .7 | |
|
||||
| **package** | .65 | .9 |
|
||||
| **license_plate** | .6 | |
|
||||
| **amazon** | .75 | |
|
||||
| **ups** | .75 | |
|
||||
| **fedex** | .75 | |
|
||||
| **person** | .65 | .85 |
|
||||
| **car** | .65 | .85 |
|
||||
| Object | Minimum confidence | Confidence threshold |
|
||||
| ----------------- | ------------------ | -------------------- |
|
||||
| **dog** | .7 | .9 |
|
||||
| **cat** | .65 | .8 |
|
||||
| **face** | .7 | |
|
||||
| **package** | .65 | .9 |
|
||||
| **license_plate** | .6 | |
|
||||
| **amazon** | .75 | |
|
||||
| **ups** | .75 | |
|
||||
| **fedex** | .75 | |
|
||||
| **person** | .65 | .85 |
|
||||
| **car** | .65 | .85 |
|
||||
|
||||
</TabItem>
|
||||
<TabItem value="yaml">
|
||||
|
||||
@@ -65,11 +65,11 @@ Some users may find that Frigate+ models result in more false positives initiall
|
||||
|
||||
Frigate+ models support a more relevant set of objects for security cameras. The labels for annotation in Frigate+ are configurable by editing the camera in the Cameras section of Frigate+. Currently, the following objects are supported:
|
||||
|
||||
- **People**: `person`, `face`
|
||||
- **Vehicles**: `car`, `motorcycle`, `bicycle`, `boat`, `school_bus`, `license_plate`
|
||||
- **People**: `person`, `face`, `baby`
|
||||
- **Vehicles**: `car`, `motorcycle`, `bicycle`, `boat`, `school_bus`, `garbage truck`, `license_plate`
|
||||
- **Delivery Logos**: `amazon`, `usps`, `ups`, `fedex`, `dhl`, `an_post`, `purolator`, `postnl`, `nzpost`, `postnord`, `gls`, `dpd`, `canada_post`, `royal_mail`
|
||||
- **Animals**: `dog`, `cat`, `deer`, `horse`, `bird`, `raccoon`, `fox`, `bear`, `cow`, `squirrel`, `goat`, `rabbit`, `skunk`, `kangaroo`
|
||||
- **Other**: `package`, `waste_bin`, `bbq_grill`, `robot_lawnmower`, `umbrella`
|
||||
- **Animals**: `dog`, `cat`, `deer`, `horse`, `bird`, `raccoon`, `fox`, `bear`, `cow`, `squirrel`, `goat`, `rabbit`, `skunk`, `kangaroo`, `possum`, `rodent`
|
||||
- **Other**: `package`, `waste_bin`, `bbq_grill`, `robot_lawnmower`, `umbrella`, `baby_stroller`
|
||||
|
||||
Other object types available in the default Frigate model are not available. Additional object types will be added in future releases.
|
||||
|
||||
@@ -77,9 +77,12 @@ Other object types available in the default Frigate model are not available. Add
|
||||
|
||||
Candidate labels are also available for annotation. These labels don't have enough data to be included in the model yet, but using them will help add support sooner. You can enable these labels by editing the camera settings.
|
||||
|
||||
Where possible, these labels are mapped to existing labels during training. For example, any `baby` labels are mapped to `person` until support for new labels is added.
|
||||
Where possible, these labels are mapped to existing labels during training. For example, any `duck` labels are mapped to `bird` until support for new labels is added.
|
||||
|
||||
The candidate labels are: `baby`, `bpost`, `badger`, `possum`, `rodent`, `chicken`, `groundhog`, `boar`, `hedgehog`, `tractor`, `golf cart`, `garbage truck`, `bus`, `sports ball`, `la_poste`, `lawnmower`, `heron`, `rickshaw`, `wombat`, `auspost`, `aramex`, `bobcat`, `mustelid`, `transoflex`, `airplane`, `drone`, `mountain_lion`, `crocodile`, `turkey`, `baby_stroller`, `monkey`, `coyote`, `porcupine`, `parcelforce`, `sheep`, `snake`, `helicopter`, `lizard`, `duck`, `hermes`, `cargus`, `fan_courier`, `sameday`
|
||||
- **Vehicles**: `tractor`, `golf_cart`, `bus`, `airplane`, `helicopter`, `rickshaw`, `scooter`
|
||||
- **Delivery Logos**: `bpost`, `auspost`, `aramex`, `transoflex`, `parcelforce`, `hermes`, `cargus`, `fan_courier`, `sameday`, `la_poste`
|
||||
- **Animals**: `badger`, `chicken`, `duck`, `turkey`, `groundhog`, `boar`, `hedgehog`, `wombat`, `bobcat`, `mustelid`, `mountain_lion`, `crocodile`, `monkey`, `coyote`, `porcupine`, `sheep`, `snake`, `lizard`, `heron`, `elk`, `moose`, `pig`, `donkey`, `civet`
|
||||
- **Other**: `sports_ball`, `drone`, `lawnmower`
|
||||
|
||||
Candidate labels are not available for automatic suggestions.
|
||||
|
||||
|
||||
@@ -133,7 +133,7 @@ The process was killed by the CPU for executing an unsupported instruction. Ther
|
||||
|
||||
<FaqItem id="onnx-invalidprotobuf" question="ONNX Runtime InvalidProtobuf / failed to load model">
|
||||
|
||||
ONNX Runtime could not parse the model file. The file exists but its contents are not a valid ONNX model, usually a corrupted or interrupted download in `model_cache`, or the wrong file pointed at by a model's `path`. Delete the cached model file so Frigate re-downloads it, and confirm the model's `path` points at an actual `.onnx` model. See [ONNX detector configuration](/configuration/object_detectors#onnx).
|
||||
ONNX Runtime could not parse the model file. The file exists but its contents are not a valid ONNX model, usually a corrupted or interrupted download in `model_cache`, or the wrong file pointed at by `model.path`. Delete the cached model file so Frigate re-downloads it, and confirm `model.path` points at an actual `.onnx` model. See [ONNX detector configuration](/configuration/object_detectors#onnx).
|
||||
|
||||
</FaqItem>
|
||||
|
||||
|
||||
@@ -39,6 +39,20 @@ To do this efficiently the following setup is required:
|
||||
|
||||
When this is done correctly, the GPU will do the decoding and scaling which will result in a small increase in CPU usage but with better results.
|
||||
|
||||
### How can I rotate my camera's video feed?
|
||||
|
||||
Rotation is best done in the camera's firmware settings (usually called rotate, flip, or corridor mode) so the video arrives already rotated and no extra processing is needed. Check there first.
|
||||
|
||||
If your camera does not support rotation, go2rtc's ffmpeg module can rotate the stream with the `#rotate` parameter (`90`, `180`, `270`, or `-90`), but this is not recommended: rotation requires transcoding (re-encoding) the video, which significantly increases CPU usage, especially for high resolution streams.
|
||||
|
||||
```yaml
|
||||
go2rtc:
|
||||
streams:
|
||||
my_camera: "ffmpeg:rtsp://user:password@192.168.1.10:554/stream#video=h264#hardware#rotate=90"
|
||||
```
|
||||
|
||||
Point the camera's inputs at the restream as described in the [restream docs](/configuration/restream.md), and swap `detect -> width` and `detect -> height` to match the rotated resolution.
|
||||
|
||||
### My mjpeg stream or snapshots look green and crazy
|
||||
|
||||
This almost always means that the width/height defined for your camera are not correct. Double check the resolution with VLC or another player. Also make sure you don't have the width and height values backwards.
|
||||
|
||||
@@ -78,7 +78,9 @@ go2rtc:
|
||||
|
||||
:::warning
|
||||
|
||||
The `#`-modifiers (`#video=`, `#audio=`, `#hardware`, `#backchannel=0`, …) **only take effect on a source that is prefixed with `ffmpeg:`**. Adding them to a bare `rtsp://…#audio=opus` source does nothing: go2rtc ignores them. Likewise, when a source references another stream by name (e.g. `ffmpeg:back#audio=aac`), the name must match the stream key **exactly** (it is case sensitive), or the transcode is silently never produced. This is the single most common configuration mistake. In the Frigate UI, the **Use compatibility mode (ffmpeg)** toggle adds the `ffmpeg:` prefix for you.
|
||||
The transcoding modifiers (`#video=`, `#audio=`, `#hardware`, …) **only take effect on a source that is prefixed with `ffmpeg:`**. Adding them to a bare `rtsp://…#audio=opus` source does nothing: go2rtc ignores them. Likewise, when a source references another stream by name (e.g. `ffmpeg:back#audio=aac`), the name must match the stream key **exactly** (it is case sensitive), or the transcode is silently never produced. This is the single most common configuration mistake. In the Frigate UI, the **Use compatibility mode (ffmpeg)** toggle adds the `ffmpeg:` prefix for you.
|
||||
|
||||
A bare `rtsp://` source reads a different set of modifiers: `#backchannel=`, `#media=`, `#timeout=`, and `#transport=`. These do nothing on an `ffmpeg:` source. Adding **any** modifier to a bare `rtsp://` source also disables the camera's backchannel unless the URL explicitly contains `#backchannel=1`, so a stream dedicated to two-way talk should carry no modifiers at all.
|
||||
|
||||
:::
|
||||
|
||||
@@ -153,7 +155,7 @@ WebRTC is only attempted when MSE fails or when using a camera's two-way talk fe
|
||||
|
||||
- **Codec mismatch**: WebRTC cannot carry H.265 or AAC. The stream backing the WebRTC view must provide Opus (or PCMA/PCMU) audio and H.264 video. Add an `ffmpeg:back#audio=opus` source as shown above.
|
||||
- **Port `8555` not reachable, or no candidates set**: WebRTC needs port `8555` (both TCP and UDP) open and a reachable candidate advertised. On Docker installs running on a custom/overlay network, go2rtc may advertise unreachable container IPs as ICE candidates; setting `webrtc.filters.candidates: []` and supplying only your host's LAN IP resolves this. See [WebRTC extra configuration](/configuration/live#webrtc-extra-configuration).
|
||||
- **Two-way talk** additionally requires a secure context (HTTPS or the authenticated port `8971`, because browsers block microphone access on plain HTTP). The camera's RTSP backchannel must also be handled correctly: go2rtc seizes the backchannel by default, which blocks two-way audio for other consumers and can inject static. Disable it on the primary stream with `#backchannel=0` and use a separate dedicated stream for talk, as documented in [preventing go2rtc from blocking two-way audio](/configuration/restream#two-way-talk-restream).
|
||||
- **Two-way talk** additionally requires a secure context (HTTPS or the authenticated port `8971`, because browsers block microphone access on plain HTTP). The camera's RTSP backchannel must also be handled correctly: go2rtc seizes the backchannel by default, which blocks two-way audio for other consumers and can inject static. Disable it on the primary stream with `#backchannel=0` and use a separate dedicated stream for talk, carrying no `#` modifiers of any kind, as documented in [preventing go2rtc from blocking two-way audio](/configuration/restream#two-way-talk-restream).
|
||||
|
||||
## High CPU usage
|
||||
|
||||
|
||||
@@ -397,19 +397,11 @@ dmesg | grep -i -E "gpu|drm|reset|hang"
|
||||
|
||||
Messages like `trying reset from guc_exec_queue_timedout_job` or similar GPU reset/hang messages indicate a driver or hardware issue. Ensure your kernel and GPU drivers (especially Intel) are up to date.
|
||||
|
||||
#### Step 6: Verify hardware acceleration configuration
|
||||
|
||||
An incorrect `hwaccel_args` preset can cause ffmpeg to fail silently or consume excessive CPU, starving the detector of resources.
|
||||
|
||||
- After upgrading Frigate, verify your preset matches your hardware (e.g., `preset-intel-qsv-h264` instead of the deprecated `preset-vaapi`).
|
||||
- For h265 cameras, use the corresponding h265 preset (e.g., `preset-intel-qsv-h265`).
|
||||
- Note that `hwaccel_args` are only relevant for the detect stream. Frigate does not decode the record stream.
|
||||
|
||||
#### Step 7: Verify go2rtc stream configuration
|
||||
#### Step 6: Verify go2rtc stream configuration
|
||||
|
||||
Ensure that the ffmpeg source names in your go2rtc configuration match the correct camera stream. A misconfigured stream name (e.g., copying a config from one camera to another without updating the stream reference) will cause the wrong stream to be used or the stream to fail entirely.
|
||||
|
||||
#### Step 8: Check system resources
|
||||
#### Step 7: Check system resources
|
||||
|
||||
If none of the above apply, the issue may be a general resource constraint. Monitor the following on your host:
|
||||
|
||||
|
||||
@@ -40,7 +40,7 @@ Deleting a group also clears any custom layout you saved for it.
|
||||
|
||||
## Rearranging a camera group layout
|
||||
|
||||
On desktop and tablet, each camera group has its own freely-arrangeable grid. Enter **Edit Layout** mode from the layout button in the lower-right corner: camera tiles gain a drag handle and corner resize handles. Drag a tile to reposition it and drag a corner to resize it (the aspect ratio is preserved). Exit edit mode to save. The layout is stored in your browser per device, so each device can have its own arrangement, and layouts can be exported to a file and imported on another device.
|
||||
On desktop and tablet, each camera group has its own freely-arrangeable grid. Enter **Edit Layout** mode from the layout button in the lower-right corner: camera tiles gain a drag handle and corner resize handles. Drag a tile to reposition it and drag a corner to resize it (the aspect ratio is preserved). Exit edit mode to save. The layout is stored in your browser per device, so each device can have its own arrangement.
|
||||
|
||||
The default **All Cameras** dashboard is not manually arrangeable. It automatically sizes tiles based on each camera's aspect ratio (wide cameras span two columns, tall cameras span two rows).
|
||||
|
||||
@@ -68,7 +68,7 @@ For non-default groups, the context menu also exposes **Streaming Settings** for
|
||||
- the **streaming method**: **No Streaming**, **Smart Streaming** (recommended), or **Continuous Streaming** (higher bandwidth), and
|
||||
- **compatibility mode**, for devices that have trouble rendering the default player.
|
||||
|
||||
These settings are saved per group and per device in your browser, not in your config file, and can be exported to a file and imported on another device.
|
||||
These settings are saved per group and per device in your browser, not in your config file.
|
||||
|
||||
## The single-camera view
|
||||
|
||||
|
||||
+30
-22
@@ -3,6 +3,9 @@ import * as path from "node:path";
|
||||
import type { Config, PluginConfig } from "@docusaurus/types";
|
||||
import type * as OpenApiPlugin from "docusaurus-plugin-openapi-docs";
|
||||
|
||||
// Bump when a new stable release ships
|
||||
const STABLE_VERSION = "0.18";
|
||||
|
||||
const config: Config = {
|
||||
title: "Frigate",
|
||||
tagline: "NVR With Realtime Object Detection for IP Cameras",
|
||||
@@ -23,17 +26,17 @@ const config: Config = {
|
||||
mermaid: true,
|
||||
},
|
||||
i18n: {
|
||||
defaultLocale: 'en',
|
||||
locales: ['en'],
|
||||
defaultLocale: "en",
|
||||
locales: ["en"],
|
||||
localeConfigs: {
|
||||
en: {
|
||||
label: 'English',
|
||||
}
|
||||
label: "English",
|
||||
},
|
||||
},
|
||||
},
|
||||
themeConfig: {
|
||||
announcementBar: {
|
||||
id: 'frigate_plus',
|
||||
id: "frigate_plus",
|
||||
content: `
|
||||
<span style="margin-right: 8px; display: inline-block; animation: pulse 2s infinite;">🚀</span>
|
||||
Get more relevant and accurate detections with Frigate+ models.
|
||||
@@ -45,8 +48,8 @@ const config: Config = {
|
||||
50% { transform: scale(1.1); }
|
||||
}
|
||||
</style>`,
|
||||
backgroundColor: '#005f73',
|
||||
textColor: '#e0fbfc',
|
||||
backgroundColor: "#005f73",
|
||||
textColor: "#e0fbfc",
|
||||
isCloseable: false,
|
||||
},
|
||||
docs: {
|
||||
@@ -83,15 +86,15 @@ const config: Config = {
|
||||
},
|
||||
},
|
||||
prism: {
|
||||
magicComments:[
|
||||
magicComments: [
|
||||
{
|
||||
className: 'theme-code-block-highlighted-line',
|
||||
line: 'highlight-next-line',
|
||||
block: {start: 'highlight-start', end: 'highlight-end'},
|
||||
className: "theme-code-block-highlighted-line",
|
||||
line: "highlight-next-line",
|
||||
block: { start: "highlight-start", end: "highlight-end" },
|
||||
},
|
||||
{
|
||||
className: 'code-block-error-line',
|
||||
line: 'highlight-error-line',
|
||||
className: "code-block-error-line",
|
||||
line: "highlight-error-line",
|
||||
},
|
||||
],
|
||||
additionalLanguages: ["bash", "json"],
|
||||
@@ -131,6 +134,11 @@ const config: Config = {
|
||||
srcDark: "img/branding/logo-dark.svg",
|
||||
},
|
||||
items: [
|
||||
{
|
||||
href: "https://github.com/blakeblackshear/frigate/releases",
|
||||
label: `${STABLE_VERSION}`,
|
||||
position: "left",
|
||||
},
|
||||
{
|
||||
to: "/",
|
||||
activeBasePath: "docs",
|
||||
@@ -148,19 +156,19 @@ const config: Config = {
|
||||
position: "right",
|
||||
},
|
||||
{
|
||||
type: 'localeDropdown',
|
||||
position: 'right',
|
||||
type: "localeDropdown",
|
||||
position: "right",
|
||||
dropdownItemsAfter: [
|
||||
{
|
||||
label: '简体中文(社区翻译)',
|
||||
href: 'https://docs.frigate-cn.video',
|
||||
}
|
||||
]
|
||||
label: "简体中文(社区翻译)",
|
||||
href: "https://docs.frigate-cn.video",
|
||||
},
|
||||
],
|
||||
},
|
||||
{
|
||||
href: 'https://github.com/blakeblackshear/frigate',
|
||||
label: 'GitHub',
|
||||
position: 'right',
|
||||
href: "https://github.com/blakeblackshear/frigate",
|
||||
label: "GitHub",
|
||||
position: "right",
|
||||
},
|
||||
],
|
||||
},
|
||||
|
||||
@@ -63,7 +63,8 @@ SYSTEM_NAV: dict[str, tuple[str, str]] = {
|
||||
"environment_vars": ("System", "Environment variables"),
|
||||
"telemetry": ("System", "Telemetry"),
|
||||
"birdseye": ("System", "Birdseye"),
|
||||
"models": ("System", "Detection models"),
|
||||
"detectors": ("System", "Detectors and model"),
|
||||
"model": ("System", "Detectors and model"),
|
||||
}
|
||||
|
||||
# All known top-level config section keys
|
||||
|
||||
@@ -122,7 +122,6 @@ const sidebars: SidebarsConfig = {
|
||||
"configuration/ffmpeg_presets",
|
||||
"configuration/pwa",
|
||||
"configuration/tls",
|
||||
"configuration/non_root",
|
||||
],
|
||||
},
|
||||
{
|
||||
|
||||
@@ -219,8 +219,6 @@ hardware:
|
||||
- host: "/run/mxa_manager"
|
||||
container: "/run/mxa_manager"
|
||||
comment: "MemryX manager"
|
||||
privileged: true
|
||||
privilegedReason: "required by MemryX to reach the max-manager"
|
||||
|
||||
- id: "axera"
|
||||
label: "AXERA Accelerator"
|
||||
|
||||
@@ -104,10 +104,6 @@ export interface DeviceConfig {
|
||||
extraHosts?: string[];
|
||||
/** Security options, e.g. ["apparmor=unconfined"] */
|
||||
securityOpt?: string[];
|
||||
/** Set only when this device type cannot work without full privileged mode */
|
||||
privileged?: boolean;
|
||||
/** Why privileged mode is required, rendered as an inline comment */
|
||||
privilegedReason?: string;
|
||||
/** Whether this device type needs the NVIDIA GPU config UI */
|
||||
needsNvidiaConfig?: boolean;
|
||||
}
|
||||
@@ -131,10 +127,6 @@ export interface HardwareOption {
|
||||
volumes?: VolumeMapping[];
|
||||
/** Extra environment variables */
|
||||
env?: Record<string, string>;
|
||||
/** Set only when this hardware cannot work without full privileged mode */
|
||||
privileged?: boolean;
|
||||
/** Why privileged mode is required, rendered as an inline comment */
|
||||
privilegedReason?: string;
|
||||
}
|
||||
|
||||
/** Port definition */
|
||||
|
||||
@@ -1,7 +1,6 @@
|
||||
import type {
|
||||
DeviceConfig,
|
||||
DeviceMapping,
|
||||
HardwareOption,
|
||||
VolumeMapping,
|
||||
} from "../config/types";
|
||||
import { hardwareMap } from "../config";
|
||||
@@ -195,32 +194,13 @@ function buildExtraHosts(device: DeviceConfig): string[] {
|
||||
}
|
||||
|
||||
function buildSecurityOpt(device: DeviceConfig): string[] {
|
||||
// no-new-privileges is the baseline for every setup; device-specific entries
|
||||
// are appended so only one security_opt key is ever emitted
|
||||
if (!device.securityOpt?.length) return [];
|
||||
return [
|
||||
" security_opt:",
|
||||
" - no-new-privileges:true",
|
||||
...(device.securityOpt ?? []).map((s) => ` - ${s}`),
|
||||
...device.securityOpt.map((s) => ` - ${s}`),
|
||||
];
|
||||
}
|
||||
|
||||
/**
|
||||
* Emit privileged mode only for hardware that genuinely cannot work without it.
|
||||
* Everything else gets device mappings, which grant far less access.
|
||||
*/
|
||||
function buildPrivileged(
|
||||
device: DeviceConfig,
|
||||
selectedHardware: HardwareOption[]
|
||||
): string[] {
|
||||
const requiring = [device, ...selectedHardware].filter((c) => c.privileged);
|
||||
if (!requiring.length) return [];
|
||||
const reasons = requiring
|
||||
.map((c) => c.privilegedReason)
|
||||
.filter((r): r is string => Boolean(r));
|
||||
const comment = reasons.length ? ` # ${reasons.join("; ")}` : "";
|
||||
return [` privileged: true${comment}`];
|
||||
}
|
||||
|
||||
// ---------------------------------------------------------------------------
|
||||
// Public API
|
||||
// ---------------------------------------------------------------------------
|
||||
@@ -237,14 +217,11 @@ export function generateDockerCompose(input: GeneratorInput): string {
|
||||
const hwVolumes: VolumeMapping[] = [];
|
||||
const hwEnv: Record<string, string> = {};
|
||||
|
||||
const selectedHw: HardwareOption[] = [];
|
||||
|
||||
for (const hwId of input.selectedHardware) {
|
||||
const hw = hardwareMap.get(hwId);
|
||||
if (!hw) continue;
|
||||
// Skip GPU device mapping for tensorrt images (it uses deploy instead)
|
||||
if (hw.id === "gpu" && device.imageTag === "stable-tensorrt") continue;
|
||||
selectedHw.push(hw);
|
||||
hwDevices.push(...(hw.devices ?? []));
|
||||
hwVolumes.push(...(hw.volumes ?? []));
|
||||
Object.assign(hwEnv, hw.env ?? {});
|
||||
@@ -254,7 +231,7 @@ export function generateDockerCompose(input: GeneratorInput): string {
|
||||
"services:",
|
||||
" frigate:",
|
||||
" container_name: frigate",
|
||||
...buildPrivileged(device, selectedHw),
|
||||
" privileged: true # This may not be necessary for all setups",
|
||||
" restart: unless-stopped",
|
||||
" stop_grace_period: 30s # Allow enough time to shut down the various services",
|
||||
...buildImage(device),
|
||||
|
||||
Vendored
+22
-357
@@ -713,7 +713,7 @@ paths:
|
||||
| `improve_contrast` | `ON`, `OFF` |
|
||||
| `ptz_autotracker` | `ON`, `OFF` |
|
||||
| `birdseye` | `ON`, `OFF` |
|
||||
| `birdseye_modes` | `CONTINUOUS`, `MOTION`, `ALL_OBJECTS`, `ALERTS`, `DETECTIONS`, `NONE`, or a comma-separated combination |
|
||||
| `birdseye_mode` | `CONTINUOUS`, `MOTION`, `OBJECTS` |
|
||||
| `motion_contour_area` | integer |
|
||||
| `motion_threshold` | integer |
|
||||
| `motion_mask` | `ON`, `OFF` |
|
||||
@@ -803,7 +803,7 @@ paths:
|
||||
| `improve_contrast` | `ON`, `OFF` |
|
||||
| `ptz_autotracker` | `ON`, `OFF` |
|
||||
| `birdseye` | `ON`, `OFF` |
|
||||
| `birdseye_modes` | `CONTINUOUS`, `MOTION`, `ALL_OBJECTS`, `ALERTS`, `DETECTIONS`, `NONE`, or a comma-separated combination |
|
||||
| `birdseye_mode` | `CONTINUOUS`, `MOTION`, `OBJECTS` |
|
||||
| `motion_contour_area` | integer |
|
||||
| `motion_threshold` | integer |
|
||||
| `motion_mask` | `ON`, `OFF` |
|
||||
@@ -2946,44 +2946,6 @@ paths:
|
||||
- frigateUserAuth: []
|
||||
x-required-role: any
|
||||
description: '**Access:** Any authenticated user.'
|
||||
/categorized_object_names:
|
||||
get:
|
||||
tags:
|
||||
- App
|
||||
summary: Get known object names by object type
|
||||
description: |-
|
||||
**Access:** Any authenticated user.
|
||||
|
||||
Returns the sub labels and attributes this install can attach,
|
||||
grouped by object type. Unlike /sub_labels, which reflects what has already been
|
||||
detected, this reads the config and model files, so it covers recognized face
|
||||
names, named license plates, custom object classification categories, and the
|
||||
detector attributes of tracked objects.
|
||||
operationId: categorized_object_names_categorized_object_names_get
|
||||
parameters:
|
||||
- name: object_type
|
||||
in: query
|
||||
required: false
|
||||
schema:
|
||||
anyOf:
|
||||
- type: string
|
||||
- type: 'null'
|
||||
title: Object Type
|
||||
responses:
|
||||
'200':
|
||||
description: Successful Response
|
||||
content:
|
||||
application/json:
|
||||
schema: {}
|
||||
'422':
|
||||
description: Validation Error
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: '#/components/schemas/HTTPValidationError'
|
||||
security:
|
||||
- frigateUserAuth: []
|
||||
x-required-role: any
|
||||
/audio_labels:
|
||||
get:
|
||||
tags:
|
||||
@@ -4010,101 +3972,6 @@ paths:
|
||||
security:
|
||||
- frigateAdminAuth: []
|
||||
x-required-role: admin
|
||||
/hardware/probe:
|
||||
get:
|
||||
tags:
|
||||
- Hardware
|
||||
summary: Probe Hardware
|
||||
description: |-
|
||||
**Access:** Admin role required.
|
||||
|
||||
Get the object detection hardware attached to this system.
|
||||
|
||||
Args:
|
||||
refresh: Probe again instead of returning the cached result
|
||||
|
||||
Returns:
|
||||
Every kind of detection hardware that was found
|
||||
operationId: probe_hardware_hardware_probe_get
|
||||
parameters:
|
||||
- name: refresh
|
||||
in: query
|
||||
required: false
|
||||
schema:
|
||||
type: boolean
|
||||
default: false
|
||||
title: Refresh
|
||||
responses:
|
||||
'200':
|
||||
description: Successful Response
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
type: array
|
||||
items:
|
||||
$ref: '#/components/schemas/DetectionHardware'
|
||||
title: Response Probe Hardware Hardware Probe Get
|
||||
'422':
|
||||
description: Validation Error
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: '#/components/schemas/HTTPValidationError'
|
||||
security:
|
||||
- frigateAdminAuth: []
|
||||
x-required-role: admin
|
||||
/hardware/hwaccel:
|
||||
get:
|
||||
tags:
|
||||
- Hardware
|
||||
summary: Hwaccel Recommendation
|
||||
description: |-
|
||||
**Access:** Admin role required.
|
||||
|
||||
Get the hardware decoding this system can do.
|
||||
|
||||
Args:
|
||||
detector: Hardware key of the detection hardware in use, which biases
|
||||
the recommendation toward that hardware's GPU
|
||||
codecs: Comma separated codecs of the streams that will be decoded,
|
||||
used to drop families that cannot decode one of them
|
||||
|
||||
Returns:
|
||||
The recommended family (empty when none fits) and every usable family
|
||||
operationId: hwaccel_recommendation_hardware_hwaccel_get
|
||||
parameters:
|
||||
- name: detector
|
||||
in: query
|
||||
required: false
|
||||
schema:
|
||||
anyOf:
|
||||
- type: string
|
||||
- type: 'null'
|
||||
title: Detector
|
||||
- name: codecs
|
||||
in: query
|
||||
required: false
|
||||
schema:
|
||||
anyOf:
|
||||
- type: string
|
||||
- type: 'null'
|
||||
title: Codecs
|
||||
responses:
|
||||
'200':
|
||||
description: Successful Response
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: '#/components/schemas/HwaccelRecommendation'
|
||||
'422':
|
||||
description: Validation Error
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: '#/components/schemas/HTTPValidationError'
|
||||
security:
|
||||
- frigateAdminAuth: []
|
||||
x-required-role: admin
|
||||
/events:
|
||||
get:
|
||||
tags:
|
||||
@@ -4206,6 +4073,16 @@ paths:
|
||||
- type: 'null'
|
||||
default: 100
|
||||
title: Limit
|
||||
- name: offset
|
||||
in: query
|
||||
required: false
|
||||
schema:
|
||||
anyOf:
|
||||
- type: integer
|
||||
minimum: 0
|
||||
- type: 'null'
|
||||
default: 0
|
||||
title: Offset
|
||||
- name: after
|
||||
in: query
|
||||
required: false
|
||||
@@ -4511,6 +4388,16 @@ paths:
|
||||
- type: 'null'
|
||||
default: 50
|
||||
title: Limit
|
||||
- name: offset
|
||||
in: query
|
||||
required: false
|
||||
schema:
|
||||
anyOf:
|
||||
- type: integer
|
||||
minimum: 0
|
||||
- type: 'null'
|
||||
default: 0
|
||||
title: Offset
|
||||
- name: cameras
|
||||
in: query
|
||||
required: false
|
||||
@@ -6117,65 +6004,6 @@ paths:
|
||||
security:
|
||||
- frigateUserAuth: []
|
||||
x-required-role: camera
|
||||
/vod/{camera_name}/{stream}/start/{start_ts}/end/{end_ts}:
|
||||
get:
|
||||
tags:
|
||||
- Media
|
||||
summary: Vod Ts Stream
|
||||
description: |-
|
||||
**Access:** Authenticated user with access to the referenced camera.
|
||||
|
||||
Returns an HLS playlist pinned to one stream type (main or sub) for the specified timestamp-range on the specified camera. Append /master.m3u8 or /index.m3u8 for HLS playback.
|
||||
operationId:
|
||||
vod_ts_stream_vod__camera_name___stream__start__start_ts__end__end_ts__get
|
||||
parameters:
|
||||
- name: camera_name
|
||||
in: path
|
||||
required: true
|
||||
schema:
|
||||
anyOf:
|
||||
- type: string
|
||||
- type: 'null'
|
||||
title: Camera Name
|
||||
- name: stream
|
||||
in: path
|
||||
required: true
|
||||
schema:
|
||||
$ref: '#/components/schemas/VodStreamPreference'
|
||||
- name: start_ts
|
||||
in: path
|
||||
required: true
|
||||
schema:
|
||||
type: number
|
||||
title: Start Ts
|
||||
- name: end_ts
|
||||
in: path
|
||||
required: true
|
||||
schema:
|
||||
type: number
|
||||
title: End Ts
|
||||
- name: force_discontinuity
|
||||
in: query
|
||||
required: false
|
||||
schema:
|
||||
type: boolean
|
||||
default: false
|
||||
title: Force Discontinuity
|
||||
responses:
|
||||
'200':
|
||||
description: Successful Response
|
||||
content:
|
||||
application/json:
|
||||
schema: {}
|
||||
'422':
|
||||
description: Validation Error
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: '#/components/schemas/HTTPValidationError'
|
||||
security:
|
||||
- frigateUserAuth: []
|
||||
x-required-role: camera
|
||||
/events/{event_id}/snapshot.jpg:
|
||||
get:
|
||||
tags:
|
||||
@@ -7114,63 +6942,6 @@ paths:
|
||||
security:
|
||||
- frigateUserAuth: []
|
||||
x-required-role: camera
|
||||
/{camera_name}/recordings/coverage:
|
||||
get:
|
||||
tags:
|
||||
- Recordings
|
||||
summary: Recordings Coverage
|
||||
description: |-
|
||||
**Access:** Authenticated user with access to the referenced camera.
|
||||
|
||||
Returns merged recording coverage spans plus codec compatibility.
|
||||
|
||||
codecs_compatible is false only when more than one known video codec
|
||||
appears across the range's rows, the case where the merged vod route
|
||||
degrades to a single-stream manifest.
|
||||
operationId: recordings_coverage__camera_name__recordings_coverage_get
|
||||
parameters:
|
||||
- name: camera_name
|
||||
in: path
|
||||
required: true
|
||||
schema:
|
||||
anyOf:
|
||||
- type: string
|
||||
- type: 'null'
|
||||
title: Camera Name
|
||||
- name: after
|
||||
in: query
|
||||
required: true
|
||||
schema:
|
||||
type: number
|
||||
title: After
|
||||
- name: before
|
||||
in: query
|
||||
required: true
|
||||
schema:
|
||||
type: number
|
||||
title: Before
|
||||
- name: timelines
|
||||
in: query
|
||||
required: false
|
||||
schema:
|
||||
type: boolean
|
||||
default: false
|
||||
title: Timelines
|
||||
responses:
|
||||
'200':
|
||||
description: Successful Response
|
||||
content:
|
||||
application/json:
|
||||
schema: {}
|
||||
'422':
|
||||
description: Validation Error
|
||||
content:
|
||||
application/json:
|
||||
schema:
|
||||
$ref: '#/components/schemas/HTTPValidationError'
|
||||
security:
|
||||
- frigateUserAuth: []
|
||||
x-required-role: camera
|
||||
/{camera_name}/recordings:
|
||||
get:
|
||||
tags:
|
||||
@@ -7937,46 +7708,6 @@ components:
|
||||
required:
|
||||
- ids
|
||||
title: DeleteFaceImagesBody
|
||||
DetectionHardware:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
title: Hardware key
|
||||
description: Stable identifier for this kind of hardware.
|
||||
detector:
|
||||
type: string
|
||||
title: Detector type
|
||||
description: The detector that drives this hardware.
|
||||
name:
|
||||
type: string
|
||||
title: Hardware name
|
||||
description: Human readable name for this kind of hardware.
|
||||
units:
|
||||
items:
|
||||
$ref: '#/components/schemas/HardwareUnit'
|
||||
type: array
|
||||
title: Units
|
||||
description: Each physical piece of this hardware that was found.
|
||||
count:
|
||||
type: integer
|
||||
title: Unit count
|
||||
description: How many units were found.
|
||||
unlimited:
|
||||
type: boolean
|
||||
title: Unlimited detectors
|
||||
description: Whether this hardware can run more inference processes
|
||||
than there are units.
|
||||
type: object
|
||||
required:
|
||||
- key
|
||||
- detector
|
||||
- name
|
||||
- units
|
||||
- count
|
||||
- unlimited
|
||||
title: DetectionHardware
|
||||
description: A kind of detection hardware, and every unit of it that was
|
||||
found.
|
||||
EventCreateResponse:
|
||||
properties:
|
||||
success:
|
||||
@@ -8704,61 +8435,6 @@ components:
|
||||
title: Detail
|
||||
type: object
|
||||
title: HTTPValidationError
|
||||
HardwareUnit:
|
||||
properties:
|
||||
device:
|
||||
type: string
|
||||
title: Device string
|
||||
description: The value to put in a model's devices list, for example
|
||||
'edgetpu:pci:1'.
|
||||
label:
|
||||
type: string
|
||||
title: Unit label
|
||||
description: How to identify this unit among others of the same kind,
|
||||
for example 'PCIe 1'.
|
||||
type: object
|
||||
required:
|
||||
- device
|
||||
- label
|
||||
title: HardwareUnit
|
||||
description: One physical piece of hardware.
|
||||
HwaccelFamily:
|
||||
properties:
|
||||
key:
|
||||
type: string
|
||||
title: Family key
|
||||
description: Stable identifier for this kind of hardware decoding.
|
||||
presets:
|
||||
additionalProperties:
|
||||
type: string
|
||||
type: object
|
||||
title: Presets
|
||||
description: The ffmpeg preset for each codec this family decodes, or
|
||||
a single 'any' preset when it decodes every codec.
|
||||
type: object
|
||||
required:
|
||||
- key
|
||||
- presets
|
||||
title: HwaccelFamily
|
||||
description: A kind of hardware decoding, and the presets that drive it.
|
||||
HwaccelRecommendation:
|
||||
properties:
|
||||
recommended:
|
||||
type: string
|
||||
title: Recommended family
|
||||
description: Key of the family that fits this system best, or an empty
|
||||
string when none does.
|
||||
available:
|
||||
items:
|
||||
$ref: '#/components/schemas/HwaccelFamily'
|
||||
type: array
|
||||
title: Available families
|
||||
description: Every family this system's hardware can use, best first.
|
||||
type: object
|
||||
required:
|
||||
- recommended
|
||||
title: HwaccelRecommendation
|
||||
description: The hardware decoding this system can do.
|
||||
Last24HoursReview:
|
||||
properties:
|
||||
reviewed_alert:
|
||||
@@ -9249,17 +8925,6 @@ components:
|
||||
- msg
|
||||
- type
|
||||
title: ValidationError
|
||||
VodStreamPreference:
|
||||
type: string
|
||||
enum:
|
||||
- main
|
||||
- sub
|
||||
title: VodStreamPreference
|
||||
description: |-
|
||||
Stream pin for the path-segment VOD route.
|
||||
|
||||
nginx-vod derives its mapping fetch URI from the playlist URL path
|
||||
(query params are dropped), so the preference must be a path segment.
|
||||
securitySchemes:
|
||||
frigateAdminAuth:
|
||||
type: apiKey
|
||||
|
||||
+29
-58
@@ -71,7 +71,6 @@ from frigate.util.config import (
|
||||
find_config_file,
|
||||
redact_credential,
|
||||
)
|
||||
from frigate.util.object_names import get_categorized_object_names
|
||||
from frigate.util.schema import get_config_schema
|
||||
from frigate.util.services import (
|
||||
get_nvidia_driver_info,
|
||||
@@ -292,6 +291,10 @@ def config(request: Request):
|
||||
config: dict[str, dict[str, Any]] = config_obj.model_dump(
|
||||
mode="json", warnings="none", exclude_none=True
|
||||
)
|
||||
config["detectors"] = {
|
||||
name: detector.model_dump(mode="json", warnings="none", exclude_none=True)
|
||||
for name, detector in config_obj.detectors.items()
|
||||
}
|
||||
|
||||
# remove environment_vars for non-admin users
|
||||
if request.headers.get("remote-role") != "admin":
|
||||
@@ -372,28 +375,31 @@ def config(request: Request):
|
||||
config["go2rtc"]["streams"][stream_name] = cleaned
|
||||
|
||||
config["plus"] = {"enabled": request.app.frigate_config.plus_api.is_active()}
|
||||
config["model"]["colormap"] = config_obj.model.colormap
|
||||
config["model"]["all_attributes"] = config_obj.model.all_attributes
|
||||
config["model"]["non_logo_attributes"] = config_obj.model.non_logo_attributes
|
||||
|
||||
for index, model in enumerate(config_obj.models):
|
||||
model_dict = config["models"][index]
|
||||
model_dict["colormap"] = model.colormap
|
||||
model_dict["all_attributes"] = model.all_attributes
|
||||
model_dict["non_logo_attributes"] = model.non_logo_attributes
|
||||
model_dict["labelmap"] = model.merged_labelmap
|
||||
|
||||
if not config["plus"]["enabled"]:
|
||||
continue
|
||||
|
||||
# Add model plus data if plus is enabled
|
||||
model_dict["plus"] = None
|
||||
|
||||
if model.path:
|
||||
model_json_path = FilePath(model.path).with_suffix(".json")
|
||||
|
||||
# Add model plus data if plus is enabled
|
||||
if config["plus"]["enabled"]:
|
||||
model_path = config.get("model", {}).get("path")
|
||||
if model_path:
|
||||
model_json_path = FilePath(model_path).with_suffix(".json")
|
||||
try:
|
||||
with open(model_json_path) as f:
|
||||
model_dict["plus"] = json.load(f)
|
||||
except (FileNotFoundError, json.JSONDecodeError):
|
||||
pass
|
||||
model_plus_data = json.load(f)
|
||||
config["model"]["plus"] = model_plus_data
|
||||
except FileNotFoundError:
|
||||
config["model"]["plus"] = None
|
||||
except json.JSONDecodeError:
|
||||
config["model"]["plus"] = None
|
||||
else:
|
||||
config["model"]["plus"] = None
|
||||
|
||||
# use merged labelamp
|
||||
for detector_config in config["detectors"].values():
|
||||
detector_config["model"]["labelmap"] = (
|
||||
request.app.frigate_config.model.merged_labelmap
|
||||
)
|
||||
|
||||
return JSONResponse(content=config)
|
||||
|
||||
@@ -1307,41 +1313,9 @@ def get_sub_labels(
|
||||
return JSONResponse(content=sub_labels)
|
||||
|
||||
|
||||
@router.get(
|
||||
"/categorized_object_names",
|
||||
dependencies=[Depends(allow_any_authenticated())],
|
||||
summary="Get known object names by object type",
|
||||
description="""Returns the sub labels and attributes this install can attach,
|
||||
grouped by object type. Unlike /sub_labels, which reflects what has already been
|
||||
detected, this reads the config and model files, so it covers recognized face
|
||||
names, named license plates, custom object classification categories, and the
|
||||
detector attributes of tracked objects.""",
|
||||
)
|
||||
def categorized_object_names(
|
||||
request: Request,
|
||||
object_type: str | None = None,
|
||||
allowed_cameras: list[str] = Depends(get_allowed_cameras_for_filter),
|
||||
):
|
||||
return JSONResponse(
|
||||
content=get_categorized_object_names(
|
||||
request.app.frigate_config, allowed_cameras, object_type
|
||||
)
|
||||
)
|
||||
|
||||
|
||||
@router.get("/audio_labels", dependencies=[Depends(allow_any_authenticated())])
|
||||
def get_audio_labels(request: Request):
|
||||
def get_audio_labels():
|
||||
labels = load_labels("/audio-labelmap.txt", prefill=521)
|
||||
|
||||
# configured overrides group several audio classes under one label, and the
|
||||
# detector merges them over the defaults at runtime. Offer them here too, or
|
||||
# a grouped label could never be picked in the UI.
|
||||
config: FrigateConfig = request.app.frigate_config
|
||||
labels.update(config.audio.labelmap)
|
||||
|
||||
for camera in config.cameras.values():
|
||||
labels.update(camera.audio.labelmap)
|
||||
|
||||
return JSONResponse(content=labels)
|
||||
|
||||
|
||||
@@ -1363,14 +1337,11 @@ def plusModels(request: Request, filterByCurrentModelDetector: bool = False):
|
||||
|
||||
modelList = models["list"]
|
||||
|
||||
config: FrigateConfig = request.app.frigate_config
|
||||
primary_model = config.primary_model
|
||||
|
||||
# current model type
|
||||
modelType = primary_model.model_type
|
||||
modelType = request.app.frigate_config.model.model_type
|
||||
|
||||
# current detectorType for comparing to supportedDetectors
|
||||
detectorType = config.devices_for_model(primary_model)[0].detector
|
||||
detectorType = list(request.app.frigate_config.detectors.values())[0].type
|
||||
|
||||
validModels = []
|
||||
|
||||
|
||||
+12
-25
@@ -83,7 +83,6 @@ def require_admin_by_default():
|
||||
"/nvinfo",
|
||||
"/labels",
|
||||
"/sub_labels",
|
||||
"/categorized_object_names",
|
||||
"/plus/models",
|
||||
"/recognized_license_plates",
|
||||
"/classification/attributes",
|
||||
@@ -128,23 +127,18 @@ def require_admin_by_default():
|
||||
if path.startswith(EXEMPT_PREFIXES):
|
||||
return
|
||||
|
||||
# Dynamic camera path exemption:
|
||||
# Any path whose first segment matches a configured camera name should
|
||||
# bypass the global admin requirement. These endpoints enforce access
|
||||
# via route-level dependencies (e.g. require_camera_access) to ensure
|
||||
# per-camera authorization. This allows non-admin authenticated users
|
||||
# (e.g. viewer role) to access camera-specific resources without
|
||||
# needing admin privileges.
|
||||
try:
|
||||
if path.startswith("/"):
|
||||
first_segment = path.split("/", 2)[1]
|
||||
if (
|
||||
first_segment
|
||||
and first_segment in request.app.frigate_config.cameras
|
||||
):
|
||||
return
|
||||
except Exception:
|
||||
pass
|
||||
# Camera routes enforce per-camera access via route-level dependencies
|
||||
# (e.g. require_camera_access). Match on the route template, not the raw
|
||||
# path, so a camera named like another namespace (e.g. "faces") can't
|
||||
# waive the admin check for that namespace's routes.
|
||||
route = request.scope.get("route")
|
||||
if (
|
||||
route is not None
|
||||
and route.path.startswith("/{camera_name}")
|
||||
and request.path_params.get("camera_name")
|
||||
in request.app.frigate_config.cameras
|
||||
):
|
||||
return
|
||||
|
||||
# For all other paths, require admin role
|
||||
# Internal port requests have admin role set automatically
|
||||
@@ -859,12 +853,9 @@ def login(request: Request, body: AppPostLoginBody):
|
||||
user = body.user
|
||||
password = body.password
|
||||
|
||||
remote_addr = get_remote_addr(request)
|
||||
|
||||
try:
|
||||
db_user: User = User.get_by_id(user)
|
||||
except DoesNotExist:
|
||||
logger.warning(f"Login failed for unknown user '{user}' from {remote_addr}")
|
||||
return JSONResponse(content={"message": "Login failed"}, status_code=401)
|
||||
|
||||
password_hash = db_user.password_hash
|
||||
@@ -892,10 +883,6 @@ def login(request: Request, body: AppPostLoginBody):
|
||||
request.app.frigate_config.auth.admin_first_time_login = False
|
||||
|
||||
return response
|
||||
|
||||
logger.warning(
|
||||
f"Login failed for user '{user}' (invalid password) from {remote_addr}"
|
||||
)
|
||||
return JSONResponse(content={"message": "Login failed"}, status_code=401)
|
||||
|
||||
|
||||
|
||||
+9
-41
@@ -33,9 +33,13 @@ from frigate.config.camera.updater import (
|
||||
CameraConfigUpdateEnum,
|
||||
CameraConfigUpdateTopic,
|
||||
)
|
||||
from frigate.config.env import UnknownVariableError, substitute_frigate_vars
|
||||
from frigate.config.env import substitute_frigate_vars
|
||||
from frigate.models import User
|
||||
from frigate.util.builtin import clean_camera_user_pass, get_record_segment_time
|
||||
from frigate.util.builtin import (
|
||||
clean_camera_user_pass,
|
||||
clear_orphaned_comments,
|
||||
get_record_segment_time,
|
||||
)
|
||||
from frigate.util.camera_cleanup import cleanup_camera_db, cleanup_camera_files
|
||||
from frigate.util.config import find_config_file
|
||||
from frigate.util.image import run_ffmpeg_snapshot
|
||||
@@ -166,7 +170,7 @@ def go2rtc_add_stream(request: Request, stream_name: str, src: str = ""):
|
||||
if src:
|
||||
try:
|
||||
resolved_src = substitute_frigate_vars(src)
|
||||
except UnknownVariableError:
|
||||
except KeyError:
|
||||
resolved_src = src
|
||||
|
||||
if is_restricted_go2rtc_source(resolved_src):
|
||||
@@ -651,32 +655,6 @@ async def _connect_onvif_camera(
|
||||
raise first_error
|
||||
|
||||
|
||||
def _supports_continuous_pan_tilt(nodes) -> bool:
|
||||
"""Whether any PTZ node advertises continuous pan/tilt velocity.
|
||||
|
||||
The web UI's directional controls issue ContinuousMove with a PanTilt
|
||||
velocity, so continuous pan/tilt is what makes those controls usable. This
|
||||
is intentionally narrower than ptz_supported, which is true for any device
|
||||
exposing the ONVIF PTZ service - including zoom/focus-only varifocal lenses.
|
||||
"""
|
||||
for node in nodes or []:
|
||||
spaces = getattr(node, "SupportedPTZSpaces", None) or (
|
||||
node.get("SupportedPTZSpaces") if isinstance(node, dict) else None
|
||||
)
|
||||
if spaces is None:
|
||||
continue
|
||||
|
||||
continuous = getattr(spaces, "ContinuousPanTiltVelocitySpace", None) or (
|
||||
spaces.get("ContinuousPanTiltVelocitySpace")
|
||||
if isinstance(spaces, dict)
|
||||
else None
|
||||
)
|
||||
if continuous:
|
||||
return True
|
||||
|
||||
return False
|
||||
|
||||
|
||||
@router.get(
|
||||
"/onvif/probe",
|
||||
dependencies=[Depends(require_role(["admin"]))],
|
||||
@@ -834,7 +812,6 @@ async def onvif_probe(
|
||||
|
||||
# Check PTZ support and capabilities
|
||||
ptz_supported = False
|
||||
pan_tilt_supported = False
|
||||
presets_count = 0
|
||||
autotrack_supported = False
|
||||
|
||||
@@ -868,15 +845,6 @@ async def onvif_probe(
|
||||
logger.debug(f"Failed to get presets: {e}")
|
||||
presets_count = 0
|
||||
|
||||
# Check for real (continuous) pan/tilt, which the UI controls need
|
||||
if ptz_supported:
|
||||
try:
|
||||
nodes = await ptz_service.GetNodes()
|
||||
pan_tilt_supported = _supports_continuous_pan_tilt(nodes)
|
||||
logger.debug(f"Continuous pan/tilt supported: {pan_tilt_supported}")
|
||||
except Exception as e:
|
||||
logger.debug(f"Failed to read PTZ nodes for pan/tilt support: {e}")
|
||||
|
||||
# Check for autotracking support - requires both FOV relative movement and MoveStatus
|
||||
if ptz_supported and first_profile_token and ptz_config_token:
|
||||
# First check for FOV relative movement support
|
||||
@@ -996,7 +964,6 @@ async def onvif_probe(
|
||||
"firmware_version": device_info["firmware_version"],
|
||||
"profiles_count": profiles_count,
|
||||
"ptz_supported": ptz_supported,
|
||||
"pan_tilt_supported": pan_tilt_supported,
|
||||
"presets_count": presets_count,
|
||||
"autotrack_supported": autotrack_supported,
|
||||
}
|
||||
@@ -1238,6 +1205,7 @@ async def delete_camera(
|
||||
# Remove camera from config
|
||||
if "cameras" in data and camera_name in data["cameras"]:
|
||||
del data["cameras"][camera_name]
|
||||
clear_orphaned_comments(data["cameras"], data, "cameras")
|
||||
|
||||
# Remove camera from auth roles
|
||||
auth = data.get("auth", {})
|
||||
@@ -1386,7 +1354,7 @@ def camera_set(
|
||||
| `improve_contrast` | `ON`, `OFF` |
|
||||
| `ptz_autotracker` | `ON`, `OFF` |
|
||||
| `birdseye` | `ON`, `OFF` |
|
||||
| `birdseye_modes` | `CONTINUOUS`, `MOTION`, `ALL_OBJECTS`, `ALERTS`, `DETECTIONS`, `NONE`, or a comma-separated combination |
|
||||
| `birdseye_mode` | `CONTINUOUS`, `MOTION`, `OBJECTS` |
|
||||
| `motion_contour_area` | integer |
|
||||
| `motion_threshold` | integer |
|
||||
| `motion_mask` | `ON`, `OFF` |
|
||||
|
||||
+4
-27
@@ -50,7 +50,6 @@ from frigate.jobs.vlm_watch import (
|
||||
stop_vlm_watch_job,
|
||||
)
|
||||
from frigate.models import Event
|
||||
from frigate.util.object_names import get_categorized_object_names
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
@@ -540,11 +539,6 @@ async def execute_tool(
|
||||
if tool_name == "search_objects":
|
||||
return await _execute_search_objects(request, arguments, allowed_cameras)
|
||||
|
||||
if tool_name == "get_categorized_object_names":
|
||||
return JSONResponse(
|
||||
content=_execute_get_categorized_object_names(request, allowed_cameras)
|
||||
)
|
||||
|
||||
if tool_name == "find_similar_objects":
|
||||
result = await _execute_find_similar_objects(
|
||||
request, arguments, allowed_cameras
|
||||
@@ -597,7 +591,7 @@ async def _execute_get_live_context(
|
||||
|
||||
try:
|
||||
frame_processor = request.app.detected_frames_processor
|
||||
camera_state = frame_processor.get_camera_state(camera)
|
||||
camera_state = frame_processor.camera_states.get(camera)
|
||||
|
||||
if camera_state is None:
|
||||
return {
|
||||
@@ -661,7 +655,7 @@ async def _get_live_frame_image_url(
|
||||
return None
|
||||
try:
|
||||
frame_processor = request.app.detected_frames_processor
|
||||
if frame_processor.get_camera_state(camera) is None:
|
||||
if camera not in frame_processor.camera_states:
|
||||
return None
|
||||
frame = frame_processor.get_current_frame(camera, {})
|
||||
if frame is None:
|
||||
@@ -723,21 +717,6 @@ async def _execute_set_camera_state(
|
||||
return {"success": True, "camera": camera, "feature": feature, "value": value}
|
||||
|
||||
|
||||
def _execute_get_categorized_object_names(
|
||||
request: Request,
|
||||
allowed_cameras: list[str],
|
||||
) -> dict[str, Any]:
|
||||
names = get_categorized_object_names(request.app.frigate_config, allowed_cameras)
|
||||
|
||||
if not names:
|
||||
return {
|
||||
"names": {},
|
||||
"message": "No names configured; search by label or semantic_query.",
|
||||
}
|
||||
|
||||
return {"names": names}
|
||||
|
||||
|
||||
async def _execute_tool_internal(
|
||||
tool_name: str,
|
||||
arguments: dict[str, Any],
|
||||
@@ -762,8 +741,6 @@ async def _execute_tool_internal(
|
||||
except (json.JSONDecodeError, AttributeError) as e:
|
||||
logger.warning(f"Failed to extract tool result: {e}")
|
||||
return {"error": "Failed to parse tool result"}
|
||||
elif tool_name == "get_categorized_object_names":
|
||||
return _execute_get_categorized_object_names(request, allowed_cameras)
|
||||
elif tool_name == "find_similar_objects":
|
||||
return await _execute_find_similar_objects(request, arguments, allowed_cameras)
|
||||
elif tool_name == "set_camera_state":
|
||||
@@ -796,8 +773,8 @@ async def _execute_tool_internal(
|
||||
else:
|
||||
logger.error(
|
||||
"Tool call failed: unknown tool %r. Expected one of: search_objects, find_similar_objects, "
|
||||
"get_categorized_object_names, get_live_context, start_camera_watch, stop_camera_watch, "
|
||||
"get_profile_status, get_recap. Arguments received: %s",
|
||||
"get_live_context, start_camera_watch, stop_camera_watch, get_profile_status, get_recap. "
|
||||
"Arguments received: %s",
|
||||
tool_name,
|
||||
json.dumps(arguments),
|
||||
)
|
||||
|
||||
@@ -14,6 +14,7 @@ class EventsQueryParams(BaseModel):
|
||||
zone: str | None = "all"
|
||||
zones: str | None = "all"
|
||||
limit: int | None = 100
|
||||
offset: int | None = Field(0, ge=0)
|
||||
after: float | None = None
|
||||
before: float | None = None
|
||||
time_range: str | None = DEFAULT_TIME_RANGE
|
||||
@@ -55,6 +56,7 @@ class EventsSearchQueryParams(BaseModel):
|
||||
deprecated=True,
|
||||
)
|
||||
limit: int | None = 50
|
||||
offset: int | None = Field(0, ge=0)
|
||||
cameras: str | None = "all"
|
||||
labels: str | None = "all"
|
||||
sub_labels: str | None = "all"
|
||||
|
||||
@@ -8,7 +8,6 @@ class Tags(Enum):
|
||||
chat = "Chat"
|
||||
events = "Events"
|
||||
export = "Export"
|
||||
hardware = "Hardware"
|
||||
classification = "Classification"
|
||||
logs = "Logs"
|
||||
media = "Media"
|
||||
|
||||
+13
-4
@@ -129,6 +129,7 @@ def events(
|
||||
zones = zone
|
||||
|
||||
limit = params.limit
|
||||
offset = params.offset
|
||||
after = params.after
|
||||
before = params.before
|
||||
time_range = params.time_range
|
||||
@@ -361,11 +362,15 @@ def events(
|
||||
else:
|
||||
order_by = Event.start_time.desc()
|
||||
|
||||
# offset paging needs a stable order when scores or speeds tie
|
||||
tiebreaker = [Event.id] if sort and sort.startswith(("score", "speed")) else []
|
||||
|
||||
events = (
|
||||
Event.select(*selected_columns)
|
||||
.where(reduce(operator.and_, clauses))
|
||||
.order_by(order_by)
|
||||
.order_by(order_by, *tiebreaker)
|
||||
.limit(limit)
|
||||
.offset(offset)
|
||||
.dicts()
|
||||
.iterator()
|
||||
)
|
||||
@@ -518,6 +523,7 @@ def events_search(
|
||||
search_type = params.search_type
|
||||
include_thumbnails = params.include_thumbnails
|
||||
limit = params.limit
|
||||
offset = params.offset
|
||||
sort = params.sort
|
||||
|
||||
# Filters
|
||||
@@ -824,6 +830,9 @@ def events_search(
|
||||
if search_results:
|
||||
events_query = events_query.where(Event.id << list(search_results.keys()))
|
||||
|
||||
# sorts below are stable, so this orders ties for offset paging
|
||||
events_query = events_query.order_by(Event.id)
|
||||
|
||||
# Fetch events and process them in a single pass
|
||||
processed_events = []
|
||||
for event in events_query.dicts():
|
||||
@@ -881,7 +890,7 @@ def events_search(
|
||||
processed_events.sort(key=lambda x: x["start_time"], reverse=True)
|
||||
|
||||
# Limit the number of events returned
|
||||
processed_events = processed_events[:limit]
|
||||
processed_events = processed_events[offset:][:limit]
|
||||
|
||||
return JSONResponse(content=processed_events)
|
||||
|
||||
@@ -1313,7 +1322,7 @@ async def set_sub_label(
|
||||
if request.app.detected_frames_processor:
|
||||
tracked_obj: TrackedObject = None
|
||||
|
||||
for state in request.app.detected_frames_processor.get_camera_states():
|
||||
for state in request.app.detected_frames_processor.camera_states.values():
|
||||
tracked_obj = state.tracked_objects.get(event_id)
|
||||
|
||||
if tracked_obj is not None:
|
||||
@@ -1372,7 +1381,7 @@ async def set_plate(
|
||||
if request.app.detected_frames_processor:
|
||||
tracked_obj: TrackedObject = None
|
||||
|
||||
for state in request.app.detected_frames_processor.get_camera_states():
|
||||
for state in request.app.detected_frames_processor.camera_states.values():
|
||||
tracked_obj = state.tracked_objects.get(event_id)
|
||||
|
||||
if tracked_obj is not None:
|
||||
|
||||
+9
-65
@@ -1,9 +1,7 @@
|
||||
"""Export apis."""
|
||||
|
||||
import contextlib
|
||||
import datetime
|
||||
import logging
|
||||
import os
|
||||
import random
|
||||
import string
|
||||
import time
|
||||
@@ -17,7 +15,7 @@ import psutil
|
||||
from fastapi import APIRouter, Depends, Query, Request
|
||||
from fastapi.responses import JSONResponse, StreamingResponse
|
||||
from pathvalidate import sanitize_filename
|
||||
from peewee import DatabaseError, DoesNotExist, IntegrityError
|
||||
from peewee import DoesNotExist
|
||||
from playhouse.shortcuts import model_to_dict
|
||||
|
||||
from frigate.api.auth import (
|
||||
@@ -71,9 +69,9 @@ from frigate.jobs.export import (
|
||||
from frigate.models import Export, ExportCase, Previews, Recordings
|
||||
from frigate.record.export import (
|
||||
DEFAULT_TIME_LAPSE_FFMPEG_ARGS,
|
||||
DEFAULT_TIME_LAPSE_FFMPEG_INPUT_ARGS,
|
||||
ChaptersEnum,
|
||||
PlaybackSourceEnum,
|
||||
export_video_path,
|
||||
validate_ffmpeg_args,
|
||||
)
|
||||
from frigate.util.path import sanitize_contained_path
|
||||
@@ -407,17 +405,14 @@ class _StreamingZipBuffer:
|
||||
|
||||
|
||||
def _unique_archive_name(export: Export, used: set[str]) -> str:
|
||||
"""Zip entry name for an export, de-duplicated within the archive.
|
||||
|
||||
The on-disk name is the one the user sees either way: renaming an export
|
||||
renames its file, so a zip entry and an individual download can't drift.
|
||||
"""
|
||||
source = Path(export.video_path)
|
||||
candidate = source.name
|
||||
base = sanitize_filename(export.name) if export.name else None
|
||||
if not base:
|
||||
base = f"{export.camera}_{int(export.date)}"
|
||||
|
||||
candidate = f"{base}.mp4"
|
||||
counter = 1
|
||||
while candidate in used:
|
||||
candidate = f"{source.stem}_{counter}{source.suffix}"
|
||||
candidate = f"{base}_{counter}.mp4"
|
||||
counter += 1
|
||||
|
||||
used.add(candidate)
|
||||
@@ -933,59 +928,8 @@ async def export_rename(event_id: str, body: ExportRenameBody, request: Request)
|
||||
status_code=404,
|
||||
)
|
||||
|
||||
if export.in_progress:
|
||||
return JSONResponse(
|
||||
content={
|
||||
"success": False,
|
||||
"message": "Export is still being written and can't be renamed yet.",
|
||||
},
|
||||
status_code=400,
|
||||
)
|
||||
|
||||
new_path = export_video_path(body.name, export.id)
|
||||
old_path = export.video_path
|
||||
moved = new_path != old_path
|
||||
|
||||
# move the file first so a rename that can't happen leaves the row alone
|
||||
if moved:
|
||||
try:
|
||||
os.rename(old_path, new_path)
|
||||
except OSError:
|
||||
logger.exception("Failed to rename export file for %s", event_id)
|
||||
return JSONResponse(
|
||||
content={"success": False, "message": "Failed to rename export."},
|
||||
status_code=500,
|
||||
)
|
||||
|
||||
export.name = body.name
|
||||
export.video_path = new_path
|
||||
|
||||
try:
|
||||
export.save()
|
||||
except DatabaseError as err:
|
||||
# the queue database has no transactions, so undo the move by hand
|
||||
if moved:
|
||||
with contextlib.suppress(OSError):
|
||||
os.rename(new_path, old_path)
|
||||
|
||||
if isinstance(err, IntegrityError):
|
||||
logger.warning(
|
||||
"Export %s cannot be renamed, %s is taken", event_id, new_path
|
||||
)
|
||||
return JSONResponse(
|
||||
content={
|
||||
"success": False,
|
||||
"message": "Another export already uses that name.",
|
||||
},
|
||||
status_code=409,
|
||||
)
|
||||
|
||||
logger.exception("Failed to save renamed export %s", event_id)
|
||||
return JSONResponse(
|
||||
content={"success": False, "message": "Failed to rename export."},
|
||||
status_code=500,
|
||||
)
|
||||
|
||||
export.save()
|
||||
return JSONResponse(
|
||||
content=(
|
||||
{
|
||||
@@ -1069,7 +1013,7 @@ def export_recording_custom(
|
||||
|
||||
# Set default values if not provided (timelapse defaults)
|
||||
if ffmpeg_input_args is None:
|
||||
ffmpeg_input_args = ""
|
||||
ffmpeg_input_args = DEFAULT_TIME_LAPSE_FFMPEG_INPUT_ARGS
|
||||
|
||||
if ffmpeg_output_args is None:
|
||||
ffmpeg_output_args = DEFAULT_TIME_LAPSE_FFMPEG_ARGS
|
||||
|
||||
@@ -21,7 +21,6 @@ from frigate.api import (
|
||||
debug_replay,
|
||||
event,
|
||||
export,
|
||||
hardware,
|
||||
media,
|
||||
motion_search,
|
||||
notification,
|
||||
@@ -146,7 +145,6 @@ def create_fastapi_app(
|
||||
app.include_router(preview.router)
|
||||
app.include_router(notification.router)
|
||||
app.include_router(export.router)
|
||||
app.include_router(hardware.router)
|
||||
app.include_router(event.router)
|
||||
app.include_router(media.router)
|
||||
app.include_router(motion_search.router)
|
||||
|
||||
@@ -1,57 +0,0 @@
|
||||
"""Hardware discovery APIs."""
|
||||
|
||||
import logging
|
||||
|
||||
from fastapi import APIRouter, Depends
|
||||
|
||||
from frigate.api.auth import require_role
|
||||
from frigate.api.defs.tags import Tags
|
||||
from frigate.detectors.hardware import DetectionHardware, hardware_prober
|
||||
from frigate.util.hwaccel import HwaccelRecommendation, hwaccel_options
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
router = APIRouter(tags=[Tags.hardware])
|
||||
|
||||
|
||||
@router.get(
|
||||
"/hardware/probe",
|
||||
response_model=list[DetectionHardware],
|
||||
dependencies=[Depends(require_role(["admin"]))],
|
||||
)
|
||||
def probe_hardware(refresh: bool = False) -> list[DetectionHardware]:
|
||||
"""Get the object detection hardware attached to this system.
|
||||
|
||||
Args:
|
||||
refresh: Probe again instead of returning the cached result
|
||||
|
||||
Returns:
|
||||
Every kind of detection hardware that was found
|
||||
"""
|
||||
return hardware_prober.probe(refresh=refresh)
|
||||
|
||||
|
||||
@router.get(
|
||||
"/hardware/hwaccel",
|
||||
response_model=HwaccelRecommendation,
|
||||
dependencies=[Depends(require_role(["admin"]))],
|
||||
)
|
||||
def hwaccel_recommendation(
|
||||
detector: str | None = None, codecs: str | None = None
|
||||
) -> HwaccelRecommendation:
|
||||
"""Get the hardware decoding this system can do.
|
||||
|
||||
Args:
|
||||
detector: Hardware key of the detection hardware in use, which biases
|
||||
the recommendation toward that hardware's GPU
|
||||
codecs: Comma separated codecs of the streams that will be decoded,
|
||||
used to drop families that cannot decode one of them
|
||||
|
||||
Returns:
|
||||
The recommended family (empty when none fits) and every usable family
|
||||
"""
|
||||
wanted = {
|
||||
codec.strip().lower() for codec in (codecs or "").split(",") if codec.strip()
|
||||
}
|
||||
recommended, available = hwaccel_options(detector, wanted)
|
||||
return HwaccelRecommendation(recommended=recommended, available=available)
|
||||
+189
-352
@@ -6,13 +6,10 @@ import logging
|
||||
import math
|
||||
import os
|
||||
import subprocess as sp
|
||||
import tempfile
|
||||
import time
|
||||
from collections.abc import Iterator
|
||||
from datetime import UTC, datetime, timedelta
|
||||
from enum import Enum
|
||||
from pathlib import Path as FilePath
|
||||
from typing import IO, Any
|
||||
from typing import Any
|
||||
from urllib.parse import unquote
|
||||
|
||||
import cv2
|
||||
@@ -42,14 +39,12 @@ from frigate.config.camera.snapshots import SnapshotsConfig
|
||||
from frigate.const import (
|
||||
CACHE_DIR,
|
||||
INSTALL_DIR,
|
||||
MAX_SEGMENT_DURATION,
|
||||
PREVIEW_FRAME_TYPE,
|
||||
STREAM_TYPE_MAIN,
|
||||
STREAM_TYPE_SUB,
|
||||
)
|
||||
from frigate.models import Event, Previews, Recordings, Regions, ReviewSegment
|
||||
from frigate.output.preview import get_most_recent_preview_frame
|
||||
from frigate.track.object_processing import TrackedObjectProcessor
|
||||
from frigate.util.ffmpeg import terminate_ffmpeg_stream
|
||||
from frigate.util.file import (
|
||||
get_event_snapshot_bytes,
|
||||
get_event_snapshot_path,
|
||||
@@ -57,40 +52,12 @@ from frigate.util.file import (
|
||||
load_event_snapshot_image,
|
||||
)
|
||||
from frigate.util.image import get_image_from_recording, get_image_quality_params
|
||||
from frigate.util.media import get_keyframe_before
|
||||
from frigate.util.object import create_empty_regions_grid
|
||||
from frigate.util.recording_coverage import (
|
||||
build_spans,
|
||||
null_audio_glitches,
|
||||
plan_clip,
|
||||
resolve_coverage,
|
||||
stream_has_audio,
|
||||
)
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
# must match the patched MAX_CLIPS in docker/main/build_nginx.sh; a
|
||||
# normal hour needs ~360, one clip per recording file
|
||||
NGINX_VOD_MAX_CLIPS = 1080
|
||||
|
||||
# tail of ffmpeg's stderr kept for the clip download failure log
|
||||
CLIP_STDERR_LOG_BYTES = 8192
|
||||
|
||||
# how long a drained clip download waits for ffmpeg to exit on its own
|
||||
CLIP_FFMPEG_EXIT_TIMEOUT = 10
|
||||
|
||||
|
||||
class VodStreamPreference(str, Enum):
|
||||
"""Stream pin for the path-segment VOD route.
|
||||
|
||||
nginx-vod derives its mapping fetch URI from the playlist URL path
|
||||
(query params are dropped), so the preference must be a path segment.
|
||||
"""
|
||||
|
||||
main = STREAM_TYPE_MAIN
|
||||
sub = STREAM_TYPE_SUB
|
||||
|
||||
|
||||
router = APIRouter(tags=[Tags.media])
|
||||
|
||||
|
||||
@@ -352,7 +319,7 @@ async def get_snapshot_from_recording(
|
||||
& (frame_time <= Recordings.end_time)
|
||||
)
|
||||
.where(Recordings.camera == camera_name)
|
||||
.order_by(Recordings.stream_type.asc(), Recordings.start_time.desc())
|
||||
.order_by(Recordings.start_time.desc())
|
||||
.limit(1)
|
||||
.get()
|
||||
)
|
||||
@@ -371,7 +338,7 @@ async def get_snapshot_from_recording(
|
||||
& (frame_time <= Recordings.end_time)
|
||||
)
|
||||
.where(Recordings.camera == camera_name)
|
||||
.order_by(Recordings.stream_type.asc(), Recordings.start_time.desc())
|
||||
.order_by(Recordings.start_time.desc())
|
||||
.limit(1)
|
||||
.get()
|
||||
)
|
||||
@@ -384,8 +351,13 @@ async def get_snapshot_from_recording(
|
||||
mime_type = "png" if format == "png" else "jpeg"
|
||||
config: FrigateConfig = request.app.frigate_config
|
||||
|
||||
image_data = get_image_from_recording(
|
||||
config.ffmpeg, recording.path, time_in_segment, codec, height
|
||||
image_data = await asyncio.to_thread(
|
||||
get_image_from_recording,
|
||||
config.ffmpeg,
|
||||
recording.path,
|
||||
time_in_segment,
|
||||
codec,
|
||||
height,
|
||||
)
|
||||
|
||||
if not image_data:
|
||||
@@ -431,7 +403,7 @@ async def submit_recording_snapshot_to_plus(
|
||||
(frame_time >= Recordings.start_time) & (frame_time <= Recordings.end_time)
|
||||
)
|
||||
.where(Recordings.camera == camera_name)
|
||||
.order_by(Recordings.stream_type.asc(), Recordings.start_time.desc())
|
||||
.order_by(Recordings.start_time.desc())
|
||||
.limit(1)
|
||||
)
|
||||
|
||||
@@ -439,8 +411,12 @@ async def submit_recording_snapshot_to_plus(
|
||||
config: FrigateConfig = request.app.frigate_config
|
||||
recording: Recordings = recording_query.get()
|
||||
time_in_segment = frame_time - recording.start_time
|
||||
image_data = get_image_from_recording(
|
||||
config.ffmpeg, recording.path, time_in_segment, "png"
|
||||
image_data = await asyncio.to_thread(
|
||||
get_image_from_recording,
|
||||
config.ffmpeg,
|
||||
recording.path,
|
||||
time_in_segment,
|
||||
"png",
|
||||
)
|
||||
|
||||
if not image_data:
|
||||
@@ -474,53 +450,6 @@ async def submit_recording_snapshot_to_plus(
|
||||
)
|
||||
|
||||
|
||||
def _read_stderr_tail(stderr_file: IO[bytes]) -> str:
|
||||
"""Read back the last CLIP_STDERR_LOG_BYTES of a captured stderr file."""
|
||||
stderr_file.seek(0, os.SEEK_END)
|
||||
stderr_file.seek(max(0, stderr_file.tell() - CLIP_STDERR_LOG_BYTES))
|
||||
return stderr_file.read().decode("utf-8", "replace")
|
||||
|
||||
|
||||
def _run_clip_download(ffmpeg_cmd: list[str], file_path: str) -> Iterator[bytes]:
|
||||
"""Stream an ffmpeg concat remux to the client, always cleaning up after it."""
|
||||
stderr_file = None
|
||||
ffmpeg = None
|
||||
|
||||
try:
|
||||
stderr_file = tempfile.TemporaryFile()
|
||||
ffmpeg = sp.Popen(ffmpeg_cmd, stdout=sp.PIPE, stderr=stderr_file)
|
||||
|
||||
while True:
|
||||
data = ffmpeg.stdout.read(8192)
|
||||
|
||||
if not data:
|
||||
break
|
||||
|
||||
yield data
|
||||
|
||||
try:
|
||||
# wait rather than signal, so the real exit code survives
|
||||
ffmpeg.wait(timeout=CLIP_FFMPEG_EXIT_TIMEOUT)
|
||||
except sp.TimeoutExpired:
|
||||
pass
|
||||
finally:
|
||||
if ffmpeg is not None:
|
||||
# read before terminating: a None here is our teardown, not a failure
|
||||
exit_code = ffmpeg.poll()
|
||||
terminate_ffmpeg_stream(ffmpeg)
|
||||
|
||||
if exit_code:
|
||||
logger.error(
|
||||
"Failed to generate clip, ffmpeg logs: %s",
|
||||
_read_stderr_tail(stderr_file),
|
||||
)
|
||||
|
||||
if stderr_file is not None:
|
||||
stderr_file.close()
|
||||
|
||||
FilePath(file_path).unlink(missing_ok=True)
|
||||
|
||||
|
||||
@router.get(
|
||||
"/{camera_name}/start/{start_ts}/end/{end_ts}/clip.mp4",
|
||||
dependencies=[Depends(require_camera_access)],
|
||||
@@ -532,29 +461,40 @@ async def recording_clip(
|
||||
start_ts: float,
|
||||
end_ts: float,
|
||||
):
|
||||
def get_clip_query(stream_type: str):
|
||||
return (
|
||||
Recordings.select(
|
||||
Recordings.path,
|
||||
Recordings.start_time,
|
||||
Recordings.end_time,
|
||||
)
|
||||
.where(
|
||||
(Recordings.start_time.between(start_ts, end_ts))
|
||||
| (Recordings.end_time.between(start_ts, end_ts))
|
||||
| ((start_ts > Recordings.start_time) & (end_ts < Recordings.end_time))
|
||||
)
|
||||
.where(Recordings.camera == camera_name)
|
||||
.where(Recordings.stream_type == stream_type)
|
||||
.order_by(Recordings.start_time.asc())
|
||||
def run_download(ffmpeg_cmd: list[str], file_path: str):
|
||||
with sp.Popen(
|
||||
ffmpeg_cmd,
|
||||
stderr=sp.PIPE,
|
||||
stdout=sp.PIPE,
|
||||
text=False,
|
||||
) as ffmpeg:
|
||||
while True:
|
||||
data = ffmpeg.stdout.read(8192)
|
||||
if data is not None and len(data) > 0:
|
||||
yield data
|
||||
else:
|
||||
if ffmpeg.returncode and ffmpeg.returncode != 0:
|
||||
logger.error(
|
||||
f"Failed to generate clip, ffmpeg logs: {ffmpeg.stderr.read()}"
|
||||
)
|
||||
else:
|
||||
FilePath(file_path).unlink(missing_ok=True)
|
||||
break
|
||||
|
||||
recordings = (
|
||||
Recordings.select(
|
||||
Recordings.path,
|
||||
Recordings.start_time,
|
||||
Recordings.end_time,
|
||||
)
|
||||
|
||||
# never mix streams in one concat; use main when available and
|
||||
# fall back to sub for expired-main history
|
||||
recordings = get_clip_query(STREAM_TYPE_MAIN)
|
||||
|
||||
if recordings.count() == 0:
|
||||
recordings = get_clip_query(STREAM_TYPE_SUB)
|
||||
.where(
|
||||
(Recordings.start_time.between(start_ts, end_ts))
|
||||
| (Recordings.end_time.between(start_ts, end_ts))
|
||||
| ((start_ts > Recordings.start_time) & (end_ts < Recordings.end_time))
|
||||
)
|
||||
.where(Recordings.camera == camera_name)
|
||||
.order_by(Recordings.start_time.asc())
|
||||
)
|
||||
|
||||
if recordings.count() == 0:
|
||||
return JSONResponse(
|
||||
@@ -565,9 +505,7 @@ async def recording_clip(
|
||||
status_code=400,
|
||||
)
|
||||
|
||||
file_name = sanitize_filename(
|
||||
f"playlist_{camera_name}_{start_ts}-{end_ts}_{os.urandom(4).hex()}.txt"
|
||||
)
|
||||
file_name = sanitize_filename(f"playlist_{camera_name}_{start_ts}-{end_ts}.txt")
|
||||
file_path = os.path.join(CACHE_DIR, file_name)
|
||||
with open(file_path, "w") as file:
|
||||
clip: Recordings
|
||||
@@ -615,195 +553,11 @@ async def recording_clip(
|
||||
]
|
||||
|
||||
return StreamingResponse(
|
||||
_run_clip_download(ffmpeg_cmd, file_path),
|
||||
run_download(ffmpeg_cmd, file_path),
|
||||
media_type="video/mp4",
|
||||
)
|
||||
|
||||
|
||||
def _build_vod_clip(
|
||||
row: Any, start: float, end: float
|
||||
) -> tuple[dict[str, Any], int] | None:
|
||||
"""Build one nginx-vod clip dict + duration (ms) for a recording row trimmed to [start, end).
|
||||
|
||||
Realization comes entirely from the shared plan_clip, so the coverage
|
||||
endpoint's realized timelines match this manifest by construction.
|
||||
"""
|
||||
plan = plan_clip(row, start, end)
|
||||
|
||||
if plan.skipped:
|
||||
return None
|
||||
|
||||
clip: dict[str, Any] = {"type": "source", "path": row.path}
|
||||
if plan.clip_from_ms is not None:
|
||||
clip["clipFrom"] = plan.clip_from_ms
|
||||
if plan.key_frame_durations is not None:
|
||||
# real gaps enable keyframe-aligned sub-file segments (bootstrap
|
||||
# ladder); the whole-clip fallback keeps one segment per file,
|
||||
# the only safe cut without an index
|
||||
if plan.first_key_frame_offset_ms > 0:
|
||||
clip["firstKeyFrameOffset"] = plan.first_key_frame_offset_ms
|
||||
clip["keyFrameDurations"] = plan.key_frame_durations
|
||||
else:
|
||||
clip["keyFrameDurations"] = [plan.duration_ms]
|
||||
logger.debug(
|
||||
"VOD: added clip %s duration_ms=%s clipFrom=%s",
|
||||
row.path,
|
||||
plan.duration_ms,
|
||||
clip.get("clipFrom"),
|
||||
)
|
||||
return clip, plan.duration_ms
|
||||
|
||||
|
||||
async def _vod_response(
|
||||
camera_name: str,
|
||||
start_ts: float,
|
||||
end_ts: float,
|
||||
force_discontinuity: bool = False,
|
||||
stream_preference: str | None = None,
|
||||
) -> JSONResponse:
|
||||
"""Build an nginx-vod mapping JSON for a camera over a timestamp range.
|
||||
|
||||
Always a single-sequence mapping; quality selection happens in the
|
||||
frontend by choosing between this route and the stream-pinned routes.
|
||||
|
||||
Args:
|
||||
camera_name: The camera to build the mapping for
|
||||
start_ts: Range start as a unix timestamp
|
||||
end_ts: Range end as a unix timestamp
|
||||
force_discontinuity: Emit HLS discontinuity markers between clips
|
||||
stream_preference: Pin the manifest to one stream type ("main" or
|
||||
"sub"), serving only that stream's recordings
|
||||
"""
|
||||
logger.debug(
|
||||
"VOD: Generating VOD for %s from %s to %s with force_discontinuity=%s",
|
||||
camera_name,
|
||||
start_ts,
|
||||
end_ts,
|
||||
force_discontinuity,
|
||||
)
|
||||
intervals = resolve_coverage(camera_name, start_ts, end_ts)
|
||||
|
||||
# rows contradicting their stream's audio composition are
|
||||
# truncated-shutdown glitches
|
||||
main_audio = stream_has_audio(intervals, main=True)
|
||||
sub_audio = stream_has_audio(intervals, main=False)
|
||||
|
||||
spans = build_spans(
|
||||
null_audio_glitches(intervals, main_audio, sub_audio),
|
||||
stream_preference,
|
||||
)
|
||||
|
||||
durations: list[int] = []
|
||||
clips: list[dict[str, Any]] = []
|
||||
# gathered after glitch-nulling and span building, so the policy
|
||||
# decisions below reflect the manifest's real contents
|
||||
video_codecs: set[str] = set()
|
||||
audio_presence: set[bool] = set()
|
||||
audio_params: set[tuple[str | None, int | None]] = set()
|
||||
span_streams: set[bool] = set()
|
||||
for row, span_start, span_end, span_is_main in spans:
|
||||
logger.debug(
|
||||
"VOD: processing recording: %s start=%s end=%s duration=%s",
|
||||
row.path,
|
||||
row.start_time,
|
||||
row.end_time,
|
||||
row.duration,
|
||||
)
|
||||
built = _build_vod_clip(row, span_start, span_end)
|
||||
|
||||
if built is None:
|
||||
continue
|
||||
|
||||
clips.append(built[0])
|
||||
durations.append(built[1])
|
||||
span_streams.add(span_is_main)
|
||||
if row.video_codec is not None:
|
||||
video_codecs.add(row.video_codec)
|
||||
audio_presence.add(row.has_audio is not False)
|
||||
# legacy rows contribute no signature, so uniformly-unknown
|
||||
# history keeps the legacy shape
|
||||
if row.has_audio is not False and (
|
||||
row.audio_codec is not None or row.audio_rate is not None
|
||||
):
|
||||
audio_params.add((row.audio_codec, row.audio_rate))
|
||||
|
||||
# nginx-vod requires a uniform track count per sequence, and adding or
|
||||
# removing an audio track across an MSE discontinuity is unproven
|
||||
if len(audio_presence) > 1:
|
||||
logger.debug(
|
||||
"VOD: %s mixes audio-bearing and audio-less recordings between "
|
||||
"%s and %s; serving the range without audio",
|
||||
camera_name,
|
||||
start_ts,
|
||||
end_ts,
|
||||
)
|
||||
for clip in clips:
|
||||
clip["tracks"] = "v"
|
||||
|
||||
# discontinuity mode emits per-clip init segments, letting the decoder
|
||||
# reconfigure at each boundary. Stream type counts as a signature of
|
||||
# its own: the two encoders differ in SPS/PPS even when codec name and
|
||||
# audio params match, and a single-init manifest then decode-fails on
|
||||
# players that only configure from the init segment (iOS)
|
||||
use_discontinuity = (
|
||||
len(video_codecs) > 1 or len(audio_params) > 1 or len(span_streams) > 1
|
||||
)
|
||||
if use_discontinuity:
|
||||
logger.debug(
|
||||
"VOD: %s mixes media signatures between %s and %s (video codecs "
|
||||
"%s, audio params %s, streams %s); serving a discontinuity "
|
||||
"manifest with per-clip init segments",
|
||||
camera_name,
|
||||
start_ts,
|
||||
end_ts,
|
||||
sorted(video_codecs),
|
||||
sorted(audio_params, key=str),
|
||||
sorted(span_streams),
|
||||
)
|
||||
|
||||
if not clips:
|
||||
logger.error(
|
||||
f"No recordings found for {camera_name} during the requested time range"
|
||||
)
|
||||
return JSONResponse(
|
||||
content={
|
||||
"success": False,
|
||||
"message": "No recordings found.",
|
||||
},
|
||||
status_code=404,
|
||||
)
|
||||
|
||||
if len(clips) > NGINX_VOD_MAX_CLIPS:
|
||||
logger.warning(
|
||||
"VOD: %s needs %d clips between %s and %s, exceeding nginx's "
|
||||
"limit of %d; playback of this range will fail. This usually "
|
||||
"means the camera produced abnormally short recording segments "
|
||||
"(check the stream's timestamps)",
|
||||
camera_name,
|
||||
len(clips),
|
||||
start_ts,
|
||||
end_ts,
|
||||
NGINX_VOD_MAX_CLIPS,
|
||||
)
|
||||
|
||||
# segmentation comes from the vod_* nginx directives plus per-clip
|
||||
# keyFrameDurations; a segment_duration field here was always ignored
|
||||
# (nginx-vod parses only camelCase segmentDuration)
|
||||
hour_ago = datetime.now() - timedelta(hours=1)
|
||||
content = {
|
||||
"cache": hour_ago.timestamp() > start_ts,
|
||||
"discontinuity": force_discontinuity or use_discontinuity,
|
||||
"consistentSequenceMediaInfo": True,
|
||||
"durations": durations,
|
||||
"sequences": [{"clips": clips}],
|
||||
}
|
||||
if use_discontinuity:
|
||||
# clip-indexed naming is what makes nginx-vod emit per-clip
|
||||
# EXT-X-MAP outside of its live mode
|
||||
content["initialClipIndex"] = 1
|
||||
return JSONResponse(content=content)
|
||||
|
||||
|
||||
@router.get(
|
||||
"/vod/{camera_name}/start/{start_ts}/end/{end_ts}",
|
||||
dependencies=[Depends(require_camera_access)],
|
||||
@@ -815,8 +569,134 @@ async def vod_ts(
|
||||
end_ts: float,
|
||||
force_discontinuity: bool = False,
|
||||
):
|
||||
return await _vod_response(
|
||||
camera_name, start_ts, end_ts, force_discontinuity=force_discontinuity
|
||||
logger.debug(
|
||||
"VOD: Generating VOD for %s from %s to %s with force_discontinuity=%s",
|
||||
camera_name,
|
||||
start_ts,
|
||||
end_ts,
|
||||
force_discontinuity,
|
||||
)
|
||||
recordings = (
|
||||
Recordings.select(
|
||||
Recordings.path,
|
||||
Recordings.duration,
|
||||
Recordings.end_time,
|
||||
Recordings.start_time,
|
||||
)
|
||||
.where(
|
||||
Recordings.start_time.between(start_ts, end_ts)
|
||||
| Recordings.end_time.between(start_ts, end_ts)
|
||||
| ((start_ts > Recordings.start_time) & (end_ts < Recordings.end_time))
|
||||
)
|
||||
.where(Recordings.camera == camera_name)
|
||||
.order_by(Recordings.start_time.asc())
|
||||
.iterator()
|
||||
)
|
||||
|
||||
clips = []
|
||||
durations = []
|
||||
min_duration_ms = 100 # Minimum 100ms to ensure at least one video frame
|
||||
max_duration_ms = MAX_SEGMENT_DURATION * 1000
|
||||
|
||||
recording: Recordings
|
||||
for recording in recordings:
|
||||
logger.debug(
|
||||
"VOD: processing recording: %s start=%s end=%s duration=%s",
|
||||
recording.path,
|
||||
recording.start_time,
|
||||
recording.end_time,
|
||||
recording.duration,
|
||||
)
|
||||
|
||||
clip = {"type": "source", "path": recording.path}
|
||||
duration = int(recording.duration * 1000)
|
||||
|
||||
# adjust start offset if start_ts is after recording.start_time
|
||||
if start_ts > recording.start_time:
|
||||
inpoint = int((start_ts - recording.start_time) * 1000)
|
||||
clip["clipFrom"] = inpoint
|
||||
duration -= inpoint
|
||||
logger.debug(
|
||||
"VOD: applied clipFrom %sms to %s",
|
||||
inpoint,
|
||||
recording.path,
|
||||
)
|
||||
|
||||
# adjust end if recording.end_time is after end_ts
|
||||
if recording.end_time > end_ts:
|
||||
duration -= int((recording.end_time - end_ts) * 1000)
|
||||
|
||||
# nginx-vod-module pushes clipFrom forward to the next keyframe,
|
||||
# which can leave too few frames and produce an empty/unplayable
|
||||
# segment. Snap clipFrom back to the preceding keyframe so the
|
||||
# segment always starts with a decodable frame.
|
||||
if "clipFrom" in clip:
|
||||
keyframe_ms = get_keyframe_before(recording.path, clip["clipFrom"])
|
||||
if keyframe_ms is not None:
|
||||
gained = clip["clipFrom"] - keyframe_ms
|
||||
clip["clipFrom"] = keyframe_ms
|
||||
duration += gained
|
||||
logger.debug(
|
||||
"VOD: snapped clipFrom to keyframe at %sms for %s, duration now %sms",
|
||||
keyframe_ms,
|
||||
recording.path,
|
||||
duration,
|
||||
)
|
||||
else:
|
||||
# could not read keyframes, remove clipFrom to use full recording
|
||||
logger.debug(
|
||||
"VOD: no keyframe info for %s, removing clipFrom to use full recording",
|
||||
recording.path,
|
||||
)
|
||||
del clip["clipFrom"]
|
||||
duration = int(recording.duration * 1000)
|
||||
if recording.end_time > end_ts:
|
||||
duration -= int((recording.end_time - end_ts) * 1000)
|
||||
|
||||
if duration < min_duration_ms:
|
||||
# skip if the clip has no valid duration (too short to contain frames)
|
||||
logger.debug(
|
||||
"VOD: skipping recording %s - resulting duration %sms too short",
|
||||
recording.path,
|
||||
duration,
|
||||
)
|
||||
continue
|
||||
|
||||
if min_duration_ms <= duration < max_duration_ms:
|
||||
clip["keyFrameDurations"] = [duration]
|
||||
clips.append(clip)
|
||||
durations.append(duration)
|
||||
logger.debug(
|
||||
"VOD: added clip %s duration_ms=%s clipFrom=%s",
|
||||
recording.path,
|
||||
duration,
|
||||
clip.get("clipFrom"),
|
||||
)
|
||||
else:
|
||||
logger.warning(f"Recording clip is missing or empty: {recording.path}")
|
||||
|
||||
if not clips:
|
||||
logger.error(
|
||||
f"No recordings found for {camera_name} during the requested time range"
|
||||
)
|
||||
return JSONResponse(
|
||||
content={
|
||||
"success": False,
|
||||
"message": "No recordings found.",
|
||||
},
|
||||
status_code=404,
|
||||
)
|
||||
|
||||
hour_ago = datetime.now() - timedelta(hours=1)
|
||||
return JSONResponse(
|
||||
content={
|
||||
"cache": hour_ago.timestamp() > start_ts,
|
||||
"discontinuity": force_discontinuity,
|
||||
"consistentSequenceMediaInfo": True,
|
||||
"durations": durations,
|
||||
"segment_duration": max(durations),
|
||||
"sequences": [{"clips": clips}],
|
||||
}
|
||||
)
|
||||
|
||||
|
||||
@@ -905,43 +785,7 @@ async def vod_clip(
|
||||
start_ts: float,
|
||||
end_ts: float,
|
||||
):
|
||||
# the tracking-details player corrects its timeline from
|
||||
# sequences[0].clips[0].clipFrom
|
||||
return await _vod_response(
|
||||
camera_name,
|
||||
start_ts,
|
||||
end_ts,
|
||||
force_discontinuity=True,
|
||||
)
|
||||
|
||||
|
||||
# registered after /vod/clip/... on purpose: both routes are six path
|
||||
# segments, Starlette matches structurally in registration order, and the
|
||||
# enum validation on {stream} would otherwise 422 every /vod/clip request
|
||||
@router.get(
|
||||
"/vod/{camera_name}/{stream}/start/{start_ts}/end/{end_ts}",
|
||||
dependencies=[Depends(require_camera_access)],
|
||||
description="Returns an HLS playlist pinned to one stream type (main or sub) for the specified timestamp-range on the specified camera. Append /master.m3u8 or /index.m3u8 for HLS playback.",
|
||||
)
|
||||
async def vod_ts_stream(
|
||||
camera_name: str,
|
||||
stream: VodStreamPreference,
|
||||
start_ts: float,
|
||||
end_ts: float,
|
||||
force_discontinuity: bool = False,
|
||||
):
|
||||
"""VOD for a timestamp range pinned to one stream type.
|
||||
|
||||
How the frontend selects quality, now that mappings are always
|
||||
single-sequence.
|
||||
"""
|
||||
return await _vod_response(
|
||||
camera_name,
|
||||
start_ts,
|
||||
end_ts,
|
||||
force_discontinuity=force_discontinuity,
|
||||
stream_preference=stream.value,
|
||||
)
|
||||
return await vod_ts(camera_name, start_ts, end_ts, force_discontinuity=True)
|
||||
|
||||
|
||||
@router.get(
|
||||
@@ -979,13 +823,13 @@ async def event_snapshot(
|
||||
timestamp_style=request.app.frigate_config.cameras[
|
||||
event.camera
|
||||
].timestamp_style,
|
||||
colormap=request.app.frigate_config.model_for_camera(event.camera).colormap,
|
||||
colormap=request.app.frigate_config.model.colormap,
|
||||
)
|
||||
except DoesNotExist:
|
||||
# see if the object is currently being tracked
|
||||
try:
|
||||
camera_states: list[CameraState] = (
|
||||
request.app.detected_frames_processor.get_camera_states()
|
||||
request.app.detected_frames_processor.camera_states.values()
|
||||
)
|
||||
for camera_state in camera_states:
|
||||
if event_id in camera_state.tracked_objects:
|
||||
@@ -1060,10 +904,10 @@ async def event_thumbnail(
|
||||
except DoesNotExist:
|
||||
thumbnail_bytes = None
|
||||
|
||||
if not thumbnail_bytes:
|
||||
if thumbnail_bytes is None:
|
||||
# see if the object is currently being tracked
|
||||
try:
|
||||
camera_states = request.app.detected_frames_processor.get_camera_states()
|
||||
camera_states = request.app.detected_frames_processor.camera_states.values()
|
||||
for camera_state in camera_states:
|
||||
if event_id in camera_state.tracked_objects:
|
||||
tracked_obj = camera_state.tracked_objects.get(event_id)
|
||||
@@ -1076,7 +920,7 @@ async def event_thumbnail(
|
||||
status_code=404,
|
||||
)
|
||||
|
||||
if not thumbnail_bytes:
|
||||
if thumbnail_bytes is None:
|
||||
return JSONResponse(
|
||||
content={"success": False, "message": "Event not found"},
|
||||
status_code=404,
|
||||
@@ -1085,13 +929,6 @@ async def event_thumbnail(
|
||||
img_as_np = np.frombuffer(thumbnail_bytes, dtype=np.uint8)
|
||||
img = cv2.imdecode(img_as_np, flags=1)
|
||||
|
||||
if img is None:
|
||||
# thumbnail on disk is truncated or corrupt
|
||||
return JSONResponse(
|
||||
content={"success": False, "message": "Event not found"},
|
||||
status_code=404,
|
||||
)
|
||||
|
||||
# android notifications prefer a 2:1 ratio
|
||||
if format == "android":
|
||||
img = cv2.copyMakeBorder(
|
||||
@@ -1299,7 +1136,7 @@ async def event_snapshot_clean(request: Request, event_id: str, download: bool =
|
||||
# see if the object is currently being tracked
|
||||
try:
|
||||
camera_states = (
|
||||
request.app.detected_frames_processor.get_camera_states()
|
||||
request.app.detected_frames_processor.camera_states.values()
|
||||
)
|
||||
for camera_state in camera_states:
|
||||
if event_id in camera_state.tracked_objects:
|
||||
|
||||
+56
-190
@@ -25,20 +25,8 @@ from frigate.api.defs.query.recordings_query_parameters import (
|
||||
)
|
||||
from frigate.api.defs.response.generic_response import GenericResponse
|
||||
from frigate.api.defs.tags import Tags
|
||||
from frigate.const import (
|
||||
MAX_SEGMENT_DURATION,
|
||||
RECORD_DIR,
|
||||
STREAM_TYPE_MAIN,
|
||||
STREAM_TYPE_SUB,
|
||||
)
|
||||
from frigate.const import RECORD_DIR
|
||||
from frigate.models import Event, Recordings
|
||||
from frigate.util.recording_coverage import (
|
||||
coverage_spans,
|
||||
known_video_codecs,
|
||||
realized_timelines,
|
||||
resolve_coverage,
|
||||
stream_media_summary,
|
||||
)
|
||||
from frigate.util.time import get_dst_transitions
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
@@ -71,7 +59,7 @@ def get_recordings_storage_usage(request: Request):
|
||||
|
||||
|
||||
@router.get("/recordings/summary", dependencies=[Depends(allow_any_authenticated())])
|
||||
async def all_recordings_summary(
|
||||
def all_recordings_summary(
|
||||
request: Request,
|
||||
params: MediaRecordingsSummaryQueryParams = Depends(),
|
||||
allowed_cameras: list[str] = Depends(get_allowed_cameras_for_filter),
|
||||
@@ -88,23 +76,18 @@ async def all_recordings_summary(
|
||||
else:
|
||||
camera_list = allowed_cameras
|
||||
|
||||
min_time: float | None = None
|
||||
max_time: float | None = None
|
||||
for camera in camera_list:
|
||||
cam_min = (
|
||||
Recordings.select(fn.MIN(Recordings.start_time))
|
||||
.where(Recordings.camera == camera)
|
||||
.scalar()
|
||||
time_range_query = (
|
||||
Recordings.select(
|
||||
fn.MIN(Recordings.start_time).alias("min_time"),
|
||||
fn.MAX(Recordings.start_time).alias("max_time"),
|
||||
)
|
||||
if cam_min is None:
|
||||
continue
|
||||
cam_max = (
|
||||
Recordings.select(fn.MAX(Recordings.start_time))
|
||||
.where(Recordings.camera == camera)
|
||||
.scalar()
|
||||
)
|
||||
min_time = cam_min if min_time is None else min(min_time, cam_min)
|
||||
max_time = cam_max if max_time is None else max(max_time, cam_max)
|
||||
.where(Recordings.camera << camera_list)
|
||||
.dicts()
|
||||
.get()
|
||||
)
|
||||
|
||||
min_time = time_range_query.get("min_time")
|
||||
max_time = time_range_query.get("max_time")
|
||||
|
||||
if min_time is None or max_time is None:
|
||||
return JSONResponse(content={})
|
||||
@@ -114,60 +97,22 @@ async def all_recordings_summary(
|
||||
days: dict[str, bool] = {}
|
||||
|
||||
for period_start, period_end, period_offset in dst_periods:
|
||||
first_start = max(min_time, period_start - MAX_SEGMENT_DURATION)
|
||||
first_day = int((first_start + period_offset) // 86400)
|
||||
last_day = int((min(max_time, period_end) + period_offset) // 86400)
|
||||
day_expr = ((Recordings.start_time + period_offset) / 86400).cast("int")
|
||||
|
||||
day_idx = first_day
|
||||
while day_idx <= last_day:
|
||||
day_str = (dt.date(1970, 1, 1) + dt.timedelta(days=day_idx)).isoformat()
|
||||
day_start = day_idx * 86400 - period_offset
|
||||
day_end = day_start + 86400
|
||||
|
||||
if day_str in days:
|
||||
day_idx += 1
|
||||
continue
|
||||
|
||||
if day_end <= period_end:
|
||||
upper = Recordings.start_time < day_end
|
||||
else:
|
||||
upper = Recordings.start_time <= period_end
|
||||
|
||||
has_recordings = (
|
||||
Recordings.select(Recordings.id)
|
||||
.where(
|
||||
(Recordings.camera << camera_list)
|
||||
& (Recordings.end_time >= period_start)
|
||||
& (Recordings.start_time >= day_start)
|
||||
& upper
|
||||
)
|
||||
.exists()
|
||||
period_query = (
|
||||
Recordings.select(day_expr.alias("day_idx"))
|
||||
.where(
|
||||
(Recordings.camera << camera_list)
|
||||
& (Recordings.end_time >= period_start)
|
||||
& (Recordings.start_time <= period_end)
|
||||
)
|
||||
if has_recordings:
|
||||
days[day_str] = True
|
||||
day_idx += 1
|
||||
continue
|
||||
.distinct()
|
||||
.namedtuples()
|
||||
)
|
||||
|
||||
# empty day
|
||||
next_start: float | None = None
|
||||
for camera in camera_list:
|
||||
cam_next = (
|
||||
Recordings.select(fn.MIN(Recordings.start_time))
|
||||
.where(
|
||||
Recordings.camera == camera,
|
||||
Recordings.start_time >= day_end,
|
||||
Recordings.start_time <= period_end,
|
||||
)
|
||||
.scalar()
|
||||
)
|
||||
if cam_next is not None and (
|
||||
next_start is None or cam_next < next_start
|
||||
):
|
||||
next_start = cam_next
|
||||
|
||||
if next_start is None:
|
||||
break
|
||||
day_idx = max(day_idx + 1, int((next_start + period_offset) // 86400))
|
||||
for g in period_query:
|
||||
day_str = (dt.date(1970, 1, 1) + dt.timedelta(days=g.day_idx)).isoformat()
|
||||
days[day_str] = True
|
||||
|
||||
return JSONResponse(content=dict(sorted(days.items())))
|
||||
|
||||
@@ -204,28 +149,23 @@ async def recordings_summary(camera_name: str, timezone: str = "utc"):
|
||||
period_hour_modifier = f"{hours_offset} hour"
|
||||
period_minute_modifier = f"{minutes_offset} minute"
|
||||
|
||||
hour_expression = fn.strftime(
|
||||
"%Y-%m-%d %H",
|
||||
fn.datetime(
|
||||
Recordings.start_time,
|
||||
"unixepoch",
|
||||
period_hour_modifier,
|
||||
period_minute_modifier,
|
||||
),
|
||||
)
|
||||
|
||||
# sub rows duplicate the camera's motion/object stats, so
|
||||
# aggregating them too would double-count
|
||||
recording_groups = (
|
||||
Recordings.select(
|
||||
hour_expression.alias("hour"),
|
||||
fn.strftime(
|
||||
"%Y-%m-%d %H",
|
||||
fn.datetime(
|
||||
Recordings.start_time,
|
||||
"unixepoch",
|
||||
period_hour_modifier,
|
||||
period_minute_modifier,
|
||||
),
|
||||
).alias("hour"),
|
||||
fn.SUM(Recordings.duration).alias("duration"),
|
||||
fn.SUM(Recordings.motion).alias("motion"),
|
||||
fn.SUM(Recordings.objects).alias("objects"),
|
||||
)
|
||||
.where(
|
||||
(Recordings.camera == camera_name)
|
||||
& (Recordings.stream_type == STREAM_TYPE_MAIN)
|
||||
& (Recordings.end_time >= period_start)
|
||||
& (Recordings.start_time <= period_end)
|
||||
)
|
||||
@@ -234,23 +174,6 @@ async def recordings_summary(camera_name: str, timezone: str = "utc"):
|
||||
.namedtuples()
|
||||
)
|
||||
|
||||
# sub recordings can outlive main, so hours covered only by sub
|
||||
# rows are reported too, flagged as sub_only
|
||||
sub_groups = (
|
||||
Recordings.select(
|
||||
hour_expression.alias("hour"),
|
||||
fn.SUM(Recordings.duration).alias("duration"),
|
||||
)
|
||||
.where(
|
||||
(Recordings.camera == camera_name)
|
||||
& (Recordings.stream_type == STREAM_TYPE_SUB)
|
||||
& (Recordings.end_time >= period_start)
|
||||
& (Recordings.start_time <= period_end)
|
||||
)
|
||||
.group_by((Recordings.start_time + period_offset).cast("int") / 3600)
|
||||
.namedtuples()
|
||||
)
|
||||
|
||||
event_groups = (
|
||||
Event.select(
|
||||
fn.strftime(
|
||||
@@ -274,43 +197,17 @@ async def recordings_summary(camera_name: str, timezone: str = "utc"):
|
||||
|
||||
event_map = {g.hour: g.count for g in event_groups}
|
||||
|
||||
hour_stats = [
|
||||
(
|
||||
g.hour,
|
||||
{
|
||||
"motion": g.motion,
|
||||
"objects": g.objects,
|
||||
"duration": round(g.duration),
|
||||
},
|
||||
)
|
||||
for g in recording_groups
|
||||
]
|
||||
main_hours = {group_hour for group_hour, _ in hour_stats}
|
||||
hour_stats.extend(
|
||||
(
|
||||
g.hour,
|
||||
{
|
||||
"motion": 0,
|
||||
"objects": 0,
|
||||
"duration": round(g.duration),
|
||||
"sub_only": True,
|
||||
},
|
||||
)
|
||||
for g in sub_groups
|
||||
if g.hour not in main_hours
|
||||
)
|
||||
# restore the most-recent-first ordering after merging in sub hours
|
||||
hour_stats.sort(key=lambda entry: entry[0], reverse=True)
|
||||
|
||||
for group_hour, stats in hour_stats:
|
||||
parts = group_hour.split()
|
||||
for recording_group in recording_groups:
|
||||
parts = recording_group.hour.split()
|
||||
hour = parts[1]
|
||||
day = parts[0]
|
||||
events_count = event_map.get(group_hour, 0)
|
||||
events_count = event_map.get(recording_group.hour, 0)
|
||||
hour_data = {
|
||||
"hour": hour,
|
||||
"events": events_count,
|
||||
**stats,
|
||||
"motion": recording_group.motion,
|
||||
"objects": recording_group.objects,
|
||||
"duration": round(recording_group.duration),
|
||||
}
|
||||
if day in days:
|
||||
# merge counts if already present (edge-case at DST boundary)
|
||||
@@ -326,35 +223,6 @@ async def recordings_summary(camera_name: str, timezone: str = "utc"):
|
||||
return JSONResponse(content=list(days.values()))
|
||||
|
||||
|
||||
@router.get(
|
||||
"/{camera_name}/recordings/coverage",
|
||||
dependencies=[Depends(require_camera_access)],
|
||||
)
|
||||
async def recordings_coverage(
|
||||
camera_name: str, after: float, before: float, timelines: bool = False
|
||||
):
|
||||
"""Returns merged recording coverage spans plus codec compatibility.
|
||||
|
||||
codecs_compatible is false only when more than one known video codec
|
||||
appears across the range's rows, the case where the merged vod route
|
||||
degrades to a single-stream manifest.
|
||||
"""
|
||||
intervals = resolve_coverage(camera_name, after, before)
|
||||
|
||||
content = {
|
||||
"spans": coverage_spans(intervals),
|
||||
"codecs_compatible": len(known_video_codecs(intervals)) <= 1,
|
||||
"streams": stream_media_summary(intervals),
|
||||
}
|
||||
|
||||
# pure computation (shared plan_clip, record-time keyframe index), but
|
||||
# opt-in for payload hygiene: day-level requests need only the spans
|
||||
if timelines:
|
||||
content["timelines"] = realized_timelines(intervals)
|
||||
|
||||
return JSONResponse(content=content)
|
||||
|
||||
|
||||
@router.get("/{camera_name}/recordings", dependencies=[Depends(require_camera_access)])
|
||||
async def recordings(
|
||||
camera_name: str,
|
||||
@@ -375,8 +243,6 @@ async def recordings(
|
||||
)
|
||||
.where(
|
||||
Recordings.camera == camera_name,
|
||||
Recordings.stream_type == STREAM_TYPE_MAIN,
|
||||
Recordings.start_time >= after - MAX_SEGMENT_DURATION,
|
||||
Recordings.end_time >= after,
|
||||
Recordings.start_time <= before,
|
||||
)
|
||||
@@ -416,22 +282,22 @@ async def no_recordings(
|
||||
)
|
||||
scale = params.scale
|
||||
|
||||
recordings: list[tuple[float, float]] = []
|
||||
for camera in camera_list:
|
||||
recordings.extend(
|
||||
Recordings.select(Recordings.start_time, Recordings.end_time)
|
||||
.where(
|
||||
Recordings.camera == camera,
|
||||
Recordings.start_time >= after - MAX_SEGMENT_DURATION,
|
||||
Recordings.end_time >= after,
|
||||
Recordings.start_time <= before,
|
||||
)
|
||||
.tuples()
|
||||
.iterator()
|
||||
)
|
||||
clauses = [
|
||||
(Recordings.end_time >= after) & (Recordings.start_time <= before),
|
||||
(Recordings.camera << camera_list),
|
||||
]
|
||||
|
||||
# the merge pass below expects a single start-ordered timeline
|
||||
recordings.sort()
|
||||
# Get recording start times
|
||||
data: list[Recordings] = (
|
||||
Recordings.select(Recordings.start_time, Recordings.end_time)
|
||||
.where(reduce(operator.and_, clauses))
|
||||
.order_by(Recordings.start_time.asc())
|
||||
.dicts()
|
||||
.iterator()
|
||||
)
|
||||
|
||||
# Convert recordings to list of (start, end) tuples, ordered by start_time
|
||||
recordings = [(r["start_time"], r["end_time"]) for r in data]
|
||||
|
||||
# Merge overlapping/adjacent recordings into covered intervals. The query
|
||||
# orders by start_time, so a single pass merges them
|
||||
|
||||
+20
-14
@@ -33,7 +33,6 @@ from frigate.api.defs.response.review_response import (
|
||||
ReviewSummaryResponse,
|
||||
)
|
||||
from frigate.api.defs.tags import Tags
|
||||
from frigate.const import STREAM_TYPE_MAIN
|
||||
from frigate.embeddings import EmbeddingsContext
|
||||
from frigate.models import Recordings, ReviewSegment, UserReviewStatus
|
||||
from frigate.review.types import SeverityEnum
|
||||
@@ -44,6 +43,22 @@ logger = logging.getLogger(__name__)
|
||||
router = APIRouter(tags=[Tags.review])
|
||||
|
||||
|
||||
def get_label_clause(label: str, include_audio: bool = True):
|
||||
"""Build a clause matching a label within a review segment's data.
|
||||
|
||||
Verified objects are stored with a `-verified` suffix (eg. `person-verified`)
|
||||
so that variant is matched as well.
|
||||
"""
|
||||
clause = (ReviewSegment.data["objects"].cast("text") % f'*"{label}"*') | (
|
||||
ReviewSegment.data["objects"].cast("text") % f'*"{label}-verified"*'
|
||||
)
|
||||
|
||||
if include_audio:
|
||||
clause |= ReviewSegment.data["audio"].cast("text") % f'*"{label}"*'
|
||||
|
||||
return clause
|
||||
|
||||
|
||||
@router.get(
|
||||
"/review",
|
||||
response_model=list[ReviewSegmentResponse],
|
||||
@@ -93,10 +108,7 @@ async def review(
|
||||
filtered_labels = labels.split(",")
|
||||
|
||||
for label in filtered_labels:
|
||||
label_clauses.append(
|
||||
(ReviewSegment.data["objects"].cast("text") % f'*"{label}"*')
|
||||
| (ReviewSegment.data["audio"].cast("text") % f'*"{label}"*')
|
||||
)
|
||||
label_clauses.append(get_label_clause(label))
|
||||
clauses.append(reduce(operator.or_, label_clauses))
|
||||
|
||||
if zones != "all":
|
||||
@@ -237,10 +249,7 @@ async def review_summary(
|
||||
filtered_labels = labels.split(",")
|
||||
|
||||
for label in filtered_labels:
|
||||
label_clauses.append(
|
||||
(ReviewSegment.data["objects"].cast("text") % f'*"{label}"*')
|
||||
| (ReviewSegment.data["audio"].cast("text") % f'*"{label}"*')
|
||||
)
|
||||
label_clauses.append(get_label_clause(label))
|
||||
clauses.append(reduce(operator.or_, label_clauses))
|
||||
if zones != "all":
|
||||
# use matching so segments with multiple zones
|
||||
@@ -338,9 +347,8 @@ async def review_summary(
|
||||
filtered_labels = labels.split(",")
|
||||
|
||||
for label in filtered_labels:
|
||||
label_clauses.append(
|
||||
ReviewSegment.data["objects"].cast("text") % f'*"{label}"*'
|
||||
)
|
||||
label_clauses.append(get_label_clause(label, include_audio=False))
|
||||
|
||||
clauses.append(reduce(operator.or_, label_clauses))
|
||||
|
||||
# Find the time range of available data
|
||||
@@ -599,8 +607,6 @@ def motion_activity(
|
||||
|
||||
clauses = [(Recordings.start_time > after) & (Recordings.end_time < before)]
|
||||
clauses.append(Recordings.motion > 0)
|
||||
# sub rows duplicate the camera's motion stats, so only count main rows
|
||||
clauses.append(Recordings.stream_type == STREAM_TYPE_MAIN)
|
||||
|
||||
if cameras != "all":
|
||||
requested = set(cameras.split(","))
|
||||
|
||||
+22
-53
@@ -49,8 +49,6 @@ from frigate.debug_replay import (
|
||||
DebugReplayManager,
|
||||
cleanup_replay_cameras,
|
||||
)
|
||||
from frigate.detectors.detector_config import SceneEnum
|
||||
from frigate.detectors.device import build_detector_config, runner_names
|
||||
from frigate.embeddings import EmbeddingProcess, EmbeddingsContext
|
||||
from frigate.events.audio import AudioProcessor
|
||||
from frigate.events.cleanup import EventCleanup
|
||||
@@ -71,7 +69,6 @@ from frigate.models import (
|
||||
User,
|
||||
)
|
||||
from frigate.object_detection.base import ObjectDetectProcess
|
||||
from frigate.object_detection.util import detection_frame_size
|
||||
from frigate.output.output import OutputProcess
|
||||
from frigate.ptz.autotrack import PtzAutoTrackerThread
|
||||
from frigate.ptz.onvif import OnvifController
|
||||
@@ -86,7 +83,6 @@ from frigate.timeline import TimelineProcessor
|
||||
from frigate.track.object_processing import TrackedObjectProcessor
|
||||
from frigate.util.builtin import empty_and_close_queue
|
||||
from frigate.util.image import UntrackedSharedMemory
|
||||
from frigate.util.ownership import chown_to_runtime
|
||||
from frigate.util.process import FrigateProcess
|
||||
from frigate.util.services import set_file_limit
|
||||
from frigate.version import VERSION
|
||||
@@ -102,9 +98,7 @@ class FrigateApp:
|
||||
self.metrics_manager = manager
|
||||
self.audio_process: mp.Process | None = None
|
||||
self.stop_event = stop_event
|
||||
self.detection_queues: dict[SceneEnum, Queue] = {
|
||||
model.scene: mp.Queue() for model in config.models
|
||||
}
|
||||
self.detection_queue: Queue = mp.Queue()
|
||||
self.detectors: dict[str, ObjectDetectProcess] = {}
|
||||
self.detection_shms: list[mp.shared_memory.SharedMemory] = []
|
||||
self.log_queue: Queue = mp.Queue()
|
||||
@@ -150,7 +144,6 @@ class FrigateApp:
|
||||
if not os.path.exists(d) and not os.path.islink(d):
|
||||
logger.info(f"Creating directory: {d}")
|
||||
os.makedirs(d, exist_ok=True)
|
||||
chown_to_runtime(d)
|
||||
else:
|
||||
logger.debug(f"Skipping directory: {d}")
|
||||
|
||||
@@ -231,17 +224,6 @@ class FrigateApp:
|
||||
|
||||
migrate_db.close()
|
||||
|
||||
# a root frigate service creates these as root; wal and shm recreated
|
||||
# later in the run are realigned by the per-boot /config sweep
|
||||
for db_file in (
|
||||
self.config.database.path,
|
||||
f"{self.config.database.path}-wal",
|
||||
f"{self.config.database.path}-shm",
|
||||
self.config.database.path.replace("frigate.db", "backup.db"),
|
||||
):
|
||||
if os.path.exists(db_file):
|
||||
chown_to_runtime(db_file)
|
||||
|
||||
def init_go2rtc(self) -> None:
|
||||
for proc in psutil.process_iter(["pid", "name"]):
|
||||
if proc.info["name"] == "go2rtc":
|
||||
@@ -353,7 +335,6 @@ class FrigateApp:
|
||||
self.ptz_metrics,
|
||||
comms,
|
||||
)
|
||||
self.dispatcher.start_communicators()
|
||||
|
||||
def init_profile_manager(self) -> None:
|
||||
self.profile_manager = ProfileManager(
|
||||
@@ -362,19 +343,20 @@ class FrigateApp:
|
||||
self.dispatcher.profile_manager = self.profile_manager
|
||||
|
||||
def start_detectors(self) -> None:
|
||||
model_cameras: dict[SceneEnum, list[str]] = {
|
||||
model.scene: [] for model in self.config.models
|
||||
}
|
||||
|
||||
for name in self.config.cameras.keys():
|
||||
model = self.config.model_for_camera(name)
|
||||
model_cameras[model.scene].append(name)
|
||||
|
||||
try:
|
||||
largest_frame = max(
|
||||
[
|
||||
det.model.height * det.model.width * 3
|
||||
if det.model is not None
|
||||
else 320
|
||||
for det in self.config.detectors.values()
|
||||
]
|
||||
)
|
||||
shm_in = UntrackedSharedMemory(
|
||||
name=name,
|
||||
create=True,
|
||||
size=detection_frame_size(model),
|
||||
size=largest_frame,
|
||||
)
|
||||
except FileExistsError:
|
||||
shm_in = UntrackedSharedMemory(name=name)
|
||||
@@ -389,26 +371,15 @@ class FrigateApp:
|
||||
self.detection_shms.append(shm_in)
|
||||
self.detection_shms.append(shm_out)
|
||||
|
||||
# a device may be listed more than once to run additional inference
|
||||
# processes on it, so names are only unique once de-duplicated
|
||||
all_devices = [
|
||||
device
|
||||
for model in self.config.models
|
||||
for device in self.config.devices_for_model(model)
|
||||
]
|
||||
names = iter(runner_names(all_devices))
|
||||
|
||||
for model in self.config.models:
|
||||
for device in self.config.devices_for_model(model):
|
||||
name = next(names)
|
||||
self.detectors[name] = ObjectDetectProcess(
|
||||
name,
|
||||
self.detection_queues[model.scene],
|
||||
model_cameras[model.scene],
|
||||
self.config,
|
||||
build_detector_config(device, model),
|
||||
self.stop_event,
|
||||
)
|
||||
for name, detector_config in self.config.detectors.items():
|
||||
self.detectors[name] = ObjectDetectProcess(
|
||||
name,
|
||||
self.detection_queue,
|
||||
list(self.config.cameras.keys()),
|
||||
self.config,
|
||||
detector_config,
|
||||
self.stop_event,
|
||||
)
|
||||
|
||||
def start_ptz_autotracker(self) -> None:
|
||||
self.ptz_autotracker_thread = PtzAutoTrackerThread(
|
||||
@@ -439,7 +410,7 @@ class FrigateApp:
|
||||
def start_camera_processor(self) -> None:
|
||||
self.camera_maintainer = CameraMaintainer(
|
||||
self.config,
|
||||
self.detection_queues,
|
||||
self.detection_queue,
|
||||
self.detected_frames_queue,
|
||||
self.camera_metrics,
|
||||
self.ptz_metrics,
|
||||
@@ -703,10 +674,8 @@ class FrigateApp:
|
||||
for detector in self.detectors.values():
|
||||
detector.stop()
|
||||
|
||||
for detection_queue in self.detection_queues.values():
|
||||
empty_and_close_queue(detection_queue)
|
||||
|
||||
logger.info("Detection queues closed")
|
||||
empty_and_close_queue(self.detection_queue)
|
||||
logger.info("Detection queue closed")
|
||||
|
||||
self.detected_frames_processor.join()
|
||||
empty_and_close_queue(self.detected_frames_queue)
|
||||
|
||||
@@ -18,7 +18,6 @@ from frigate.config.camera.updater import (
|
||||
CameraConfigUpdateEnum,
|
||||
CameraConfigUpdateSubscriber,
|
||||
)
|
||||
from frigate.detectors.detector_config import NON_LOGO_ATTRIBUTES
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
@@ -104,12 +103,13 @@ class CameraActivityManager:
|
||||
all_objects: list[dict[str, Any]] = []
|
||||
|
||||
for camera in new_activity.keys():
|
||||
if camera not in self.config.cameras:
|
||||
camera_config = self.config.cameras.get(camera)
|
||||
if camera_config is None:
|
||||
continue
|
||||
|
||||
# handle cameras that were added dynamically
|
||||
if camera not in self.camera_all_object_counts:
|
||||
self.__init_camera(self.config.cameras[camera])
|
||||
self.__init_camera(camera_config)
|
||||
|
||||
new_objects = new_activity[camera].get("objects", [])
|
||||
all_objects.extend(new_objects)
|
||||
@@ -179,7 +179,7 @@ class CameraActivityManager:
|
||||
return
|
||||
|
||||
for label in camera_config.objects.track:
|
||||
if label in NON_LOGO_ATTRIBUTES:
|
||||
if label in self.config.model.non_logo_attributes:
|
||||
continue
|
||||
|
||||
new_count = all_objects[label]
|
||||
@@ -234,12 +234,13 @@ class AudioActivityManager:
|
||||
now = datetime.datetime.now().timestamp()
|
||||
|
||||
for camera in new_activity.keys():
|
||||
if camera not in self.config.cameras:
|
||||
camera_config = self.config.cameras.get(camera)
|
||||
if camera_config is None:
|
||||
continue
|
||||
|
||||
# handle cameras that were added dynamically
|
||||
if camera not in self.current_audio_detections:
|
||||
self.__init_camera(self.config.cameras[camera])
|
||||
self.__init_camera(camera_config)
|
||||
|
||||
new_detections = new_activity[camera].get("detections", [])
|
||||
if self.compare_audio_activity(camera, new_detections, now):
|
||||
|
||||
@@ -15,9 +15,7 @@ from frigate.config.camera.updater import (
|
||||
CameraConfigUpdateSubscriber,
|
||||
)
|
||||
from frigate.const import REPLAY_CAMERA_PREFIX
|
||||
from frigate.detectors.detector_config import SceneEnum
|
||||
from frigate.models import Regions
|
||||
from frigate.object_detection.util import detection_frame_size
|
||||
from frigate.util.builtin import empty_and_close_queue
|
||||
from frigate.util.image import SharedMemoryFrameManager, UntrackedSharedMemory
|
||||
from frigate.util.object import get_camera_regions_grid
|
||||
@@ -31,7 +29,7 @@ class CameraMaintainer(threading.Thread):
|
||||
def __init__(
|
||||
self,
|
||||
config: FrigateConfig,
|
||||
detection_queues: dict[SceneEnum, Queue],
|
||||
detection_queue: Queue,
|
||||
detected_frames_queue: Queue,
|
||||
camera_metrics: DictProxy,
|
||||
ptz_metrics: dict[str, PTZMetrics],
|
||||
@@ -40,7 +38,7 @@ class CameraMaintainer(threading.Thread):
|
||||
):
|
||||
super().__init__(name="camera_processor")
|
||||
self.config = config
|
||||
self.detection_queues = detection_queues
|
||||
self.detection_queue = detection_queue
|
||||
self.detected_frames_queue = detected_frames_queue
|
||||
self.stop_event = stop_event
|
||||
self.camera_metrics = camera_metrics
|
||||
@@ -81,11 +79,10 @@ class CameraMaintainer(threading.Thread):
|
||||
# create or update region grids for each camera
|
||||
for camera in self.config.cameras.values():
|
||||
assert camera.name is not None
|
||||
model = self.config.model_for_camera(camera.name)
|
||||
self.region_grids[camera.name] = get_camera_regions_grid(
|
||||
camera.name,
|
||||
camera.detect,
|
||||
max(model.width, model.height),
|
||||
max(self.config.model.width, self.config.model.height),
|
||||
)
|
||||
|
||||
def __calculate_shm_frame_count(self) -> int:
|
||||
@@ -117,7 +114,6 @@ class CameraMaintainer(threading.Thread):
|
||||
return
|
||||
|
||||
camera_stop_event = self.__ensure_camera_stop_event(name)
|
||||
model = self.config.model_for_camera(name)
|
||||
|
||||
if runtime:
|
||||
self.camera_metrics[name] = CameraMetrics(self.metrics_manager)
|
||||
@@ -127,24 +123,32 @@ class CameraMaintainer(threading.Thread):
|
||||
self.region_grids[name] = get_camera_regions_grid(
|
||||
name,
|
||||
config.detect,
|
||||
max(model.width, model.height),
|
||||
max(self.config.model.width, self.config.model.height),
|
||||
)
|
||||
|
||||
try:
|
||||
largest_frame = max(
|
||||
[
|
||||
det.model.height * det.model.width * 3
|
||||
if det.model is not None
|
||||
else 320
|
||||
for det in self.config.detectors.values()
|
||||
]
|
||||
)
|
||||
UntrackedSharedMemory(name=f"out-{name}", create=True, size=20 * 6 * 4)
|
||||
UntrackedSharedMemory(
|
||||
name=name,
|
||||
create=True,
|
||||
size=detection_frame_size(model),
|
||||
size=largest_frame,
|
||||
)
|
||||
except FileExistsError:
|
||||
pass
|
||||
|
||||
camera_process = CameraTracker(
|
||||
config,
|
||||
model,
|
||||
model.merged_labelmap,
|
||||
self.detection_queues[model.scene],
|
||||
self.config.model,
|
||||
self.config.model.merged_labelmap,
|
||||
self.detection_queue,
|
||||
self.detected_frames_queue,
|
||||
self.camera_metrics[name],
|
||||
self.ptz_metrics[name],
|
||||
|
||||
+12
-7
@@ -40,7 +40,6 @@ class CameraState:
|
||||
self.name = name
|
||||
self.config = config
|
||||
self.camera_config = config.cameras[name]
|
||||
self.model = config.model_for_camera(name)
|
||||
self.frame_manager = frame_manager
|
||||
self.best_objects: dict[str, TrackedObject] = {}
|
||||
self.tracked_objects: dict[str, TrackedObject] = {}
|
||||
@@ -63,7 +62,7 @@ class CameraState:
|
||||
self.lpr_min_obj_area: int = 0
|
||||
self.lp_objects = {
|
||||
label
|
||||
for label, attributes in self.model.attributes_map.items()
|
||||
for label, attributes in config.model.attributes_map.items()
|
||||
if "license_plate" in attributes
|
||||
}
|
||||
|
||||
@@ -107,7 +106,9 @@ class CameraState:
|
||||
thickness = 1
|
||||
else:
|
||||
thickness = 2
|
||||
color = self.model.colormap.get(obj["label"], (255, 255, 255))
|
||||
color = self.config.model.colormap.get(
|
||||
obj["label"], (255, 255, 255)
|
||||
)
|
||||
else:
|
||||
thickness = 1
|
||||
color = (255, 0, 0)
|
||||
@@ -129,7 +130,9 @@ class CameraState:
|
||||
and obj["frame_time"] == frame_time
|
||||
):
|
||||
thickness = 5
|
||||
color = self.model.colormap.get(obj["label"], (255, 255, 255))
|
||||
color = self.config.model.colormap.get(
|
||||
obj["label"], (255, 255, 255)
|
||||
)
|
||||
|
||||
# debug autotracking zooming - show the zoom factor box
|
||||
if (
|
||||
@@ -263,7 +266,9 @@ class CameraState:
|
||||
if draw_options.get("paths"):
|
||||
for obj in tracked_objects.values():
|
||||
if obj["frame_time"] == frame_time and obj["path_data"]:
|
||||
color = self.model.colormap.get(obj["label"], (255, 255, 255))
|
||||
color = self.config.model.colormap.get(
|
||||
obj["label"], (255, 255, 255)
|
||||
)
|
||||
|
||||
path_points = [
|
||||
(
|
||||
@@ -366,7 +371,7 @@ class CameraState:
|
||||
for id in new_ids:
|
||||
logger.debug(f"{self.name}: New tracked object ID: {id}")
|
||||
new_obj = tracked_objects[id] = TrackedObject(
|
||||
self.model,
|
||||
self.config.model,
|
||||
self.camera_config,
|
||||
self.config.ui,
|
||||
self.frame_cache,
|
||||
@@ -510,7 +515,7 @@ class CameraState:
|
||||
sub_label = None
|
||||
|
||||
if obj.obj_data.get("sub_label"):
|
||||
if obj.obj_data["sub_label"][0] in self.model.all_attributes:
|
||||
if obj.obj_data["sub_label"][0] in self.config.model.all_attributes:
|
||||
label = obj.obj_data["sub_label"][0]
|
||||
else:
|
||||
label = f"{object_type}-verified"
|
||||
|
||||
@@ -1,27 +1,11 @@
|
||||
from abc import ABC, abstractmethod
|
||||
from collections.abc import Callable
|
||||
from typing import TYPE_CHECKING, Any
|
||||
|
||||
if TYPE_CHECKING:
|
||||
from frigate.comms.dispatcher import Dispatcher
|
||||
from typing import Any
|
||||
|
||||
|
||||
class Communicator(ABC):
|
||||
"""pub/sub model via specific protocol."""
|
||||
|
||||
def attach_dispatcher(self, dispatcher: "Dispatcher") -> None:
|
||||
"""Receive the owning dispatcher.
|
||||
|
||||
Transports that need more than the receiver callback (the command topic
|
||||
surface, the snapshot API) take it here rather than reaching through the
|
||||
bound receiver.
|
||||
"""
|
||||
return None
|
||||
|
||||
def start(self) -> None:
|
||||
"""Start background I/O after receiver wiring is complete."""
|
||||
return None
|
||||
|
||||
@abstractmethod
|
||||
def publish(self, topic: str, payload: Any, retain: bool = False) -> None:
|
||||
"""Send data via specific protocol."""
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user