mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-09-28 10:56:52 +03:00
* Run the frigate service as the frigate user * Run go2rtc as its own restricted user * Run nginx as the frigate user with writable state in /tmp/nginx * Disable bandwidth stats gracefully when not running as root * Hand TensorRT model cache ownership to the runtime user * Document non-root operation and per-hardware device access * Create /media/frigate after the ownership sweep * Assert non-root services, JWT migration, and escape hatch in CI * only write the sweep sentinel when a media volume is mounted * tolerate homekit config chown failures in the go2rtc run script * chown the s6 log pipe so non-root nginx can reopen /dev/stdout * set HOME to /config for non-root services * run smoke nginx -t and the write probe as the runtime user * re-own the nginx shm cache on service restart * discard stdout for the unprivileged smoke nginx -t * unwrap hard-wrapped prose in the installation docs * report progress during the ownership sweep * document EXTRA_GROUPS as the only device access path for dropped services * expand the non-root device access docs with diagnosis steps and udev rules * document network storage ownership and the remaining detector hardware * skip lost+found during the ownership sweep * hand /tmp/cache to the runtime user before services start * make bundled models readable by the runtime user * reload nginx by signaling the master instead of parsing its config as root * harden root writes into unprivileged-owned paths Restrict the sweep sentinel to a mount at or below /media/frigate so a parent /media mount cannot bless a later-shadowed volume. Rebuild /tmp/nginx root-owned each start so root's cp and tempio writes cannot follow a symlink an unprivileged nginx planted in the previous run. * collapse the duplicated sentinel comment * add a service-runs-as-root helper for granular root services * validate FRIGATE_ROOT_SERVICES and fail fast on unknown names * let services listed in FRIGATE_ROOT_SERVICES skip the privilege drop * record the root-services mode in the sentinel and sweep small trees each boot * cache the runtime ids in the ownership helper * chown recordings, previews, and exports to the runtime user at create * chown the database files after init * recommend FRIGATE_ROOT_SERVICES in the bandwidth stats warning * assert granular root services in CI * document FRIGATE_ROOT_SERVICES * own every directory level created for a recording segment * clear the cached runtime ids when ownership tests finish * skip missing media paths in the per-boot ownership sweep * clarify granular root services docs * clean up * install acl for device access grants * grant runtime users access to mapped device nodes at boot * assert device access grants in CI * document automatic device access grants * stop telling users device access needs host side setup * clarify the non-root docs * link the migration script to the repo * group the manual device setup under one section * harden against symlink attacks /config is owned by the unprivileged runtime user after the ownership sweep, so root operations on files there could be redirected by a planted symlink. - go2rtc HomeKit setup: replace the root yq/jq normalization and chown with an O_NOFOLLOW helper (prepare_homekit.py), so a symlink at go2rtc_homekit.yml can't redirect a root write or chown onto another file - go2rtc binary override: ignore /config/go2rtc whenever the service runs as root, so a planted binary can't exec as root under FRIGATE_ROOT_SERVICES - sweep sentinel: read and write it through safe-sentinel, which trusts only a root-owned regular file and never follows a symlink, so it can't be forged to skip the migration or symlinked to clobber a root file - ownership sweep: chown with -execdir so a parent directory swapped for a symlink mid-walk can't redirect the chown out of the volume - validate inputs: restrict DEVICE_ACL_PATHS to /dev, require nonzero numeric EXTRA_GROUPS, and reject PUID/PGID that collide with the go2rtc ids - docs: correct the TLS key ownership note to match what actually happens * tweak docs * stop the ownership sweep chasing entries other mechanisms own * keep custom binaries out of root services only under granular root
96 lines
3.6 KiB
Plaintext
Executable File
96 lines
3.6 KiB
Plaintext
Executable File
#!/command/with-contenv bash
|
|
# shellcheck shell=bash
|
|
# Remap the frigate user to PUID/PGID and register EXTRA_GROUPS.
|
|
# No-op when: started with --user (euid != 0), FRIGATE_RUN_AS_ROOT=true,
|
|
# or PUID/PGID already match. FRIGATE_ROOT_SERVICES is validated here too.
|
|
|
|
set -o errexit -o nounset -o pipefail
|
|
|
|
if [[ "$(id -u)" -ne 0 ]]; then
|
|
# Started with docker --user; the host owns UID mapping entirely.
|
|
exit 0
|
|
fi
|
|
|
|
if [[ "${FRIGATE_RUN_AS_ROOT:-false}" == "true" ]]; then
|
|
if [[ -n "${FRIGATE_ROOT_SERVICES:-}" ]]; then
|
|
echo "[INFO] FRIGATE_RUN_AS_ROOT=true: ignoring FRIGATE_ROOT_SERVICES"
|
|
fi
|
|
echo "[INFO] FRIGATE_RUN_AS_ROOT=true: skipping user remapping"
|
|
exit 0
|
|
fi
|
|
|
|
# a typo must fail the boot, not silently drop a service to non-root
|
|
if [[ -n "${FRIGATE_ROOT_SERVICES:-}" ]]; then
|
|
IFS=',' read -ra root_services <<< "${FRIGATE_ROOT_SERVICES}"
|
|
for entry in "${root_services[@]}"; do
|
|
entry="${entry//[[:space:]]/}"
|
|
if [[ -z "$entry" ]]; then
|
|
continue
|
|
fi
|
|
case "$entry" in
|
|
frigate|go2rtc|nginx) ;;
|
|
*)
|
|
echo "[ERROR] FRIGATE_ROOT_SERVICES contains unknown service '${entry}'; valid names are frigate, go2rtc, nginx" >&2
|
|
exit 1
|
|
;;
|
|
esac
|
|
done
|
|
fi
|
|
|
|
puid="${PUID:-1000}"
|
|
pgid="${PGID:-1000}"
|
|
|
|
if ! [[ "$puid" =~ ^[0-9]+$ && "$pgid" =~ ^[0-9]+$ ]]; then
|
|
echo "[ERROR] PUID and PGID must be numeric, got '${puid}' and '${pgid}'" >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Remapping to 0 would make the frigate user root, so every service would keep
|
|
# full privilege while reporting a successful migration.
|
|
if [[ "$puid" -eq 0 || "$pgid" -eq 0 ]]; then
|
|
echo "[ERROR] PUID/PGID 0 would run the services as root and defeat the privilege separation." >&2
|
|
echo "[ERROR] Set FRIGATE_RUN_AS_ROOT=true if you want to keep running as root." >&2
|
|
exit 1
|
|
fi
|
|
|
|
# Colliding with the go2rtc ids would merge the two users and collapse the
|
|
# separation between the main process and the network-facing restreamer.
|
|
go2rtc_uid="$(id -u go2rtc)"
|
|
go2rtc_gid="$(id -g go2rtc)"
|
|
if [[ "$puid" -eq "$go2rtc_uid" || "$pgid" -eq "$go2rtc_gid" ]]; then
|
|
echo "[ERROR] PUID/PGID must not equal the go2rtc service ids (${go2rtc_uid}:${go2rtc_gid})." >&2
|
|
exit 1
|
|
fi
|
|
|
|
current_uid="$(id -u frigate)"
|
|
current_gid="$(id -g frigate)"
|
|
|
|
if [[ "$puid" != "$current_uid" || "$pgid" != "$current_gid" ]]; then
|
|
if [[ ! -w /etc/passwd ]]; then
|
|
echo "[ERROR] PUID/PGID remapping needs a writable /etc and is not compatible with read_only: true." >&2
|
|
echo "[ERROR] Either remove read_only and keep PUID, or drop PUID/PGID and use docker's user: ${puid}:${pgid} instead." >&2
|
|
echo "[ERROR] See https://docs.frigate.video/configuration/non_root for the compatibility matrix." >&2
|
|
exit 1
|
|
fi
|
|
echo "[INFO] Remapping frigate user to ${puid}:${pgid}"
|
|
groupmod -o -g "$pgid" frigate
|
|
usermod -o -u "$puid" frigate
|
|
fi
|
|
|
|
# EXTRA_GROUPS: numeric host GIDs granting device access (e.g. host render/video)
|
|
if [[ -n "${EXTRA_GROUPS:-}" ]]; then
|
|
for gid in ${EXTRA_GROUPS//,/ }; do
|
|
if ! [[ "$gid" =~ ^[0-9]+$ ]] || [[ "$gid" -eq 0 ]]; then
|
|
echo "[ERROR] EXTRA_GROUPS must be nonzero numeric GIDs, got '${gid}'" >&2
|
|
exit 1
|
|
fi
|
|
if ! getent group "$gid" >/dev/null; then
|
|
groupadd -o -g "$gid" "frigate-extra-${gid}"
|
|
fi
|
|
group_name="$(getent group "$gid" | cut -d: -f1)"
|
|
usermod -aG "$group_name" frigate
|
|
usermod -aG "$group_name" go2rtc
|
|
echo "[INFO] Added frigate and go2rtc to supplementary group ${group_name} (gid ${gid})"
|
|
done
|
|
fi
|