nixos/frigate: harden runtime execution environment

This commit is contained in:
Martin Weinelt
2026-07-19 16:22:08 +02:00
parent aa1b83e8ea
commit b453b6ed6c
2 changed files with 46 additions and 0 deletions

View File

@@ -792,9 +792,53 @@ in
# Sockets/IPC
RuntimeDirectory = "frigate";
RemoveIPC = true;
# Reduce visible process scope to cgroup
ProtectProc = "invisible";
# Allow wide /proc inspection, e.g. for cpuinfo
ProcSubset = "all";
# Protect various system locations/interfaces
ProtectControlGroups = true;
ProtectHome = true;
ProtectHostname = true;
ProtectKernelLogs = true;
ProtectKernelModules = true;
ProtectKernelTunables = true;
ProtectSystem = "strict";
# No JIT compilation
MemoryDenyWriteExecute = true;
# No ABI personality changes
LockPersonality = true;
# Only IP/Unix sockets
RestrictAddressFamilies = [
"AF_INET"
"AF_INET6"
"AF_UNIX"
];
# Deny namespace creation
RestrictNamespaces = true;
# No privilege escalation
NoNewPrivileges = true;
RestrictSUIDSGID = true;
# No realtime schedulign
RestrictRealtime = true;
# Restrict allowed syscalls
SystemCallFilter = [
"@system-service"
"~@privileged"
];
SystemCallArchitectures = "native";
SystemCallErrorNumber = "EPERM";
};
};

View File

@@ -77,5 +77,7 @@
# wait for a recording to appear
machine.wait_for_file("/var/cache/frigate/test@*.mp4")
machine.log(machine.execute("systemd-analyze security frigate.service | grep -v ✓")[1])
'';
}