mirror of
https://github.com/NixOS/nixpkgs.git
synced 2026-09-30 03:39:59 +00:00
nixos/frigate: harden runtime execution environment
This commit is contained in:
@@ -792,9 +792,53 @@ in
|
||||
|
||||
# Sockets/IPC
|
||||
RuntimeDirectory = "frigate";
|
||||
RemoveIPC = true;
|
||||
|
||||
# Reduce visible process scope to cgroup
|
||||
ProtectProc = "invisible";
|
||||
|
||||
# Allow wide /proc inspection, e.g. for cpuinfo
|
||||
ProcSubset = "all";
|
||||
|
||||
# Protect various system locations/interfaces
|
||||
ProtectControlGroups = true;
|
||||
ProtectHome = true;
|
||||
ProtectHostname = true;
|
||||
ProtectKernelLogs = true;
|
||||
ProtectKernelModules = true;
|
||||
ProtectKernelTunables = true;
|
||||
ProtectSystem = "strict";
|
||||
|
||||
# No JIT compilation
|
||||
MemoryDenyWriteExecute = true;
|
||||
|
||||
# No ABI personality changes
|
||||
LockPersonality = true;
|
||||
|
||||
# Only IP/Unix sockets
|
||||
RestrictAddressFamilies = [
|
||||
"AF_INET"
|
||||
"AF_INET6"
|
||||
"AF_UNIX"
|
||||
];
|
||||
|
||||
# Deny namespace creation
|
||||
RestrictNamespaces = true;
|
||||
|
||||
# No privilege escalation
|
||||
NoNewPrivileges = true;
|
||||
RestrictSUIDSGID = true;
|
||||
|
||||
# No realtime schedulign
|
||||
RestrictRealtime = true;
|
||||
|
||||
# Restrict allowed syscalls
|
||||
SystemCallFilter = [
|
||||
"@system-service"
|
||||
"~@privileged"
|
||||
];
|
||||
SystemCallArchitectures = "native";
|
||||
SystemCallErrorNumber = "EPERM";
|
||||
};
|
||||
};
|
||||
|
||||
|
||||
@@ -77,5 +77,7 @@
|
||||
|
||||
# wait for a recording to appear
|
||||
machine.wait_for_file("/var/cache/frigate/test@*.mp4")
|
||||
|
||||
machine.log(machine.execute("systemd-analyze security frigate.service | grep -v ✓")[1])
|
||||
'';
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user