From b453b6ed6cfea9b0a2f3df740be00ee06a8f362c Mon Sep 17 00:00:00 2001 From: Martin Weinelt Date: Sun, 19 Jul 2026 16:22:08 +0200 Subject: [PATCH] nixos/frigate: harden runtime execution environment --- nixos/modules/services/video/frigate.nix | 44 ++++++++++++++++++++++++ nixos/tests/frigate.nix | 2 ++ 2 files changed, 46 insertions(+) diff --git a/nixos/modules/services/video/frigate.nix b/nixos/modules/services/video/frigate.nix index c358f0cd63b2..6ee20f7cf582 100644 --- a/nixos/modules/services/video/frigate.nix +++ b/nixos/modules/services/video/frigate.nix @@ -792,9 +792,53 @@ in # Sockets/IPC RuntimeDirectory = "frigate"; + RemoveIPC = true; # Reduce visible process scope to cgroup ProtectProc = "invisible"; + + # Allow wide /proc inspection, e.g. for cpuinfo + ProcSubset = "all"; + + # Protect various system locations/interfaces + ProtectControlGroups = true; + ProtectHome = true; + ProtectHostname = true; + ProtectKernelLogs = true; + ProtectKernelModules = true; + ProtectKernelTunables = true; + ProtectSystem = "strict"; + + # No JIT compilation + MemoryDenyWriteExecute = true; + + # No ABI personality changes + LockPersonality = true; + + # Only IP/Unix sockets + RestrictAddressFamilies = [ + "AF_INET" + "AF_INET6" + "AF_UNIX" + ]; + + # Deny namespace creation + RestrictNamespaces = true; + + # No privilege escalation + NoNewPrivileges = true; + RestrictSUIDSGID = true; + + # No realtime schedulign + RestrictRealtime = true; + + # Restrict allowed syscalls + SystemCallFilter = [ + "@system-service" + "~@privileged" + ]; + SystemCallArchitectures = "native"; + SystemCallErrorNumber = "EPERM"; }; }; diff --git a/nixos/tests/frigate.nix b/nixos/tests/frigate.nix index 10712387f421..ca6fc5a5c621 100644 --- a/nixos/tests/frigate.nix +++ b/nixos/tests/frigate.nix @@ -77,5 +77,7 @@ # wait for a recording to appear machine.wait_for_file("/var/cache/frigate/test@*.mp4") + + machine.log(machine.execute("systemd-analyze security frigate.service | grep -v ✓")[1]) ''; }