I've opened them an issue just in case https://github.com/bunkerity/bunkerized-nginx/issues/11
A web server need root privileges in order to bind ports 80/443.
But in this case it’s only the primary Nginx process that will run as root. The subprocesses will run as a non-privileged user, as specified with the “user nginx” directive.
https://github.com/bunkerity/bunkerized-nginx/blob/master/co...
https://unix.stackexchange.com/questions/134301/why-does-ngi...
Starting as root for the sole purpose of binding to a low-numbered port and then dropping privileges is an outdated practice that is both difficult to program correctly and arguably unnecessary today.
[1] https://www.archlinux.org/packages/extra/x86_64/nginx/
[2] https://github.com/archlinux/svntogit-packages/blob/packages...
A quick googling tells me that FreeBSD has something similar: https://gist.github.com/TomHetmer/b0a048d688af78e78f45609880...
PS. If I would have bothered to read the whole Stack Exchange article I linked to, that capability is even mentioned there (^_^) https://unix.stackexchange.com/a/134324/68449