If nginx does not run as root, how can it read other files than the ones explicitly assigned to the nginx user?
If nginx does not run as root, how can it read other files than the ones explicitly assigned to the nginx user?
It's LITERALLY app hosting 101 and people did it that way 20+ years ago.
It may require more fiddling with group memberships, but it's well worth it.
Probably really screwing things up. Ouch.
Unfortunately, nginx (and other web servers) generally need to run as root in normal web applications because they are listening on port 80 or 443. Ports below 1024 can be opened only by root.
A more detailed explanation can be found here: https://unix.stackexchange.com/questions/134301/why-does-ngi...
/bin/sh -c set -x && groupadd --system --gid 101 nginx && useradd --system --gid nginx --no-create-home --home /nonexistent --comment "nginx user" --shell /bin/false --uid 101 nginx .....
[1] https://hub.docker.com/layers/library/nginx/latest/images/sh...
Or processes running with the CAP_NET_BIND_SERVICE capability! [1]
Capabilities are a Linux kernel feature. Granting CAP_NET_BIND_SERVICE to nginx means you do not need to start it with full root privileges. This capability gives it the ability to open ports below 1024
Using systemd, you can use this feature like this:
[Service]
ExecStart=/usr/bin/nginx -c /etc/my_nginx.conf
AmbientCapabilities=CAP_NET_BIND_SERVICE
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
User=nginx
Group=nginx
(You probably also want to enable a ton of other sandboxing options, see `systemd-analyze security` for tips)[1]: https://man7.org/linux/man-pages/man7/capabilities.7.html