关于Snap以非root用户运行服务及Gitea配置方法的咨询
Hey there! I've dealt with this exact scenario before when setting up Gitea via Snap, so let me walk you through the steps to get it running as a non-root user:
Create a dedicated system user for Gitea
First, we'll make a locked-down system user that Gitea can run under. This user won't have a login shell, which is more secure:sudo adduser --system --group --disabled-login --home /var/snap/gitea/common giteaThe home directory points to Snap's Gitea common folder, where all your Gitea data lives.
Fix directory permissions
The existing Gitea data folder is owned by root right now, so we need to transfer ownership to our new user:sudo chown -R gitea:gitea /var/snap/gitea/commonOverride the systemd service to run as non-root
Snap manages Gitea via a systemd service, but we can safely modify it without breaking future Snap updates using an override file. Run this command to open the override editor:sudo systemctl edit snap.gitea.gitea.servicePaste these lines into the editor, save, and exit:
[Service] User=gitea Group=giteaUpdate Gitea's internal config
Open Gitea's app.ini file to make sure it knows to use our new user:sudo nano /var/snap/gitea/common/conf/app.iniFind the
RUN_USERline (usually under the[server]section) and set it to:RUN_USER = giteaSave and exit the editor.
Handle low port access (if needed)
If you're using ports below 1024 (like 80 or 443) for Gitea, non-root users can't bind these by default. Fix this by adding the necessary capability to the Gitea binary:sudo setcap 'cap_net_bind_service=+ep' /snap/gitea/current/giteaRestart the service and verify
Finally, restart Gitea to apply all changes:sudo systemctl restart snap.gitea.gitea.serviceCheck that it's running as the
giteauser with this command:ps aux | grep giteaYou should see the gitea process listed under the
giteauser instead of root.
备注:内容来源于stack exchange,提问作者chrisyue

