09 Run & deploy
Cross-User Execution (--for)
In this chapter
The --for flag lets a privileged operator run BrowserBox commands on behalf of an unprivileged runtime user. This is the recommended deployment pattern for multi-tenant or security-hardened environments where the runtime user should have no sudo capability.
9.1 Requirements #
The operator must have passwordless
sudo(sudo -n).The target user must already exist and must not have
sudo.Linux only — macOS does not support
--for.
9.2 Supported commands #
bbx setup --for <user> [setup-options]
bbx run --for <user>
bbx ng-run --for <user>
bbx stop --for <user>
bbx status --for <user>
bbx policy <subcommand> --for <user>start/run and ng-start/ng-run are equivalent spellings. Both --for <user> and --for=<user> syntax are accepted.
9.3 What happens #
Operator-level tasks (TLS certificate generation, nginx configuration, host file entries, port binding) run as the operator via
sudo.Runtime tasks (BrowserBox services, license certification, browser process) run as the target user via
sudo -u <user>.SSL certificates generated during setup are automatically
chowned to the target user so that the Node.js runtime can read them.Configuration is stored under the target user’s home directory ().
9.4 Example workflow #
# As the operator (e.g. bbxadmin, with sudo):
bbx setup --port 9090 --hostname app.example.com -z --for bbxruntime
bbx ng-run --for bbxruntime
# Later:
bbx status --for bbxruntime
bbx stop --for bbxruntimeAll BrowserBox processes will run as bbxruntime. The operator never needs to su or log in as the runtime user.
9.5 Combining with certificate override #
--for respects BBX_SSLCERTS_DIR when set explicitly:
export BBX_SSLCERTS_DIR="/opt/shared-certs"
bbx ng-run --for bbxruntimeIf BBX_SSLCERTS_DIR is not set, certificates are generated into the target user’s default location (~/<user>/sslcerts/).