This commit is contained in:
@@ -4,6 +4,15 @@ Description=Watch for TallyNote release update requests
|
||||
[Path]
|
||||
PathExists=/var/lib/tallynote/update-request.json
|
||||
PathChanged=/var/lib/tallynote/update-request.json
|
||||
# The recovery marker lives beside the release link. Watching it as well
|
||||
# allows systemd to resume reconciliation when the runner is interrupted
|
||||
# after consuming the request but before clearing its state file.
|
||||
PathExists=/opt/tallynote/.update-state
|
||||
PathChanged=/opt/tallynote/.update-state
|
||||
# Keep a directory-level fallback because some systemd/inotify versions skip
|
||||
# dotfiles when watching an individual path. State writes are atomic renames,
|
||||
# so the containing directory changes even when the marker itself is hidden.
|
||||
PathChanged=/opt/tallynote
|
||||
Unit=tallynote-update.service
|
||||
|
||||
[Install]
|
||||
|
||||
@@ -2,7 +2,6 @@
|
||||
Description=TallyNote privileged release updater
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
ConditionPathExists=/var/lib/tallynote/update-request.json
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
@@ -12,6 +11,10 @@ WorkingDirectory=/opt/tallynote/current
|
||||
EnvironmentFile=-/etc/tallynote/tallynote.env
|
||||
ExecStart=/usr/local/libexec/tallynote-update-runner
|
||||
Environment=PATH=/usr/sbin:/usr/bin:/sbin:/bin
|
||||
# Downloads, archive validation and data backups can exceed systemd's 90s
|
||||
# default start timeout on a slower server. Keep one update job alive long
|
||||
# enough to finish or reach its own health-check/recovery path.
|
||||
TimeoutStartSec=30min
|
||||
NoNewPrivileges=true
|
||||
CapabilityBoundingSet=
|
||||
AmbientCapabilities=
|
||||
|
||||
@@ -14,6 +14,8 @@ Environment=PATH=/opt/tallynote/current/runtime/bin:/usr/sbin:/usr/bin:/sbin:/bi
|
||||
ExecStart=/opt/tallynote/current/bin/tallynote
|
||||
Restart=on-failure
|
||||
RestartSec=5s
|
||||
# Do not let a wedged Node process hold an update stop forever.
|
||||
TimeoutStopSec=30s
|
||||
NoNewPrivileges=true
|
||||
PrivateTmp=true
|
||||
ProtectSystem=strict
|
||||
|
||||
Reference in New Issue
Block a user