[Unit] Description=TallyNote privileged release updater [Service] Type=oneshot User=root Group=root WorkingDirectory=/opt/tallynote/current EnvironmentFile=-/etc/tallynote/tallynote.env Environment=TALLYNOTE_CONFIG_DIR=/etc/tallynote ExecStart=/usr/local/libexec/tallynote-update-runner Environment=PATH=/usr/local/bin:/usr/bin:/usr/sbin:/sbin:/bin # The runner consumes queued requests immediately and applies its own bounded # phase timeouts while keeping full CLI diagnostics in the runner log. # Archive validation and data backups can exceed systemd's 90s # default start timeout on a slower server. Keep one update job alive long # enough to finish or reach its own health-check/recovery path. TimeoutStartSec=5min NoNewPrivileges=true # Keep the updater compatible with the same Node/libuv interface discovery # path while retaining an explicit socket-family allowlist. RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK PrivateTmp=true PrivateDevices=true ProtectHome=true ProtectSystem=strict ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectClock=true LockPersonality=true RestrictRealtime=true RestrictSUIDSGID=true SystemCallArchitectures=native UMask=0077 ReadWritePaths=/opt/tallynote /var/lib/tallynote /var/lib/tallynote-backups