[Unit] Description=TallyNote privileged release updater After=network-online.target Wants=network-online.target [Service] Type=oneshot User=root Group=root WorkingDirectory=/opt/tallynote/current EnvironmentFile=-/etc/tallynote/tallynote.env ExecStart=/usr/local/libexec/tallynote-update-runner Environment=PATH=/usr/sbin:/usr/bin:/sbin:/bin # Downloads, archive validation and data backups can exceed systemd's 90s # default start timeout on a slower server. Keep one update job alive long # enough to finish or reach its own health-check/recovery path. TimeoutStartSec=30min NoNewPrivileges=true # Keep the updater compatible with the same Node/libuv interface discovery # path while retaining an explicit socket-family allowlist. RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK PrivateTmp=true PrivateDevices=true ProtectHome=true ProtectSystem=strict ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectClock=true LockPersonality=true RestrictRealtime=true RestrictSUIDSGID=true SystemCallArchitectures=native UMask=0077 ReadWritePaths=/opt/tallynote /var/lib/tallynote /var/lib/tallynote-backups