39 lines
1.2 KiB
Desktop File
39 lines
1.2 KiB
Desktop File
[Unit]
|
|
Description=TallyNote privileged release updater
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
User=root
|
|
Group=root
|
|
WorkingDirectory=/opt/tallynote/current
|
|
EnvironmentFile=-/etc/tallynote/tallynote.env
|
|
ExecStart=/usr/local/libexec/tallynote-update-runner
|
|
Environment=PATH=/usr/sbin:/usr/bin:/sbin:/bin
|
|
# Downloads, archive validation and data backups can exceed systemd's 90s
|
|
# default start timeout on a slower server. Keep one update job alive long
|
|
# enough to finish or reach its own health-check/recovery path.
|
|
TimeoutStartSec=30min
|
|
NoNewPrivileges=true
|
|
CapabilityBoundingSet=
|
|
AmbientCapabilities=
|
|
# Keep the updater compatible with the same Node/libuv interface discovery
|
|
# path while retaining an explicit socket-family allowlist.
|
|
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
|
|
PrivateTmp=true
|
|
PrivateDevices=true
|
|
ProtectHome=true
|
|
ProtectSystem=strict
|
|
ProtectKernelTunables=true
|
|
ProtectKernelModules=true
|
|
ProtectKernelLogs=true
|
|
ProtectControlGroups=true
|
|
ProtectClock=true
|
|
LockPersonality=true
|
|
RestrictRealtime=true
|
|
RestrictSUIDSGID=true
|
|
SystemCallArchitectures=native
|
|
UMask=0077
|
|
ReadWritePaths=/opt/tallynote /var/lib/tallynote /var/lib/tallynote-backups
|