Files
TallyNote/systemd/tallynote-update.service
T
2026-09-11 18:28:03 +08:00

36 lines
1.3 KiB
Desktop File

[Unit]
Description=TallyNote privileged release updater
[Service]
Type=oneshot
User=root
Group=root
WorkingDirectory=/opt/tallynote/current
EnvironmentFile=-/etc/tallynote/tallynote.env
Environment=TALLYNOTE_CONFIG_DIR=/etc/tallynote
ExecStart=/usr/local/libexec/tallynote-update-runner
Environment=PATH=/usr/local/bin:/usr/bin:/usr/sbin:/sbin:/bin
# The runner consumes queued requests immediately and applies its own bounded
# phase timeouts while keeping full CLI diagnostics in the runner log.
# Archive validation and data backups can exceed systemd's 90s
# default start timeout on a slower server. Keep one update job alive long
# enough to finish or reach its own health-check/recovery path.
TimeoutStartSec=5min
NoNewPrivileges=true
# Keep the updater compatible with the same Node/libuv interface discovery
# path while retaining an explicit socket-family allowlist.
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
PrivateTmp=true
PrivateDevices=true
ProtectHome=true
ProtectSystem=strict
ProtectKernelTunables=true
ProtectKernelModules=true
ProtectKernelLogs=true
ProtectClock=true
LockPersonality=true
RestrictRealtime=true
RestrictSUIDSGID=true
SystemCallArchitectures=native
UMask=0077
ReadWritePaths=/opt/tallynote /var/lib/tallynote /var/lib/tallynote-backups