36 lines
1.3 KiB
Desktop File
36 lines
1.3 KiB
Desktop File
[Unit]
|
|
Description=TallyNote privileged release updater
|
|
[Service]
|
|
Type=oneshot
|
|
User=root
|
|
Group=root
|
|
WorkingDirectory=/opt/tallynote/current
|
|
EnvironmentFile=-/etc/tallynote/tallynote.env
|
|
Environment=TALLYNOTE_CONFIG_DIR=/etc/tallynote
|
|
ExecStart=/usr/local/libexec/tallynote-update-runner
|
|
Environment=PATH=/usr/local/bin:/usr/bin:/usr/sbin:/sbin:/bin
|
|
# The runner consumes queued requests immediately and applies its own bounded
|
|
# phase timeouts while keeping full CLI diagnostics in the runner log.
|
|
# Archive validation and data backups can exceed systemd's 90s
|
|
# default start timeout on a slower server. Keep one update job alive long
|
|
# enough to finish or reach its own health-check/recovery path.
|
|
TimeoutStartSec=5min
|
|
NoNewPrivileges=true
|
|
# Keep the updater compatible with the same Node/libuv interface discovery
|
|
# path while retaining an explicit socket-family allowlist.
|
|
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
|
|
PrivateTmp=true
|
|
PrivateDevices=true
|
|
ProtectHome=true
|
|
ProtectSystem=strict
|
|
ProtectKernelTunables=true
|
|
ProtectKernelModules=true
|
|
ProtectKernelLogs=true
|
|
ProtectClock=true
|
|
LockPersonality=true
|
|
RestrictRealtime=true
|
|
RestrictSUIDSGID=true
|
|
SystemCallArchitectures=native
|
|
UMask=0077
|
|
ReadWritePaths=/opt/tallynote /var/lib/tallynote /var/lib/tallynote-backups
|