build: package standalone DWH authentication service
This commit is contained in:
@@ -0,0 +1,42 @@
|
||||
[Unit]
|
||||
Description=Standalone DWH API-key verifier
|
||||
After=local-fs.target
|
||||
Wants=local-fs.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=dwh-auth
|
||||
Group=www-data
|
||||
SupplementaryGroups=dwh-auth
|
||||
ExecStart=/usr/local/sbin/dwh-auth serve --registry-root /var/lib/dwh-auth --socket /run/dwh-auth/verify.sock
|
||||
Restart=on-failure
|
||||
RestartSec=2s
|
||||
RuntimeDirectory=dwh-auth
|
||||
RuntimeDirectoryMode=0750
|
||||
UMask=0007
|
||||
NoNewPrivileges=true
|
||||
PrivateTmp=true
|
||||
PrivateDevices=true
|
||||
ProtectSystem=strict
|
||||
ProtectHome=true
|
||||
ProtectClock=true
|
||||
ProtectControlGroups=true
|
||||
ProtectHostname=true
|
||||
ProtectKernelLogs=true
|
||||
ProtectKernelModules=true
|
||||
ProtectKernelTunables=true
|
||||
ProtectProc=invisible
|
||||
ReadOnlyPaths=/var/lib/dwh-auth
|
||||
ReadWritePaths=/run/dwh-auth
|
||||
RestrictAddressFamilies=AF_UNIX
|
||||
RestrictNamespaces=true
|
||||
RestrictRealtime=true
|
||||
RestrictSUIDSGID=true
|
||||
LockPersonality=true
|
||||
MemoryDenyWriteExecute=true
|
||||
SystemCallArchitectures=native
|
||||
CapabilityBoundingSet=
|
||||
AmbientCapabilities=
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in New Issue
Block a user