Files

43 lines
963 B
Desktop File

[Unit]
Description=Standalone DWH API-key verifier
After=local-fs.target
Wants=local-fs.target
[Service]
Type=simple
User=dwh-auth
Group=www-data
SupplementaryGroups=dwh-auth
ExecStart=/usr/local/sbin/dwh-auth serve --registry-root /var/lib/dwh-auth --socket /run/dwh-auth/verify.sock
Restart=on-failure
RestartSec=2s
RuntimeDirectory=dwh-auth
RuntimeDirectoryMode=0750
UMask=0007
NoNewPrivileges=true
PrivateTmp=true
PrivateDevices=true
ProtectSystem=strict
ProtectHome=true
ProtectClock=true
ProtectControlGroups=true
ProtectHostname=true
ProtectKernelLogs=true
ProtectKernelModules=true
ProtectKernelTunables=true
ProtectProc=invisible
ReadOnlyPaths=/var/lib/dwh-auth
ReadWritePaths=/run/dwh-auth
RestrictAddressFamilies=AF_UNIX
RestrictNamespaces=true
RestrictRealtime=true
RestrictSUIDSGID=true
LockPersonality=true
MemoryDenyWriteExecute=true
SystemCallArchitectures=native
CapabilityBoundingSet=
AmbientCapabilities=
[Install]
WantedBy=multi-user.target