deploy/gitbay-runner-egress.service

3bcdce33fb9a2309312854331359d376171c7368
gitbay/deploy/gitbay-runner-egress.service history · blame · raw

29 lines · 1164 bytes

 1# Loads the CI runner's host egress rule (#260,
 2# deploy/gitbay-runner-egress.nft). gitbay-runner.service requires this
 3# unit, so the runner starts only with the rule in force; stopping this
 4# unit removes the table and stops the runner with it.
 5#
 6# Ordered after nftables.service and ufw.service: either may rewrite the
 7# ruleset at boot, and nftables.service's default config starts with
 8# flush ruleset. A missing unit in After= is ignored.
 9#
10# Reload re-reads the file and replaces the table in one transaction; it
11# does not restart the runner, which a restart of this unit would
12# (Requires= propagates restarts). `make deploy-runner` reloads.
13#
14# Stop uses destroy, which succeeds when the table is already gone (a
15# flush ruleset removes it); delete would fail and leave the unit failed.
16[Unit]
17Description=Host egress rule for CI builds
18After=nftables.service ufw.service
19Before=gitbay-runner.service
20
21[Service]
22Type=oneshot
23RemainAfterExit=yes
24ExecStart=/usr/sbin/nft -f /etc/gitbay-runner/egress.nft
25ExecReload=/usr/sbin/nft -f /etc/gitbay-runner/egress.nft
26ExecStop=/usr/sbin/nft destroy table inet gitbay_runner
27
28[Install]
29WantedBy=multi-user.target