services/skunkyart.example.service

v1.5.2
skunky-art/services/skunkyart.example.service history · blame · raw

38 lines · 1143 bytes · executable

 1# systemd unit for SkunkyArt. Install the binary and its static/ directory
 2# (or a binary built with -tags embed) under /opt/skunkyart, put config.json
 3# beside it, then:
 4#
 5#   cp services/skunkyart.example.service /etc/systemd/system/skunkyart.service
 6#   systemctl daemon-reload
 7#   systemctl enable --now skunkyart
 8#
 9# DynamicUser gives the service a throwaway account with no home and no
10# shell; StateDirectory is the one writable place it gets, mounted at
11# /var/lib/skunkyart, which is where the media cache goes.
12
13[Unit]
14Description=SkunkyArt, an alternative frontend for DeviantArt
15After=network-online.target
16Wants=network-online.target
17
18[Service]
19WorkingDirectory=/opt/skunkyart
20ExecStart=/opt/skunkyart/skunkyart -c /opt/skunkyart/config.json
21Restart=on-failure
22RestartSec=5s
23
24DynamicUser=yes
25StateDirectory=skunkyart
26# Point "cache": {"path": "/var/lib/skunkyart"} at the state directory.
27ProtectSystem=strict
28ProtectHome=yes
29PrivateTmp=yes
30NoNewPrivileges=yes
31PrivateDevices=yes
32ProtectKernelTunables=yes
33ProtectControlGroups=yes
34RestrictAddressFamilies=AF_INET AF_INET6
35LockPersonality=yes
36
37[Install]
38WantedBy=multi-user.target