mailinglist.rb/deploy/mailinglistrb.service

36 lines
820 B
SYSTEMD

[Unit]
Description=Mailinglist.rb
Documentation=https://git.sceptique.eu/Sceptique/mailinglist.rb
[Service]
ExecStart=/opt/mailinglistrb/bin/distributor
Restart=on-failure
RestartSec=3
User=mailinglistrb
Group=mailinglistrb
WorkingDirectory=/opt/mailinglistrb
Environment=/usr/local/sbin:/usr/local/bin:/usr/bin:/usr/bin/site_perl:/usr/bin/vendor_perl:/usr/bin/core_perl
SystemCallArchitectures=native
CapabilityBoundingSet=
NoNewPrivileges=true
PrivateDevices=true
RemoveIPC=true
LockPersonality=true
ProtectControlGroups=true
ProtectKernelTunables=true
ProtectKernelModules=true
ProtectKernelLogs=true
ProtectClock=true
ProtectHostname=true
ProtectProc=noaccess
RestrictRealtime=true
RestrictSUIDSGID=true
RestrictNamespaces=true
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
[Install]
WantedBy=default.target