diff options
Diffstat (limited to 'metamuffin-website-git/metamuffin-website.service')
-rw-r--r-- | metamuffin-website-git/metamuffin-website.service | 33 |
1 files changed, 33 insertions, 0 deletions
diff --git a/metamuffin-website-git/metamuffin-website.service b/metamuffin-website-git/metamuffin-website.service new file mode 100644 index 0000000..4195d98 --- /dev/null +++ b/metamuffin-website-git/metamuffin-website.service @@ -0,0 +1,33 @@ +[Unit] +Description=metamuffin personal website +After=network.target +Wants=network-online.target + +[Service] +WorkingDirectory=/usr/share/metamuffin-website +ExecStart=/usr/bin/metamuffin-website +User=metamuffin_website +LockPersonality=yes +MemoryDenyWriteExecute=yes +NoNewPrivileges=yes +PrivateDevices=true +PrivateTmp=true +ProtectClock=yes +ProtectControlGroups=yes +ProtectHome=true +ProtectHostname=yes +ProtectKernelLogs=yes +ProtectKernelModules=yes +ProtectKernelTunables=yes +ProtectSystem=full +RestrictAddressFamilies=~AF_PACKET AF_NETLINK +RestrictNamespaces=yes +RestrictSUIDSGID=yes +RestrictRealtime=yes +Restart=always +SystemCallArchitectures=native +SystemCallFilter=@system-service +Type=simple + +[Install] +WantedBy=multi-user.target |