systemd: simplify walls-bot-rs service
This commit is contained in:
parent
781320644a
commit
3892a47658
|
@ -10,22 +10,17 @@ WorkingDirectory=/home/bot
|
|||
EnvironmentFile=/home/bot/walls-bot.config
|
||||
ExecStart=/usr/bin/walls-bot-rs
|
||||
ExecReload=/bin/kill -USR1 $MAINPID
|
||||
ReadOnlyDirectories=/var/www/dl.msfjarvis.dev/.walls
|
||||
KillMode=mixed
|
||||
KillSignal=SIGQUIT
|
||||
TimeoutStopSec=5s
|
||||
KillSignal=SIGINT
|
||||
TimeoutStopSec=10s
|
||||
|
||||
# Security
|
||||
PrivateTmp=true
|
||||
ProtectSystem=full
|
||||
NoNewPrivileges=true
|
||||
ProtectControlGroups=true
|
||||
ProtectKernelModules=true
|
||||
ProtectKernelTunables=true
|
||||
PrivateDevices=true
|
||||
RestrictAddressFamilies=AF_INET AF_INET6
|
||||
RestrictNamespaces=true
|
||||
RestrictRealtime=true
|
||||
SystemCallArchitectures=native
|
||||
|
||||
[Install]
|
||||
|
|
Loading…
Reference in New Issue