From 9a2a1060c822a26b8871a97f1d8fb4cac5e0b99b Mon Sep 17 00:00:00 2001 From: Harsh Shandilya Date: Sat, 17 Aug 2019 11:47:35 +0530 Subject: [PATCH] systemd_units: Strip out comments Signed-off-by: Harsh Shandilya --- systemd_units/caddy.service | 22 ---------------------- systemd_units/mirror-bot-2.service | 6 ------ systemd_units/mirror-bot.service | 6 ------ systemd_units/uno-bot.service | 6 ------ systemd_units/walls-bot-2.service | 6 ------ systemd_units/walls-bot.service | 6 ------ 6 files changed, 52 deletions(-) diff --git a/systemd_units/caddy.service b/systemd_units/caddy.service index 9e09f91..0415173 100644 --- a/systemd_units/caddy.service +++ b/systemd_units/caddy.service @@ -6,43 +6,21 @@ Wants=network-online.target systemd-networkd-wait-online.service [Service] Restart=on-abnormal - -; User and group the process will run as. User=caddy Group=caddy - -; Letsencrypt-issued certificates will be written to this directory. Environment=CADDYPATH=/etc/ssl/caddy - -; Always set "-root" to something safe in case it gets forgotten in the Caddyfile. ExecStart=/usr/local/bin/caddy -log stdout -agree=true -conf=/etc/caddy/Caddyfile -root=/var/tmp -envfile /etc/caddy/env ExecReload=/bin/kill -USR1 $MAINPID - -; Use graceful shutdown with a reasonable timeout KillMode=mixed KillSignal=SIGQUIT TimeoutStopSec=5s - -; Limit the number of file descriptors; see `man systemd.exec` for more limit settings. LimitNOFILE=1048576 -; Unmodified caddy is not expected to use more than that. LimitNPROC=512 - -; Use private /tmp and /var/tmp, which are discarded after caddy stops. PrivateTmp=true -; Use a minimal /dev (May bring additional security if switched to 'true', but it may not work on Raspberry Pi's or other devices, so it has been disabled in this dist.) PrivateDevices=true -; Hide /home, /root, and /run/user. Nobody will steal your SSH-keys. ProtectHome=true -; Make /usr, /boot, /etc and possibly some more folders read-only. ProtectSystem=full -; … except /etc/ssl/caddy, because we want Letsencrypt-certificates there. -; This merely retains r/w access rights, it does not add any new. Must still be writable on the host! ReadWriteDirectories=/etc/ssl/caddy - -; The following additional security directives only work with systemd v229 or later. -; They further restrict privileges that can be gained by caddy. Uncomment if you like. -; Note that you may have to add capabilities required by any plugins in use. CapabilityBoundingSet=CAP_NET_BIND_SERVICE AmbientCapabilities=CAP_NET_BIND_SERVICE NoNewPrivileges=true diff --git a/systemd_units/mirror-bot-2.service b/systemd_units/mirror-bot-2.service index 9741da3..ce6b078 100644 --- a/systemd_units/mirror-bot-2.service +++ b/systemd_units/mirror-bot-2.service @@ -10,17 +10,11 @@ WorkingDirectory=/home/bot/aria-telegram-mirror-bot-2 ExecStartPre=/usr/bin/env bash aria.sh ExecStart=/usr/bin/npm start ExecReload=/bin/kill -USR1 $MAINPID - -; Use graceful shutdown with a reasonable timeout KillMode=mixed KillSignal=SIGQUIT TimeoutStopSec=5s - -; Use private /tmp and /var/tmp, which are discarded after the process stops. PrivateTmp=true -; Use a minimal /dev (May bring additional security if switched to 'true', but it may not work on Raspberry Pi's or other devices, so it has been disabled in this dist.) PrivateDevices=true -; Make /usr, /boot, /etc and possibly some more folders read-only. ProtectSystem=full [Install] diff --git a/systemd_units/mirror-bot.service b/systemd_units/mirror-bot.service index b5f1bec..f28c807 100644 --- a/systemd_units/mirror-bot.service +++ b/systemd_units/mirror-bot.service @@ -10,17 +10,11 @@ WorkingDirectory=/home/bot/aria-telegram-mirror-bot ExecStartPre=/usr/bin/env bash aria.sh ExecStart=/usr/bin/npm start ExecReload=/bin/kill -USR1 $MAINPID - -; Use graceful shutdown with a reasonable timeout KillMode=mixed KillSignal=SIGQUIT TimeoutStopSec=5s - -; Use private /tmp and /var/tmp, which are discarded after the process stops. PrivateTmp=true -; Use a minimal /dev (May bring additional security if switched to 'true', but it may not work on Raspberry Pi's or other devices, so it has been disabled in this dist.) PrivateDevices=true -; Make /usr, /boot, /etc and possibly some more folders read-only. ProtectSystem=full [Install] diff --git a/systemd_units/uno-bot.service b/systemd_units/uno-bot.service index d255822..7a57c9c 100644 --- a/systemd_units/uno-bot.service +++ b/systemd_units/uno-bot.service @@ -9,17 +9,11 @@ User=bot WorkingDirectory=/home/bot/mau_mau_bot ExecStart=/home/bot/mau_mau_bot/venv/bin/python bot.py ExecReload=/bin/kill -USR1 $MAINPID - -; Use graceful shutdown with a reasonable timeout KillMode=mixed KillSignal=SIGQUIT TimeoutStopSec=5s - -; Use private /tmp and /var/tmp, which are discarded after the process stops. PrivateTmp=true -; Use a minimal /dev (May bring additional security if switched to 'true', but it may not work on Raspberry Pi's or other devices, so it has been disabled in this dist.) PrivateDevices=false -; Make /usr, /boot, /etc and possibly some more folders read-only. ProtectSystem=full [Install] diff --git a/systemd_units/walls-bot-2.service b/systemd_units/walls-bot-2.service index fe85c49..57fbfe0 100644 --- a/systemd_units/walls-bot-2.service +++ b/systemd_units/walls-bot-2.service @@ -9,17 +9,11 @@ User=bot WorkingDirectory=/home/bot/walls-bot-2 ExecStart=/home/bot/walls-bot/gradlew run ExecReload=/bin/kill -USR1 $MAINPID - -; Use graceful shutdown with a reasonable timeout KillMode=mixed KillSignal=SIGQUIT TimeoutStopSec=5s - -; Use private /tmp and /var/tmp, which are discarded after the process stops. PrivateTmp=true -; Use a minimal /dev (May bring additional security if switched to 'true', but it may not work on Raspberry Pi's or other devices, so it has been disabled in this dist.) PrivateDevices=false -; Make /usr, /boot, /etc and possibly some more folders read-only. ProtectSystem=full [Install] diff --git a/systemd_units/walls-bot.service b/systemd_units/walls-bot.service index 3427bea..72f144b 100644 --- a/systemd_units/walls-bot.service +++ b/systemd_units/walls-bot.service @@ -9,17 +9,11 @@ User=bot WorkingDirectory=/home/bot/walls-bot ExecStart=/home/bot/walls-bot/gradlew run ExecReload=/bin/kill -USR1 $MAINPID - -; Use graceful shutdown with a reasonable timeout KillMode=mixed KillSignal=SIGQUIT TimeoutStopSec=5s - -; Use private /tmp and /var/tmp, which are discarded after the process stops. PrivateTmp=true -; Use a minimal /dev (May bring additional security if switched to 'true', but it may not work on Raspberry Pi's or other devices, so it has been disabled in this dist.) PrivateDevices=false -; Make /usr, /boot, /etc and possibly some more folders read-only. ProtectSystem=full [Install]