| 1 | # /etc/systemd/system/snowbound-site.service: snowbound.paperclover.net, the hosted web build |
| 2 | # and the codes' pages, behind a TLS proxy on this machine (README.md). Options go on |
| 3 | # ExecStart, or as SNOWBOUND_SITE_* in Environment. |
| 4 | [Unit] |
| 5 | Description=Snowbound web build and Live Share links |
| 6 | After=network-online.target |
| 7 | Wants=network-online.target |
| 8 | |
| 9 | [Service] |
| 10 | ExecStart=/usr/local/bin/snowbound-site --listen 127.0.0.1:23593 --root /srv/snowbound/web --crashes /var/lib/snowbound-site --trust-forwarded true |
| 11 | StateDirectory=snowbound-site |
| 12 | Restart=always |
| 13 | RestartSec=2 |
| 14 | DynamicUser=yes |
| 15 | TasksMax=200 |
| 16 | MemoryMax=256M |
| 17 | NoNewPrivileges=yes |
| 18 | ProtectSystem=strict |
| 19 | ReadOnlyPaths=/srv/snowbound/web |
| 20 | ProtectHome=yes |
| 21 | PrivateTmp=yes |
| 22 | PrivateDevices=yes |
| 23 | ProtectKernelTunables=yes |
| 24 | ProtectKernelModules=yes |
| 25 | ProtectControlGroups=yes |
| 26 | RestrictAddressFamilies=AF_INET AF_INET6 |
| 27 | RestrictNamespaces=yes |
| 28 | LockPersonality=yes |
| 29 | MemoryDenyWriteExecute=yes |
| 30 | SystemCallArchitectures=native |
| 31 | CapabilityBoundingSet= |
| 32 | |
| 33 | [Install] |
| 34 | WantedBy=multi-user.target |