etc-configs/systemd/system/rimgo.service

38 lines
732 B
Desktop File

[Unit]
Description=Rimgo - An Imgur Proxy
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=rimgo
Group=rimgo
WorkingDirectory=/opt/rimgo
ExecStart=/opt/rimgo/rimgo
Restart=on-failure
RestartSec=3s
ReadWritePaths=/opt/rimgo
NoNewPrivileges=yes
MemoryDenyWriteExecute=true
PrivateDevices=yes
PrivateTmp=yes
ProtectHome=yes
ProtectSystem=strict
ProtectControlGroups=true
RestrictSUIDSGID=true
RestrictRealtime=true
LockPersonality=true
ProtectKernelLogs=true
ProtectKernelTunables=true
ProtectHostname=true
ProtectKernelModules=true
PrivateUsers=true
ProtectClock=true
SystemCallArchitectures=native
SystemCallErrorNumber=EPERM
SystemCallFilter=@system-service
[Install]
WantedBy=multi-user.target