Files
c-relay-pg/systemd/c-relay-pg-admin-prod.service
T

53 lines
1.7 KiB
Desktop File

[Unit]
Description=C-Relay-PG Production Admin Dashboard (PHP built-in server on port 7077)
Documentation=https://git.laantungir.net/laantungir/c-relay-pg.git
After=network.target network-online.target postgresql.service c-relay-pg-local.service
Wants=network-online.target
Requires=postgresql.service
# Start after the production relay so the dashboard has a live backend to admin.
Requires=c-relay-pg-local.service
[Service]
Type=simple
User=user
Group=user
WorkingDirectory=/home/user/lt/c-relay-pg/admin_prod
ExecStart=/usr/bin/php -S 127.0.0.1:7077 -t /home/user/lt/c-relay-pg/admin_prod
Restart=always
RestartSec=5
StandardOutput=journal
StandardError=journal
SyslogIdentifier=c-relay-pg-admin-prod
# Environment — point the PHP admin at the PRODUCTION database.
# admin/lib/config.php reads these; defaults to crelay_prod, set explicitly
# so the unit is self-documenting and survives future config.php changes.
Environment=C_RELAY_DB_HOST=127.0.0.1
Environment=C_RELAY_DB_PORT=5432
Environment=C_RELAY_DB_NAME=crelay_prod
Environment=C_RELAY_DB_USER=crelay
Environment=C_RELAY_DB_PASSWORD=crelay
# Security settings
NoNewPrivileges=true
ProtectSystem=strict
ProtectHome=false
ReadWritePaths=/home/user/lt/c-relay-pg/admin_prod
PrivateTmp=true
ProtectKernelTunables=true
ProtectKernelModules=true
ProtectControlGroups=true
# Network security — only needs loopback for the PHP server and PG socket.
PrivateNetwork=false
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
# Resource limits — must be high enough to spawn php under user 'user'
# which already runs many processes (relay, caching, etc.). A low NPROC
# here causes EAGAIN ("Resource temporarily unavailable") on exec.
LimitNOFILE=65536
LimitNPROC=4096
[Install]
WantedBy=multi-user.target