53 lines
1.7 KiB
Desktop File
53 lines
1.7 KiB
Desktop File
[Unit]
|
|
Description=C-Relay-PG Production Admin Dashboard (PHP built-in server on port 7077)
|
|
Documentation=https://git.laantungir.net/laantungir/c-relay-pg.git
|
|
After=network.target network-online.target postgresql.service c-relay-pg-local.service
|
|
Wants=network-online.target
|
|
Requires=postgresql.service
|
|
# Start after the production relay so the dashboard has a live backend to admin.
|
|
Requires=c-relay-pg-local.service
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=user
|
|
Group=user
|
|
WorkingDirectory=/home/user/lt/c-relay-pg/admin_prod
|
|
ExecStart=/usr/bin/php -S 127.0.0.1:7077 -t /home/user/lt/c-relay-pg/admin_prod
|
|
Restart=always
|
|
RestartSec=5
|
|
StandardOutput=journal
|
|
StandardError=journal
|
|
SyslogIdentifier=c-relay-pg-admin-prod
|
|
|
|
# Environment — point the PHP admin at the PRODUCTION database.
|
|
# admin/lib/config.php reads these; defaults to crelay_prod, set explicitly
|
|
# so the unit is self-documenting and survives future config.php changes.
|
|
Environment=C_RELAY_DB_HOST=127.0.0.1
|
|
Environment=C_RELAY_DB_PORT=5432
|
|
Environment=C_RELAY_DB_NAME=crelay_prod
|
|
Environment=C_RELAY_DB_USER=crelay
|
|
Environment=C_RELAY_DB_PASSWORD=crelay
|
|
|
|
# Security settings
|
|
NoNewPrivileges=true
|
|
ProtectSystem=strict
|
|
ProtectHome=false
|
|
ReadWritePaths=/home/user/lt/c-relay-pg/admin_prod
|
|
PrivateTmp=true
|
|
ProtectKernelTunables=true
|
|
ProtectKernelModules=true
|
|
ProtectControlGroups=true
|
|
|
|
# Network security — only needs loopback for the PHP server and PG socket.
|
|
PrivateNetwork=false
|
|
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
|
|
|
|
# Resource limits — must be high enough to spawn php under user 'user'
|
|
# which already runs many processes (relay, caching, etc.). A low NPROC
|
|
# here causes EAGAIN ("Resource temporarily unavailable") on exec.
|
|
LimitNOFILE=65536
|
|
LimitNPROC=4096
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|