-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathstarter.service
More file actions
63 lines (55 loc) · 2.11 KB
/
Copy pathstarter.service
File metadata and controls
63 lines (55 loc) · 2.11 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
# The starter example as a systemd service.
#
# install -m 755 .build/release/starter /usr/local/bin/starter
# install -m 644 Examples/deploy/starter.service /etc/systemd/system/
# install -m 640 -o root -g starter Examples/deploy/env.example /etc/starter/env
# systemctl daemon-reload && systemctl enable --now starter
#
# A new binary goes out with `systemctl reload starter`: the workers are
# replaced one at a time and no connection is dropped.
[Unit]
Description=starter
Documentation=https://github.com/grepjava/garuda/blob/main/Examples/STARTER.md
After=network-online.target postgresql.service
Wants=network-online.target
[Service]
Type=simple
User=starter
Group=starter
EnvironmentFile=/etc/starter/env
# Migrate before any worker serves. Workers would migrate for themselves; doing
# it here means a failed migration fails the unit instead of the first request.
ExecStartPre=/usr/local/bin/starter migrate
# Everything after -- is Garuda's own (CONFIG.md). Loopback because a proxy
# terminates TLS; --forwarded-allow-ips is what makes the proxy's headers
# trusted. For TLS here instead: --tls-cert, --tls-key or --acme-domain.
ExecStart=/usr/local/bin/starter serve -- \
--host 127.0.0.1 --port 8080 --workers 0 \
--access-log --request-id \
--forwarded-allow-ips 127.0.0.1 \
--drain-delay 5000 --health-check-path /health \
--metrics-port 9090 --metrics-host 127.0.0.1
# SIGHUP replaces the workers without dropping a connection.
ExecReload=/bin/kill -HUP $MAINPID
Restart=on-failure
RestartSec=2
# Above --drain-delay plus --graceful-timeout (10 s by default).
TimeoutStopSec=30
# Nothing here writes to disk, so almost everything can be taken away.
NoNewPrivileges=true
PrivateTmp=true
PrivateDevices=true
ProtectSystem=strict
ProtectHome=true
ProtectKernelTunables=true
ProtectKernelModules=true
ProtectControlGroups=true
RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX
RestrictNamespaces=true
LockPersonality=true
MemoryDenyWriteExecute=true
SystemCallArchitectures=native
# With --acme-domain, the cache directory must be writable:
# ReadWritePaths=/var/lib/starter
[Install]
WantedBy=multi-user.target