secubox-deb/packages/secubox-appstore/debian/secubox-appstore.service
CyberMind-FR 2ec7cef1b2 feat(profiles): Phase 2 — Requires=secubox-core → Wants= on all units (remove hard cascade)
secubox-core.service is a Type=oneshot (mkdir+chown) that RemainAfterExit=yes. A hard
Requires= on ~108 units cascade-stops them all if core is restarted/fails (e.g. a
secubox-core package upgrade) — a thundering-herd outage. After= keeps the ordering;
Wants= keeps the soft dependency without the cascade. Prereq for mass native apply
(Phase 3). Scaffolds (new-module.sh/new-package.sh) updated so future units use Wants=.

Co-Authored-By: Gerald KERMA <devel@cybermind.fr>
2026-07-19 09:06:54 +02:00

28 lines
733 B
Desktop File

[Unit]
Description=SecuBox App Store — module catalog API
After=network.target secubox-core.service
Wants=secubox-core.service
[Service]
Type=simple
User=secubox
Group=secubox
RuntimeDirectory=secubox
RuntimeDirectoryPreserve=yes
ExecStart=/usr/bin/python3 -m uvicorn api.main:app --uds /run/secubox/appstore.sock --workers 1
WorkingDirectory=/usr/lib/secubox/appstore
Restart=on-failure
RestartSec=5
StandardOutput=journal
StandardError=journal
# sudo->secubox-appstorectl bridge requires new privileges; the narrow
# sudoers rule + helper validation are the security boundary.
NoNewPrivileges=no
ProtectHome=yes
PrivateTmp=yes
ReadWritePaths=/run/secubox /var/log/secubox /var/lib/secubox
[Install]
WantedBy=multi-user.target