mirror of
https://github.com/CyberMind-FR/secubox-deb.git
synced 2026-07-28 21:17:36 +00:00
secubox-core.service is a Type=oneshot (mkdir+chown) that RemainAfterExit=yes. A hard Requires= on ~108 units cascade-stops them all if core is restarted/fails (e.g. a secubox-core package upgrade) — a thundering-herd outage. After= keeps the ordering; Wants= keeps the soft dependency without the cascade. Prereq for mass native apply (Phase 3). Scaffolds (new-module.sh/new-package.sh) updated so future units use Wants=. Co-Authored-By: Gerald KERMA <devel@cybermind.fr>
28 lines
733 B
Desktop File
28 lines
733 B
Desktop File
[Unit]
|
|
Description=SecuBox App Store — module catalog API
|
|
After=network.target secubox-core.service
|
|
Wants=secubox-core.service
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=secubox
|
|
Group=secubox
|
|
RuntimeDirectory=secubox
|
|
RuntimeDirectoryPreserve=yes
|
|
ExecStart=/usr/bin/python3 -m uvicorn api.main:app --uds /run/secubox/appstore.sock --workers 1
|
|
WorkingDirectory=/usr/lib/secubox/appstore
|
|
Restart=on-failure
|
|
RestartSec=5
|
|
StandardOutput=journal
|
|
StandardError=journal
|
|
|
|
# sudo->secubox-appstorectl bridge requires new privileges; the narrow
|
|
# sudoers rule + helper validation are the security boundary.
|
|
NoNewPrivileges=no
|
|
ProtectHome=yes
|
|
PrivateTmp=yes
|
|
ReadWritePaths=/run/secubox /var/log/secubox /var/lib/secubox
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|