pleroma.service 983 Bytes
Newer Older
1
2
3
4
5
6
7
8
[Unit]
Description=Pleroma social network
After=network.target postgresql.service

[Service]
User=pleroma
WorkingDirectory=/home/pleroma/pleroma
Environment="HOME=/home/pleroma"
shibayashi's avatar
shibayashi committed
9
Environment="MIX_ENV=prod"
10
11
12
13
14
ExecStart=/usr/local/bin/mix phx.server
ExecReload=/bin/kill $MAINPID
KillMode=process
Restart=on-failure

15
16
17
; Some security directives.
; Use private /tmp and /var/tmp folders inside a new file system namespace, which are discarded after the process stops.
PrivateTmp=true
18
; Mount /usr, /boot, and /etc as read-only for processes invoked by this service.
19
20
21
ProtectSystem=full
; Sets up a new /dev mount for the process and only adds API pseudo devices like /dev/null, /dev/zero or /dev/random but not physical devices. Disabled by default because it may not work on devices like the Raspberry Pi.
PrivateDevices=false
22
; Ensures that the service process and all its children can never gain new privileges through execve().
23
24
NoNewPrivileges=true

25
26
[Install]
WantedBy=multi-user.target