Skip to content

Commit 543d051

Browse files
committed
specify config dir, simplify systemd unit
1 parent e46b9ff commit 543d051

File tree

2 files changed

+5
-9
lines changed

2 files changed

+5
-9
lines changed

derper.service

+1-8
Original file line numberDiff line numberDiff line change
@@ -6,19 +6,12 @@ After=network.target
66
Type=simple
77
User=derper
88
Group=derper
9-
ExecStart=/usr/bin/derper
9+
ExecStart=/usr/bin/derper -c /etc/derper/derper.conf
1010
Restart=on-failure
1111
RestartSec=5
1212
LimitNOFILE=1048576
1313

1414
# Hardening measures
15-
PrivateTmp=yes
16-
ProtectSystem=full
17-
NoNewPrivileges=yes
18-
ProtectHome=yes
19-
ProtectKernelTunables=yes
20-
ProtectKernelModules=yes
21-
ProtectControlGroups=yes
2215
AmbientCapabilities=CAP_NET_BIND_SERVICE
2316
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
2417

scripts/preinstall.sh

+4-1
Original file line numberDiff line numberDiff line change
@@ -2,4 +2,7 @@
22
getent group xdpderper >/dev/null || groupadd -r xdpderper
33
getent passwd xdpderper >/dev/null || useradd -r -g xdpderper -s /bin/bash -c "XDPDERP server" xdpderper
44
getent group derper >/dev/null || groupadd -r derper
5-
getent passwd derper >/dev/null || useradd -r -g derper -s /bin/bash -c "DERP server" derper
5+
getent passwd derper >/dev/null || useradd -r -g derper -s /bin/bash -c "DERP server" derper
6+
7+
mkdir /etc/derper
8+
chown -R derper:derper /etc/derper

0 commit comments

Comments
 (0)