systemd: cluster daemon unit for production lifecycle #24
@@ -0,0 +1,37 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=Clawstor cluster daemon (gossip + RPC + Prometheus + build cache)
|
||||||
|
Documentation=https://git.redclaw.dev/clawverse/clawstor
|
||||||
|
After=network-online.target
|
||||||
|
Wants=network-online.target
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
# Set both CLAWSTOR_BIN + CLAWSTOR_CONFIG via `systemctl edit
|
||||||
|
# clawstor-cluster.service` — the drop-in replaces this unit's
|
||||||
|
# ExecStart when the operator wants a non-default install.
|
||||||
|
Environment=CLAWSTOR_BIN=%h/clawstor-deploy/claw-store
|
||||||
|
Environment=CLAWSTOR_CONFIG=%h/clawstor-deploy/config.toml
|
||||||
|
# rustc must be on PATH so the fingerprint gossip probe finds it.
|
||||||
|
# `%h/.cargo/bin` is where rustup normally installs it. Adjust via
|
||||||
|
# drop-in if your toolchain lives elsewhere.
|
||||||
|
Environment=PATH=%h/.cargo/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
|
||||||
|
Environment=RUST_LOG=info
|
||||||
|
ExecStart=/bin/sh -c '"$CLAWSTOR_BIN" --config "$CLAWSTOR_CONFIG" daemon'
|
||||||
|
Restart=on-failure
|
||||||
|
RestartSec=10
|
||||||
|
# Give the daemon 60s to shut down cleanly (gossip needs to
|
||||||
|
# advertise its intent so peers observe departure quickly). Longer
|
||||||
|
# than default so a slow gossip round can complete.
|
||||||
|
TimeoutStopSec=60
|
||||||
|
|
||||||
|
# Security hardening — safe defaults for a build-cache daemon:
|
||||||
|
NoNewPrivileges=yes
|
||||||
|
ProtectSystem=strict
|
||||||
|
ProtectHome=read-only
|
||||||
|
# The blob-store root + hot/warm dirs are the only writable paths.
|
||||||
|
# Adjust via drop-in when your dirs live outside `%h/clawstor-deploy`.
|
||||||
|
ReadWritePaths=%h/clawstor-deploy
|
||||||
|
PrivateTmp=yes
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=default.target
|
||||||
Reference in New Issue
Block a user