37 lines
1.1 KiB
Desktop File
37 lines
1.1 KiB
Desktop File
[Unit]
|
|
Description=FrameFlow isolated restore rehearsal of the latest verified backup
|
|
Documentation=file:///srv/frameflow/docs/deployment.md
|
|
Requires=docker.service frameflow-backup.service
|
|
After=docker.service frameflow-backup.service network-online.target
|
|
Wants=network-online.target
|
|
RequiresMountsFor=/mnt/encrypted-backups
|
|
AssertPathIsMountPoint=/mnt/encrypted-backups
|
|
ConditionPathExists=/srv/frameflow/scripts/scheduled-maintenance.sh
|
|
ConditionPathExists=/etc/frameflow/backup.env
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
User=frameflow
|
|
Group=frameflow
|
|
SupplementaryGroups=docker
|
|
EnvironmentFile=/etc/frameflow/backup.env
|
|
WorkingDirectory=/srv/frameflow
|
|
ExecStart=/srv/frameflow/scripts/scheduled-maintenance.sh restore-latest
|
|
UMask=0077
|
|
TimeoutStartSec=6h
|
|
Nice=10
|
|
IOSchedulingClass=best-effort
|
|
IOSchedulingPriority=6
|
|
NoNewPrivileges=true
|
|
PrivateTmp=true
|
|
ProtectHome=true
|
|
ProtectSystem=strict
|
|
ProtectControlGroups=true
|
|
ProtectKernelModules=true
|
|
ProtectKernelTunables=true
|
|
RestrictRealtime=true
|
|
RestrictSUIDSGID=true
|
|
LockPersonality=true
|
|
ReadOnlyPaths=/mnt/encrypted-backups/frameflow
|
|
ReadWritePaths=/var/lib/frameflow/metrics /var/run/docker.sock
|