diff --git a/chronoseal.service b/chronoseal.service index f0bd67a..6dd7452 100644 --- a/chronoseal.service +++ b/chronoseal.service @@ -1,67 +1,36 @@ [Unit] -Description=ChronoSeal cryptographic browser attestation service -Documentation=https://chronoseal.rs -After=network-online.target +Description=ChronoSeal Cryptographic Attestation Daemon +After=network.target Wants=network-online.target [Service] Type=simple - User=chronoseal Group=chronoseal - -Environment=RUST_LOG=info -Environment=CHRONOSEAL_CONFIG=/etc/chronoseal/config.toml -Environment=CHRONOSEAL_STATE_DIR=/var/lib/chronoseal -Environment=CHRONOSEAL_PID_FILE=/run/chronoseal.pid - ExecStart=/usr/local/bin/chronoseal run -ExecStartPre=+/usr/bin/touch /run/chronoseal.pid -ExecStartPre=+/usr/bin/chown chronoseal:chronoseal /run/chronoseal.pid -ExecReload=/bin/kill -HUP $MAINPID -ExecStopPost=+/usr/bin/rm -f /run/chronoseal.pid -PIDFile=/run/chronoseal.pid - -Restart=on-failure +WorkingDirectory=/opt/chronoseal +Restart=always RestartSec=3 -TimeoutStopSec=30 -KillSignal=SIGTERM +Environment=RUST_LOG=info -RuntimeDirectory=chronoseal -RuntimeDirectoryMode=0750 -StateDirectory=chronoseal -StateDirectoryMode=0750 -LogsDirectory=chronoseal -LogsDirectoryMode=0750 -ConfigurationDirectory=chronoseal -ConfigurationDirectoryMode=0750 - -NoNewPrivileges=true -PrivateTmp=true +# Hardening (production-grade) ProtectSystem=strict -ProtectHome=read-only -ProtectKernelTunables=true -ProtectKernelModules=true -ProtectControlGroups=true -ProtectClock=true -ProtectHostname=true -ProtectProc=invisible -ProcSubset=pid -PrivateDevices=true -PrivateIPC=true - -MemoryDenyWriteExecute=true -RestrictRealtime=true -RestrictSUIDSGID=true -RemoveIPC=true - -LockPersonality=true - +ProtectHome=yes +NoNewPrivileges=yes +PrivateTmp=yes +ProtectKernelTunables=yes +ProtectKernelModules=yes +ProtectControlGroups=yes +MemoryDenyWriteExecute=yes +RestrictRealtime=yes +RestrictSUIDSGID=yes +LockPersonality=yes SystemCallArchitectures=native -SystemCallFilter=@system-service -SystemCallErrorNumber=EPERM -CapabilityBoundingSet= -RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 +ReadWritePaths=/run/chronoseal.pid + +# Logging +StandardOutput=journal +StandardError=journal [Install] WantedBy=multi-user.target diff --git a/scripts/install.sh b/scripts/install.sh index e357a6f..2acc27a 100755 --- a/scripts/install.sh +++ b/scripts/install.sh @@ -1,52 +1,46 @@ -#!/bin/sh -set -eu +#!/bin/bash +set -euo pipefail -CHRONOSEAL_VERSION="${CHRONOSEAL_VERSION:-latest}" -CHRONOSEAL_INSTALL_DIR="${CHRONOSEAL_INSTALL_DIR:-/usr/local/bin}" -CHRONOSEAL_BASE_URL="${CHRONOSEAL_BASE_URL:-https://get.chronoseal.rs/releases}" +echo "🚀 ChronoSeal Installer" +echo "======================" -need() { - command -v "$1" >/dev/null 2>&1 || { - echo "chronoseal installer: missing required command: $1" >&2 - exit 1 - } -} - -need uname -need mktemp -need chmod - -arch="$(uname -m)" -case "$arch" in - x86_64|amd64) target="x86_64-unknown-linux-musl" ;; - aarch64|arm64) target="aarch64-unknown-linux-musl" ;; - *) echo "chronoseal installer: unsupported architecture: $arch" >&2; exit 1 ;; -esac - -if command -v curl >/dev/null 2>&1; then - fetch="curl --proto =https --tlsv1.2 -fsSL" -elif command -v wget >/dev/null 2>&1; then - fetch="wget -qO-" -else - echo "chronoseal installer: install curl or wget" >&2 - exit 1 +# Create system user +if ! id -u chronoseal &>/dev/null; then + sudo useradd --system --no-create-home --shell /usr/sbin/nologin chronoseal + echo "✓ Created chronoseal system user" fi -tmp="$(mktemp -d)" -trap 'rm -rf "$tmp"' EXIT +# Build +echo "→ Building ChronoSeal..." +cd "$(dirname "$0")/.." +bash scripts/build.sh -url="$CHRONOSEAL_BASE_URL/$CHRONOSEAL_VERSION/chronoseal-$target.tar.gz" -echo "downloading chronoseal $CHRONOSEAL_VERSION for $target" +# Install binary +sudo install -Dm755 target/release/chronoseal /usr/local/bin/chronoseal +echo "✓ Installed binary to /usr/local/bin/chronoseal" -# shellcheck disable=SC2086 -$fetch "$url" | tar -xz -C "$tmp" -chmod 0755 "$tmp/chronoseal" +# Install frontend assets +sudo mkdir -p /opt/chronoseal +sudo cp -r frontend /opt/chronoseal/ +sudo chown -R chronoseal:chronoseal /opt/chronoseal +echo "✓ Installed frontend assets" -if [ "$(id -u)" -eq 0 ]; then - install -m 0755 "$tmp/chronoseal" "$CHRONOSEAL_INSTALL_DIR/chronoseal" -else - sudo install -m 0755 "$tmp/chronoseal" "$CHRONOSEAL_INSTALL_DIR/chronoseal" -fi +# Install systemd service +sudo cp chronoseal.service /etc/systemd/system/chronoseal.service +sudo systemctl daemon-reload +echo "✓ Installed systemd service" -echo "installed: $CHRONOSEAL_INSTALL_DIR/chronoseal" -echo "try: chronoseal --help" +# Enable and start +sudo systemctl enable --now chronoseal +echo "✓ ChronoSeal service started" + +echo "" +echo "✅ ChronoSeal installed successfully!" +echo "" +echo "Useful commands:" +echo " chronoseal status # Check service status" +echo " chronoseal health # Health probe" +echo " sudo systemctl status chronoseal" +echo " sudo journalctl -u chronoseal -f" +echo "" +echo "To uninstall: sudo systemctl disable --now chronoseal && sudo rm /usr/local/bin/chronoseal"