Add systemd service and installation workflow improvements
This commit is contained in:
1 parent
9e78daeeba
commit
e0f6d7c72c
2 files changed
+59
-96
No files matched your search
+21
-52
@@ -1,67 +1,36 @@
|
|||||||
[Unit]
|
[Unit]
|
||||||
Description=ChronoSeal cryptographic browser attestation service
|
Description=ChronoSeal Cryptographic Attestation Daemon
|
||||||
Documentation=https://chronoseal.rs
|
After=network.target
|
||||||
After=network-online.target
|
|
||||||
Wants=network-online.target
|
Wants=network-online.target
|
||||||
|
|
||||||
[Service]
|
[Service]
|
||||||
Type=simple
|
Type=simple
|
||||||
|
|
||||||
User=chronoseal
|
User=chronoseal
|
||||||
Group=chronoseal
|
Group=chronoseal
|
||||||
|
|
||||||
Environment=RUST_LOG=info
|
|
||||||
Environment=CHRONOSEAL_CONFIG=/etc/chronoseal/config.toml
|
|
||||||
Environment=CHRONOSEAL_STATE_DIR=/var/lib/chronoseal
|
|
||||||
Environment=CHRONOSEAL_PID_FILE=/run/chronoseal.pid
|
|
||||||
|
|
||||||
ExecStart=/usr/local/bin/chronoseal run
|
ExecStart=/usr/local/bin/chronoseal run
|
||||||
ExecStartPre=+/usr/bin/touch /run/chronoseal.pid
|
WorkingDirectory=/opt/chronoseal
|
||||||
ExecStartPre=+/usr/bin/chown chronoseal:chronoseal /run/chronoseal.pid
|
Restart=always
|
||||||
ExecReload=/bin/kill -HUP $MAINPID
|
|
||||||
ExecStopPost=+/usr/bin/rm -f /run/chronoseal.pid
|
|
||||||
PIDFile=/run/chronoseal.pid
|
|
||||||
|
|
||||||
Restart=on-failure
|
|
||||||
RestartSec=3
|
RestartSec=3
|
||||||
TimeoutStopSec=30
|
Environment=RUST_LOG=info
|
||||||
KillSignal=SIGTERM
|
|
||||||
|
|
||||||
RuntimeDirectory=chronoseal
|
# Hardening (production-grade)
|
||||||
RuntimeDirectoryMode=0750
|
|
||||||
StateDirectory=chronoseal
|
|
||||||
StateDirectoryMode=0750
|
|
||||||
LogsDirectory=chronoseal
|
|
||||||
LogsDirectoryMode=0750
|
|
||||||
ConfigurationDirectory=chronoseal
|
|
||||||
ConfigurationDirectoryMode=0750
|
|
||||||
|
|
||||||
NoNewPrivileges=true
|
|
||||||
PrivateTmp=true
|
|
||||||
ProtectSystem=strict
|
ProtectSystem=strict
|
||||||
ProtectHome=read-only
|
ProtectHome=yes
|
||||||
ProtectKernelTunables=true
|
NoNewPrivileges=yes
|
||||||
ProtectKernelModules=true
|
PrivateTmp=yes
|
||||||
ProtectControlGroups=true
|
ProtectKernelTunables=yes
|
||||||
ProtectClock=true
|
ProtectKernelModules=yes
|
||||||
ProtectHostname=true
|
ProtectControlGroups=yes
|
||||||
ProtectProc=invisible
|
MemoryDenyWriteExecute=yes
|
||||||
ProcSubset=pid
|
RestrictRealtime=yes
|
||||||
PrivateDevices=true
|
RestrictSUIDSGID=yes
|
||||||
PrivateIPC=true
|
LockPersonality=yes
|
||||||
|
|
||||||
MemoryDenyWriteExecute=true
|
|
||||||
RestrictRealtime=true
|
|
||||||
RestrictSUIDSGID=true
|
|
||||||
RemoveIPC=true
|
|
||||||
|
|
||||||
LockPersonality=true
|
|
||||||
|
|
||||||
SystemCallArchitectures=native
|
SystemCallArchitectures=native
|
||||||
SystemCallFilter=@system-service
|
ReadWritePaths=/run/chronoseal.pid
|
||||||
SystemCallErrorNumber=EPERM
|
|
||||||
CapabilityBoundingSet=
|
# Logging
|
||||||
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
|
StandardOutput=journal
|
||||||
|
StandardError=journal
|
||||||
|
|
||||||
[Install]
|
[Install]
|
||||||
WantedBy=multi-user.target
|
WantedBy=multi-user.target
|
||||||
+38
-44
@@ -1,52 +1,46 @@
|
|||||||
#!/bin/sh
|
#!/bin/bash
|
||||||
set -eu
|
set -euo pipefail
|
||||||
|
|
||||||
CHRONOSEAL_VERSION="${CHRONOSEAL_VERSION:-latest}"
|
echo "🚀 ChronoSeal Installer"
|
||||||
CHRONOSEAL_INSTALL_DIR="${CHRONOSEAL_INSTALL_DIR:-/usr/local/bin}"
|
echo "======================"
|
||||||
CHRONOSEAL_BASE_URL="${CHRONOSEAL_BASE_URL:-https://get.chronoseal.rs/releases}"
|
|
||||||
|
|
||||||
need() {
|
# Create system user
|
||||||
command -v "$1" >/dev/null 2>&1 || {
|
if ! id -u chronoseal &>/dev/null; then
|
||||||
echo "chronoseal installer: missing required command: $1" >&2
|
sudo useradd --system --no-create-home --shell /usr/sbin/nologin chronoseal
|
||||||
exit 1
|
echo "✓ Created chronoseal system user"
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
need uname
|
|
||||||
need mktemp
|
|
||||||
need chmod
|
|
||||||
|
|
||||||
arch="$(uname -m)"
|
|
||||||
case "$arch" in
|
|
||||||
x86_64|amd64) target="x86_64-unknown-linux-musl" ;;
|
|
||||||
aarch64|arm64) target="aarch64-unknown-linux-musl" ;;
|
|
||||||
*) echo "chronoseal installer: unsupported architecture: $arch" >&2; exit 1 ;;
|
|
||||||
esac
|
|
||||||
|
|
||||||
if command -v curl >/dev/null 2>&1; then
|
|
||||||
fetch="curl --proto =https --tlsv1.2 -fsSL"
|
|
||||||
elif command -v wget >/dev/null 2>&1; then
|
|
||||||
fetch="wget -qO-"
|
|
||||||
else
|
|
||||||
echo "chronoseal installer: install curl or wget" >&2
|
|
||||||
exit 1
|
|
||||||
fi
|
fi
|
||||||
|
|
||||||
tmp="$(mktemp -d)"
|
# Build
|
||||||
trap 'rm -rf "$tmp"' EXIT
|
echo "→ Building ChronoSeal..."
|
||||||
|
cd "$(dirname "$0")/.."
|
||||||
|
bash scripts/build.sh
|
||||||
|
|
||||||
url="$CHRONOSEAL_BASE_URL/$CHRONOSEAL_VERSION/chronoseal-$target.tar.gz"
|
# Install binary
|
||||||
echo "downloading chronoseal $CHRONOSEAL_VERSION for $target"
|
sudo install -Dm755 target/release/chronoseal /usr/local/bin/chronoseal
|
||||||
|
echo "✓ Installed binary to /usr/local/bin/chronoseal"
|
||||||
|
|
||||||
# shellcheck disable=SC2086
|
# Install frontend assets
|
||||||
$fetch "$url" | tar -xz -C "$tmp"
|
sudo mkdir -p /opt/chronoseal
|
||||||
chmod 0755 "$tmp/chronoseal"
|
sudo cp -r frontend /opt/chronoseal/
|
||||||
|
sudo chown -R chronoseal:chronoseal /opt/chronoseal
|
||||||
|
echo "✓ Installed frontend assets"
|
||||||
|
|
||||||
if [ "$(id -u)" -eq 0 ]; then
|
# Install systemd service
|
||||||
install -m 0755 "$tmp/chronoseal" "$CHRONOSEAL_INSTALL_DIR/chronoseal"
|
sudo cp chronoseal.service /etc/systemd/system/chronoseal.service
|
||||||
else
|
sudo systemctl daemon-reload
|
||||||
sudo install -m 0755 "$tmp/chronoseal" "$CHRONOSEAL_INSTALL_DIR/chronoseal"
|
echo "✓ Installed systemd service"
|
||||||
fi
|
|
||||||
|
|
||||||
echo "installed: $CHRONOSEAL_INSTALL_DIR/chronoseal"
|
# Enable and start
|
||||||
echo "try: chronoseal --help"
|
sudo systemctl enable --now chronoseal
|
||||||
|
echo "✓ ChronoSeal service started"
|
||||||
|
|
||||||
|
echo ""
|
||||||
|
echo "✅ ChronoSeal installed successfully!"
|
||||||
|
echo ""
|
||||||
|
echo "Useful commands:"
|
||||||
|
echo " chronoseal status # Check service status"
|
||||||
|
echo " chronoseal health # Health probe"
|
||||||
|
echo " sudo systemctl status chronoseal"
|
||||||
|
echo " sudo journalctl -u chronoseal -f"
|
||||||
|
echo ""
|
||||||
|
echo "To uninstall: sudo systemctl disable --now chronoseal && sudo rm /usr/local/bin/chronoseal"
|
||||||
Reference in new issue
Block a user