cli: avoid data-dir initialization for version; create db parent dirs; redact generated passwords in CLI output
- Prevent 'nx9-wg version' from creating data directories by avoiding database initialization. - Create parent directories when an explicit --database path is provided. - Redact printed generated administrator passwords; announce file path or redact instead. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
This commit is contained in:
commit
2ac6c81dfe
140 files changed
+31342
No files matched your search
@@ -0,0 +1,42 @@
|
||||
[Unit]
|
||||
Description=NX9 WireGuard Appliance Management Engine
|
||||
Documentation=https://github.com/nx9/nx9-wg
|
||||
After=network.target network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=root
|
||||
Group=root
|
||||
|
||||
# Environment configuration file
|
||||
EnvironmentFile=-/etc/nx9-wg/nx9-wg.env
|
||||
|
||||
# Executable location and invocation
|
||||
ExecStart=/usr/local/bin/nx9-wg --config /etc/nx9-wg/config.toml --data-dir /var/lib/nx9-wg serve
|
||||
|
||||
# Process management and restart policy
|
||||
Restart=always
|
||||
RestartSec=5s
|
||||
KillMode=process
|
||||
TimeoutStopSec=15s
|
||||
|
||||
# Security Hardening & Linux Capability Bounds
|
||||
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
|
||||
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
|
||||
NoNewPrivileges=true
|
||||
|
||||
# Filesystem Isolation
|
||||
ProtectSystem=strict
|
||||
ProtectHome=true
|
||||
PrivateTmp=true
|
||||
ProtectKernelTunables=false
|
||||
ProtectControlGroups=true
|
||||
ReadWritePaths=/var/lib/nx9-wg /etc/nx9-wg /var/log
|
||||
|
||||
# Resource Limits
|
||||
LimitNOFILE=65536
|
||||
LimitNPROC=4096
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in new issue
Block a user