systemd yacy "hardened" unit
Posted 08-31-2016 at 01:51 PM by serafean
This is more of an archive for my yacy service file
In this case CPUAccounting limits yacy to one CPU.
Code:
[Unit] Description=Yacy distributed search engine [Service] #Service Type=forking GuessMainPID=yes ExecStart=/opt/yacy/startYACY.sh ExecStop=/opt/yacy/stopYACY.sh User=yacy Group=yacy WorkingDirectory=/opt/yacy # Hardening PrivateTmp=yes PrivateDevices=yes ProtectSystem=full ProtectHome=yes NoNewPrivileges=yes DevicePolicy=closed #Quotas CPUAccounting=True CPUQuota=100% MemoryAccounting=True MemoryLimit=4G [Install] WantedBy=multi-user.target
Total Comments 0