SYSTEMD
SYSTEM Daemon Starts and monitors system and user services.
Overview
| Command | Description |
|---|---|
systemctl status <serivename>.service |
Status of service (active, inactive, enabled, disabled, ...) |
systemctl list-timers <servicename>.timer |
Status of service timer (time since last run, next planned start, ...) |
/etc/systemd/system/ |
Directory of self created services |
Create timed service
- Create service entry
sudo nano /etc/systemd/system/<servicename>.service
[Unit] Description=<what the service / called script does> # Wants=network-online.target # After=network-online.target [Service] Type=oneshot|simple # RemainAfterExit=no User=<user for script> Group=<group of files?> UMask=0002 Environment=HOME=<home directory> ExecStart=<script with absolute path> # ExecStart=/usr/bin/flock --nonblock /tmp/<lock filename>.lock <script with absolute path> # ExecStop= # [Install] # WantedBy=multi-user.target|timers.target
- wants/after network-online.target mean that this service needs the network to be online
- Type
oneshotis for short running tasks like backup scripts,simplefor permanently running things like server and databases - additional line
RemainAfterExit=yeswould be for things likemountwhich result is active even if the service has exited - then also an additional lne forExecStopwould be necessary tounmountthe service - UMask means rights that are removed from created files (0002 - remove write rights for other)
- Environment could also be directory of python (inside a virtual environment)
- flock create lock file to prevent different backups running in parallel
- nonblock means, that additional starts doesn't wait but stop executing
Restart=on-failuremeans restart if service crashedRestartSec=5delay for automatic restartInstall WantedBytells the service what to do whensystemctl enableis called
Protection
| Param | Value | Effect |
|---|---|---|
| ProtectSystem | no | --- |
| ProtectSystem | yes | /usrand /boot are read-only |
| ProtectSystem | full | /usrand /boot and /etc are read-only |
| ProtectSystem | strict | almost everything is read-only |
| - | - | - |
| ReadWritePaths | /var/backups |
paths with write access |
| ReadWritePaths | /var/backups /var/test |
paths with write access |
| ReadWritePaths | -/var/test |
paths with write access + okay if not existing at start of service |
| - | - | - |
| ReadOnlyPaths | /home/nano/bin |
explicit read-only paths (probably not necessary with ProtectSystem=strict) |
| - | - | - |
| PrivateTmp | yes | cannot see foreign files in /tmp and /var/tmp |
| - | - | - |
| ProtectHome | yes | protects acces for /home, /root and /run/user- also no read access! |
| - | - | - |
| NoNewPrivileges | yes | no new rights through modification like setuid or setgid |
check for protection
systemd-analyze security <service>.service
- Test (only needed, if not started by timer (see below))
sudo systemctl daemon-reload sudo systemctl start <servicename>.service sudo systemctl status <servicename>.service
- Create timer
sudo nano /etc/system/system/<servicename>.timer
[Unit] Description=<name and how often as title> [Timer] OnCalendar=*-*-* 03:15:00 Persistent=false Unit=<servicename>.service [Install] WantedBy=timers.target
- OnCalendar sets time for daily start
- Persistent=true would mean, that if Raspi would be offline during start time, the run will be catched up after the next start
- Enable / activate Timer
sudo systemctl daemon-reload sudo systemctl enable --now <servicetimer>.timer systemctl status <servicetimer>.timer
- --now starts the timer after enabling
List all timers
systemctl list-timers or systemctl list-timers <servicename>.timer
