Blame

86e713 Niklas Polke 2026-08-03 20:52:15
Create SYSTEMD
1
# SYSTEMD
2
SYSTEM Daemon
3
Starts and monitors system and user services.
4
5
## Overview
6
| Command | Description |
7
| - | - |
8
| `systemctl status <serivename>.service` | Status of service (active, inactive, enabled, disabled, ...) |
9
| `systemctl list-timers <servicename>.timer` | Status of service timer (time since last run, next planned start, ...) |
10
| `/etc/systemd/system/` | Directory of self created services |
11
12
## Create timed service
13
14
1. Create service entry
15
```bash
16
sudo nano /etc/systemd/system/<servicename>.service
17
```
18
f00298 Niklas Polke 2026-08-13 13:12:53
Update Systemd Configuration
19
```bash
86e713 Niklas Polke 2026-08-03 20:52:15
Create SYSTEMD
20
[Unit]
21
Description=<what the service / called script does>
f00298 Niklas Polke 2026-08-13 13:12:53
Update Systemd Configuration
22
# Wants=network-online.target
23
# After=network-online.target
86e713 Niklas Polke 2026-08-03 20:52:15
Create SYSTEMD
24
25
[Service]
26
Type=oneshot|simple
f00298 Niklas Polke 2026-08-13 13:12:53
Update Systemd Configuration
27
# RemainAfterExit=no
86e713 Niklas Polke 2026-08-03 20:52:15
Create SYSTEMD
28
User=<user for script>
29
Group=<group of files?>
a5d709 Niklas Polke 2026-08-13 15:08:22
Add UMask to SYSTEMD
30
UMask=0002
86e713 Niklas Polke 2026-08-03 20:52:15
Create SYSTEMD
31
Environment=HOME=<home directory>
f00298 Niklas Polke 2026-08-13 13:12:53
Update Systemd Configuration
32
ExecStart=<script with absolute path>
33
# ExecStart=/usr/bin/flock --nonblock /tmp/<lock filename>.lock <script with absolute path>
34
# ExecStop=
d340b1 Niklas Polke 2026-08-03 21:01:55
Additional SYSTEMD options
35
f00298 Niklas Polke 2026-08-13 13:12:53
Update Systemd Configuration
36
# [Install]
37
# WantedBy=multi-user.target|timers.target
86e713 Niklas Polke 2026-08-03 20:52:15
Create SYSTEMD
38
```
39
- wants/after network-online.target mean that this service needs the network to be online
40
- Type `oneshot` is for short running tasks like backup scripts, `simple` for permanently running things like server and databases
41
- additional line `RemainAfterExit=yes` would be for things like `mount` which result is *active* even if the service has exited - then also an additional lne for `ExecStop` would be necessary to `unmount` the service
a5d709 Niklas Polke 2026-08-13 15:08:22
Add UMask to SYSTEMD
42
- UMask means rights that are removed from created files (0002 - remove write rights for other)
d340b1 Niklas Polke 2026-08-03 21:01:55
Additional SYSTEMD options
43
- Environment could also be directory of python (inside a virtual environment)
86e713 Niklas Polke 2026-08-03 20:52:15
Create SYSTEMD
44
- flock create lock file to prevent different backups running in parallel
45
- nonblock means, that additional starts doesn't wait but stop executing
d340b1 Niklas Polke 2026-08-03 21:01:55
Additional SYSTEMD options
46
- `Restart=on-failure` means restart if service crashed
47
- `RestartSec=5` delay for automatic restart
48
- `Install WantedBy` tells the service what to do when `systemctl enable` is called
86e713 Niklas Polke 2026-08-03 20:52:15
Create SYSTEMD
49
1f8f06 Niklas Polke 2026-08-13 15:34:35
Add Protection Params for SYSTEMD Service
50
### Protection
51
| Param | Value | Effect |
52
| - | - | - |
53
| ProtectSystem | no | --- |
54
| ProtectSystem | yes | `/usr`and `/boot` are read-only |
55
| ProtectSystem | full | `/usr`and `/boot` and `/etc` are read-only |
56
| ProtectSystem | strict | almost **everything** is read-only |
57
| - | - | - |
58
| ReadWritePaths | `/var/backups` | paths with write access |
59
| ReadWritePaths | `/var/backups /var/test` | paths with write access |
60
| ReadWritePaths | `-/var/test` | paths with write access + okay if not existing at start of service |
61
| - | - | - |
62
| ReadOnlyPaths | `/home/nano/bin` | explicit read-only paths (probably not necessary with `ProtectSystem=strict`) |
63
| - | - | - |
64
| PrivateTmp | yes | cannot see foreign files in `/tmp` and `/var/tmp` |
65
| - | - | - |
66
| ProtectHome | yes | protects acces for `/home`, `/root` and `/run/user`- also no read access! |
67
| - | - | - |
68
| NoNewPrivileges | yes | no new rights through modification like `setuid` or `setgid` |
69
70
check for protection
71
```bash
72
systemd-analyze security <service>.service
73
```
74
ff84e5 Niklas Polke 2026-08-13 13:23:43
Update SystemD Timer
75
2. Test (only needed, if not started by timer (see below))
86e713 Niklas Polke 2026-08-03 20:52:15
Create SYSTEMD
76
```bash
77
sudo systemctl daemon-reload
78
sudo systemctl start <servicename>.service
79
sudo systemctl status <servicename>.service
80
```
81
82
3. Create timer
83
```bash
84
sudo nano /etc/system/system/<servicename>.timer
85
```
86
87
```
88
[Unit]
89
Description=<name and how often as title>
90
91
[Timer]
92
OnCalendar=*-*-* 03:15:00
93
Persistent=false
94
Unit=<servicename>.service
95
96
[Install]
97
WantedBy=timers.target
98
```
99
- OnCalendar sets time for daily start
100
- Persistent=true would mean, that if Raspi would be offline during start time, the run will be catched up after the next start
101
102
4. Enable / activate Timer
103
```bash
104
sudo systemctl daemon-reload
105
sudo systemctl enable --now <servicetimer>.timer
106
systemctl status <servicetimer>.timer
107
```
108
- --now starts the timer after enabling
109
110
## List all timers
111
`systemctl list-timers` or `systemctl list-timers <servicename>.timer`