# SYSTEMD SYSTEM Daemon Starts and monitors system and user services. ## Overview | Command | Description | | - | - | | `systemctl status <serivename>.service` | Status of service (active, inactive, enabled, disabled, ...) | | `systemctl list-timers <servicename>.timer` | Status of service timer (time since last run, next planned start, ...) | | `/etc/systemd/system/` | Directory of self created services | ## Create timed service 1. Create service entry ```bash sudo nano /etc/systemd/system/<servicename>.service ``` ```bash [Unit] Description=<what the service / called script does> # Wants=network-online.target # After=network-online.target [Service] Type=oneshot|simple # RemainAfterExit=no User=<user for script> Group=<group of files?> UMask=0002 Environment=HOME=<home directory> ExecStart=<script with absolute path> # ExecStart=/usr/bin/flock --nonblock /tmp/<lock filename>.lock <script with absolute path> # ExecStop= # [Install] # WantedBy=multi-user.target|timers.target ``` - wants/after network-online.target mean that this service needs the network to be online - Type `oneshot` is for short running tasks like backup scripts, `simple` for permanently running things like server and databases - additional line `RemainAfterExit=yes` would be for things like `mount` which result is *active* even if the service has exited - then also an additional lne for `ExecStop` would be necessary to `unmount` the service - UMask means rights that are removed from created files (0002 - remove write rights for other) - Environment could also be directory of python (inside a virtual environment) - flock create lock file to prevent different backups running in parallel - nonblock means, that additional starts doesn't wait but stop executing - `Restart=on-failure` means restart if service crashed - `RestartSec=5` delay for automatic restart - `Install WantedBy` tells the service what to do when `systemctl enable` is called ### Protection | Param | Value | Effect | | - | - | - | | ProtectSystem | no | --- | | ProtectSystem | yes | `/usr`and `/boot` are read-only | | ProtectSystem | full | `/usr`and `/boot` and `/etc` are read-only | | ProtectSystem | strict | almost **everything** is read-only | | - | - | - | | ReadWritePaths | `/var/backups` | paths with write access | | ReadWritePaths | `/var/backups /var/test` | paths with write access | | ReadWritePaths | `-/var/test` | paths with write access + okay if not existing at start of service | | - | - | - | | ReadOnlyPaths | `/home/nano/bin` | explicit read-only paths (probably not necessary with `ProtectSystem=strict`) | | - | - | - | | PrivateTmp | yes | cannot see foreign files in `/tmp` and `/var/tmp` | | - | - | - | | ProtectHome | yes | protects acces for `/home`, `/root` and `/run/user`- also no read access! | | - | - | - | | NoNewPrivileges | yes | no new rights through modification like `setuid` or `setgid` | check for protection ```bash systemd-analyze security <service>.service ``` 2. Test (only needed, if not started by timer (see below)) ```bash sudo systemctl daemon-reload sudo systemctl start <servicename>.service sudo systemctl status <servicename>.service ``` 3. Create timer ```bash sudo nano /etc/system/system/<servicename>.timer ``` ``` [Unit] Description=<name and how often as title> [Timer] OnCalendar=*-*-* 03:15:00 Persistent=false Unit=<servicename>.service [Install] WantedBy=timers.target ``` - OnCalendar sets time for daily start - Persistent=true would mean, that if Raspi would be offline during start time, the run will be catched up after the next start 4. Enable / activate Timer ```bash sudo systemctl daemon-reload sudo systemctl enable --now <servicetimer>.timer systemctl status <servicetimer>.timer ``` - --now starts the timer after enabling ## List all timers `systemctl list-timers` or `systemctl list-timers <servicename>.timer`
