# SYSTEMD
SYSTEM Daemon
Starts and monitors system and user services.

## Overview
| Command | Description |
| - | - |
| `systemctl status <serivename>.service` | Status of service (active, inactive, enabled, disabled, ...) |
| `systemctl list-timers <servicename>.timer` | Status of service timer (time since last run, next planned start, ...) |
| `/etc/systemd/system/` | Directory of self created services |

## Create timed service

1. Create service entry
```bash
sudo nano /etc/systemd/system/<servicename>.service
```

```bash
[Unit]
Description=<what the service / called script does>
# Wants=network-online.target
# After=network-online.target

[Service]
Type=oneshot|simple
# RemainAfterExit=no
User=<user for script>
Group=<group of files?>
UMask=0002
Environment=HOME=<home directory>
ExecStart=<script with absolute path>
# ExecStart=/usr/bin/flock --nonblock /tmp/<lock filename>.lock <script with absolute path>
# ExecStop=

# [Install]
# WantedBy=multi-user.target|timers.target
```
- wants/after network-online.target mean that this service needs the network to be online
- Type `oneshot` is for short running tasks like backup scripts, `simple` for permanently running things like server and databases
- additional line `RemainAfterExit=yes` would be for things like `mount` which result is *active* even if the service has exited - then also an additional lne for `ExecStop` would be necessary to `unmount` the service
- UMask means rights that are removed from created files (0002 - remove write rights for other)
- Environment could also be directory of python (inside a virtual environment)
- flock create lock file to prevent different backups running in parallel
- nonblock means, that additional starts doesn't wait but stop executing
- `Restart=on-failure` means restart if service crashed
- `RestartSec=5` delay for automatic restart
- `Install WantedBy` tells the service what to do when `systemctl enable` is called

### Protection
| Param | Value | Effect |
| - | - | - |
| ProtectSystem | no | --- |
| ProtectSystem | yes | `/usr`and `/boot` are read-only |
| ProtectSystem | full | `/usr`and `/boot` and `/etc` are read-only |
| ProtectSystem | strict | almost **everything** is read-only |
| - | - | - |
| ReadWritePaths | `/var/backups` | paths with write access |
| ReadWritePaths | `/var/backups /var/test` | paths with write access |
| ReadWritePaths | `-/var/test` | paths with write access + okay if not existing at start of service |
| - | - | - |
| ReadOnlyPaths | `/home/nano/bin` | explicit read-only paths (probably not necessary with `ProtectSystem=strict`) |
| - | - | - |
| PrivateTmp | yes | cannot see foreign files in `/tmp` and `/var/tmp` |
| - | - | - |
| ProtectHome | yes | protects acces for `/home`, `/root` and `/run/user`- also no read access! |
| - | - | - |
| NoNewPrivileges | yes | no new rights through modification like `setuid` or `setgid` |

check for protection
```bash
systemd-analyze security <service>.service
```

2. Test  (only needed, if not started by timer (see below))
```bash
sudo systemctl daemon-reload
sudo systemctl start <servicename>.service
sudo systemctl status <servicename>.service
```

3. Create timer
```bash
sudo nano /etc/system/system/<servicename>.timer
```

```
[Unit]
Description=<name and how often as title>

[Timer]
OnCalendar=*-*-* 03:15:00
Persistent=false
Unit=<servicename>.service

[Install]
WantedBy=timers.target
```
- OnCalendar sets time for daily start
- Persistent=true would mean, that if Raspi would be offline during start time, the run will be catched up after the next start

4. Enable / activate Timer
```bash
sudo systemctl daemon-reload
sudo systemctl enable --now <servicetimer>.timer
systemctl status <servicetimer>.timer
```
- --now starts the timer after enabling

## List all timers
`systemctl list-timers` or `systemctl list-timers <servicename>.timer`
0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 5 6 7 8 9