repo init
This commit is contained in:
commit
7e44db87b2
48 files changed
+5346
No files matched your search
@@ -0,0 +1,24 @@
|
||||
[Unit]
|
||||
Description=Cloud IP Validator - Control API
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=cloud-ip-validator
|
||||
Group=cloud-ip-validator
|
||||
ExecStart=/usr/local/bin/control-api -config /etc/cloud-ip-validator/control-api.yaml
|
||||
# Holds OS_AUTH_URL / OS_TOKEN / OS_PROJECT_ID / etc — the admin credential
|
||||
# for OpenStack Floating IP management. Keep this file mode 0600, owned by
|
||||
# the service user; never commit it or put credentials in the YAML config.
|
||||
EnvironmentFile=/etc/cloud-ip-validator/control-api.env
|
||||
WorkingDirectory=/var/lib/cloud-ip-validator
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
NoNewPrivileges=true
|
||||
ProtectSystem=strict
|
||||
ReadWritePaths=/var/lib/cloud-ip-validator
|
||||
PrivateTmp=true
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -0,0 +1,22 @@
|
||||
[Unit]
|
||||
Description=Cloud IP Validator - Prober
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=cloud-ip-validator
|
||||
Group=cloud-ip-validator
|
||||
ExecStart=/usr/local/bin/prober -config /etc/cloud-ip-validator/prober.yaml
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
NoNewPrivileges=true
|
||||
# Unprivileged ICMP echo requires either root or CAP_NET_RAW; grant only
|
||||
# the latter rather than running the prober as root.
|
||||
AmbientCapabilities=CAP_NET_RAW
|
||||
CapabilityBoundingSet=CAP_NET_RAW
|
||||
ProtectSystem=strict
|
||||
PrivateTmp=true
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
@@ -0,0 +1,22 @@
|
||||
[Unit]
|
||||
Description=Cloud IP Validator - Validator Agent
|
||||
After=network-online.target
|
||||
Wants=network-online.target
|
||||
|
||||
[Service]
|
||||
Type=simple
|
||||
User=cloud-ip-validator
|
||||
Group=cloud-ip-validator
|
||||
ExecStart=/usr/local/bin/validator-agent -config /etc/cloud-ip-validator/validator-agent.yaml
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
NoNewPrivileges=true
|
||||
# Unprivileged ICMP echo requires either root or CAP_NET_RAW; grant only
|
||||
# the latter rather than running the agent as root.
|
||||
AmbientCapabilities=CAP_NET_RAW
|
||||
CapabilityBoundingSet=CAP_NET_RAW
|
||||
ProtectSystem=strict
|
||||
PrivateTmp=true
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Reference in new issue
Block a user