mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 11:12:35 +02:00
bambuddy.service shipped with ProtectHome=true, which makes /home/* invisible to the service namespace. Installing into /home/bambuddy/ (instead of the default /opt/bambuddy/) made ExecStart=/home/bambuddy/venv/bin/uvicorn fail with status=203/EXEC because systemd couldn't resolve the binary path. ReadWritePaths=$INSTALL_PATH does not reliably re-expose /home/* subpaths for exec resolution. install/install.sh now detects /home/* INSTALL_PATH and emits ProtectHome=read-only; default /opt/bambuddy installs keep ProtectHome=true. The manual deploy template defaults to read-only with a comment on when to tighten it. read-only keeps /home immutable to the service - no security regression, since ReadWritePaths still gates writes to the install/data/log dirs only.
65 lines
1.8 KiB
Desktop File
65 lines
1.8 KiB
Desktop File
# BamBuddy Systemd Service Template
|
|
#
|
|
# INSTALLATION:
|
|
# 1. Copy this file to /etc/systemd/system/bambuddy.service
|
|
# 2. Replace placeholders:
|
|
# - INSTALL_PATH: Where BamBuddy is installed (e.g., /opt/bambuddy)
|
|
# - SERVICE_USER: User to run as (e.g., bambuddy)
|
|
# - DATA_DIR: Data directory (e.g., /opt/bambuddy/data)
|
|
# - LOG_DIR: Log directory (e.g., /opt/bambuddy/logs)
|
|
# 3. Run: sudo systemctl daemon-reload
|
|
# 4. Run: sudo systemctl enable bambuddy
|
|
# 5. Run: sudo systemctl start bambuddy
|
|
#
|
|
# Or use the install script: ./install/install.sh
|
|
#
|
|
|
|
[Unit]
|
|
Description=BamBuddy - Bambu Lab Print Management
|
|
Documentation=https://github.com/maziggy/bambuddy
|
|
After=network.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=SERVICE_USER
|
|
Group=SERVICE_USER
|
|
WorkingDirectory=INSTALL_PATH
|
|
|
|
# Environment file (optional - created by install script)
|
|
EnvironmentFile=-INSTALL_PATH/.env
|
|
|
|
# Use virtual environment
|
|
Environment="PATH=INSTALL_PATH/venv/bin:/usr/local/bin:/usr/bin:/bin"
|
|
|
|
# Server configuration
|
|
ExecStart=INSTALL_PATH/venv/bin/uvicorn backend.app.main:app --host 0.0.0.0 --port ${PORT:-8000}
|
|
|
|
# Restart policy
|
|
Restart=on-failure
|
|
RestartSec=5
|
|
|
|
# Graceful shutdown
|
|
TimeoutStopSec=10
|
|
|
|
# Kill zombie ffmpeg processes (timelapse processing)
|
|
ExecStartPre=-/usr/bin/pkill -9 -f "ffmpeg.*bambuddy"
|
|
ExecStopPost=-/usr/bin/pkill -9 -f "ffmpeg.*bambuddy"
|
|
|
|
# Logging
|
|
StandardOutput=journal
|
|
StandardError=journal
|
|
SyslogIdentifier=bambuddy
|
|
|
|
# Security hardening
|
|
NoNewPrivileges=true
|
|
PrivateTmp=true
|
|
ProtectSystem=strict
|
|
# ProtectHome=true hides /home/* and breaks ExecStart when INSTALL_PATH is
|
|
# under /home (issue #1685). Default is the safer read-only; flip to true if
|
|
# your INSTALL_PATH is outside /home (e.g. /opt/bambuddy).
|
|
ProtectHome=read-only
|
|
ReadWritePaths=DATA_DIR LOG_DIR INSTALL_PATH
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|