Commit the accumulated infrastructure work that was living only in the working tree: monitoring stack, emergency access/bot, gyro allocator, grimmory, adguard, backup audit and the OpenCode agent definitions. Also ignore Python bytecode, local archives and Nix/direnv artifacts. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GTocXkGUUazHdKKd3r9k71
32 lines
824 B
Django/Jinja
32 lines
824 B
Django/Jinja
[Unit]
|
|
Description=Gyro investment allocator
|
|
Wants=network-online.target
|
|
After=network-online.target
|
|
OnFailure=gyro-failure@%n.service
|
|
|
|
[Service]
|
|
Type=oneshot
|
|
User={{ gyro_user }}
|
|
Group={{ gyro_group }}
|
|
WorkingDirectory={{ gyro_app_dir }}
|
|
EnvironmentFile={{ gyro_config_dir }}/gyro.env
|
|
Environment=UV_CACHE_DIR={{ gyro_cache_dir }}/uv
|
|
Environment=PYTHONDONTWRITEBYTECODE=1
|
|
ExecStart=/usr/local/bin/uv run --frozen --no-sync python main.py
|
|
UMask=0077
|
|
NoNewPrivileges=true
|
|
PrivateTmp=true
|
|
ProtectClock=true
|
|
ProtectControlGroups=true
|
|
ProtectHome=true
|
|
ProtectHostname=true
|
|
ProtectKernelLogs=true
|
|
ProtectKernelModules=true
|
|
ProtectKernelTunables=true
|
|
ProtectSystem=strict
|
|
ReadWritePaths={{ gyro_cache_dir }}
|
|
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
|
|
RestrictNamespaces=true
|
|
LockPersonality=true
|
|
MemoryDenyWriteExecute=true
|