Cap boot unit restarts so it fails open
This commit is contained in:
@@ -6,6 +6,8 @@ Wants=network-pre.target
|
||||
Before=network-pre.target shutdown.target
|
||||
After=local-fs.target systemd-sysctl.service
|
||||
Conflicts=shutdown.target tomswall-agent.service
|
||||
StartLimitIntervalSec=60
|
||||
StartLimitBurst=5
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
@@ -14,7 +16,7 @@ Environment=TOMSWALL_CONFIG=/etc/tomswall/tomswall.yaml
|
||||
EnvironmentFile=-/etc/tomswall/tomswall.env
|
||||
ExecStart=/usr/sbin/tomswall apply -c ${TOMSWALL_CONFIG}
|
||||
ExecReload=/usr/sbin/tomswall apply -c ${TOMSWALL_CONFIG}
|
||||
# Fails open: once restarts are exhausted, boot continues without the ruleset.
|
||||
# Fails open: after StartLimitBurst failures within StartLimitIntervalSec, boot continues without the ruleset.
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
# No ExecStop: stopping the unit leaves the ruleset in place (flush would open the firewall).
|
||||
|
||||
Reference in New Issue
Block a user