aboutsummaryrefslogtreecommitdiff
path: root/contrib
diff options
context:
space:
mode:
Diffstat (limited to 'contrib')
-rw-r--r--contrib/prometheus-borgmatic-exporter.service23
-rw-r--r--contrib/prometheus-borgmatic-exporter.timer2
2 files changed, 14 insertions, 11 deletions
diff --git a/contrib/prometheus-borgmatic-exporter.service b/contrib/prometheus-borgmatic-exporter.service
index 706a4f5..54a5f4e 100644
--- a/contrib/prometheus-borgmatic-exporter.service
+++ b/contrib/prometheus-borgmatic-exporter.service
@@ -3,11 +3,20 @@ Description=Borgmatic Prometheus metrics exporter
After=network-online.target
Wants=network-online.target
+# Allow the initial attempt plus five retries.
+StartLimitIntervalSec=2h
+StartLimitBurst=6
+
+
[Service]
Type=oneshot
EnvironmentFile=/etc/conf.d/prometheus-borgmatic-exporter
ExecStart=/usr/bin/prometheus-borgmatic-exporter $PROMETHEUS_BORGMATIC_EXPORTER_ARGS
+Restart=on-failure
+RestartPreventExitStatus=2
+RestartSec=10min
+
User=root
Group=root
@@ -19,7 +28,8 @@ ReadWritePaths=/root/.cache/borg
PrivateTmp=true
# Mount a minimal /dev without the access to raw block or character devices
PrivateDevices=true
-# ProtectSystem and ProtectHome are ineffective for root and intentionally omitted
+ProtectSystem=full
+ProtectHome=false
# Hide other processes in /proc
ProtectProc=invisible
@@ -29,7 +39,7 @@ ProcSubset=pid
UMask=0022
# Restrict to the address families needed for SSH and local communication
-RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX
+RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX AF_NETLINK
# Kernel and system hardening
ProtectKernelTunables=true
@@ -45,11 +55,9 @@ LockPersonality=true
MemoryDenyWriteExecute=true
RemoveIPC=true
-# Capabilites
+# Capabilities
# Root always holds capabilites, but we restrict what child processes can inherit
-# CAP_DAC_OVERRIDE: needed by borg for file acess
-# CAP_NET_RAW: needed for SSH connections
-CapabilityBoundingSet=CAP_DAC_OVERRIDE CAP_NET_RAW
+CapabilityBoundingSet=CAP_DAC_OVERRIDE CAP_FOWNER CAP_NET_RAW
AmbientCapabilities=
# NoNewPrivileges is intentionally omitted as borg needs to exec SSH
@@ -58,6 +66,3 @@ SystemCallArchitectures=native
SystemCallFilter=@system-service
SystemCallFilter=~@privileged @resources @mount @swap @reboot
SystemCallFilter=setfsuid setfsgid
-
-[Install]
-WantedBy=multi-user.target
diff --git a/contrib/prometheus-borgmatic-exporter.timer b/contrib/prometheus-borgmatic-exporter.timer
index 951a774..7c2c2d5 100644
--- a/contrib/prometheus-borgmatic-exporter.timer
+++ b/contrib/prometheus-borgmatic-exporter.timer
@@ -1,7 +1,5 @@
[Unit]
Description=Run Borgmatic Prometheus metrics exporter daily
-After=network-online.target
-Wants=network-online.target
[Timer]
OnCalendar=daily