From 138074a6a1148fd40b1d48d85f76b762dcb7ec5f Mon Sep 17 00:00:00 2001 From: Dennis Fink Date: Wed, 30 Sep 2026 18:50:01 +0200 Subject: fix(systemd): retry failed exporter runs Retry transient exporter failures up to five times while avoiding retries for invalid command-line usage. Tighten the service sandbox with filesystem protection, required address families, and a corrected capability set, and leave activation solely to the timer unit. --- contrib/prometheus-borgmatic-exporter.service | 23 ++++++++++++++--------- contrib/prometheus-borgmatic-exporter.timer | 2 -- 2 files changed, 14 insertions(+), 11 deletions(-) (limited to 'contrib') diff --git a/contrib/prometheus-borgmatic-exporter.service b/contrib/prometheus-borgmatic-exporter.service index 706a4f5..54a5f4e 100644 --- a/contrib/prometheus-borgmatic-exporter.service +++ b/contrib/prometheus-borgmatic-exporter.service @@ -3,11 +3,20 @@ Description=Borgmatic Prometheus metrics exporter After=network-online.target Wants=network-online.target +# Allow the initial attempt plus five retries. +StartLimitIntervalSec=2h +StartLimitBurst=6 + + [Service] Type=oneshot EnvironmentFile=/etc/conf.d/prometheus-borgmatic-exporter ExecStart=/usr/bin/prometheus-borgmatic-exporter $PROMETHEUS_BORGMATIC_EXPORTER_ARGS +Restart=on-failure +RestartPreventExitStatus=2 +RestartSec=10min + User=root Group=root @@ -19,7 +28,8 @@ ReadWritePaths=/root/.cache/borg PrivateTmp=true # Mount a minimal /dev without the access to raw block or character devices PrivateDevices=true -# ProtectSystem and ProtectHome are ineffective for root and intentionally omitted +ProtectSystem=full +ProtectHome=false # Hide other processes in /proc ProtectProc=invisible @@ -29,7 +39,7 @@ ProcSubset=pid UMask=0022 # Restrict to the address families needed for SSH and local communication -RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX +RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX AF_NETLINK # Kernel and system hardening ProtectKernelTunables=true @@ -45,11 +55,9 @@ LockPersonality=true MemoryDenyWriteExecute=true RemoveIPC=true -# Capabilites +# Capabilities # Root always holds capabilites, but we restrict what child processes can inherit -# CAP_DAC_OVERRIDE: needed by borg for file acess -# CAP_NET_RAW: needed for SSH connections -CapabilityBoundingSet=CAP_DAC_OVERRIDE CAP_NET_RAW +CapabilityBoundingSet=CAP_DAC_OVERRIDE CAP_FOWNER CAP_NET_RAW AmbientCapabilities= # NoNewPrivileges is intentionally omitted as borg needs to exec SSH @@ -58,6 +66,3 @@ SystemCallArchitectures=native SystemCallFilter=@system-service SystemCallFilter=~@privileged @resources @mount @swap @reboot SystemCallFilter=setfsuid setfsgid - -[Install] -WantedBy=multi-user.target diff --git a/contrib/prometheus-borgmatic-exporter.timer b/contrib/prometheus-borgmatic-exporter.timer index 951a774..7c2c2d5 100644 --- a/contrib/prometheus-borgmatic-exporter.timer +++ b/contrib/prometheus-borgmatic-exporter.timer @@ -1,7 +1,5 @@ [Unit] Description=Run Borgmatic Prometheus metrics exporter daily -After=network-online.target -Wants=network-online.target [Timer] OnCalendar=daily -- cgit v1.3.1