[Unit] Description=Borgmatic Prometheus metrics exporter After=network.target [Service] Type=oneshot EnvironmentFile=/etc/conf.d/prometheus-borgmatic-exporter ExecStart=/usr/bin/prometheus-borgmatic-exporter $PROMETHEUS_BORGMATIC_EXPORTER_ARGS User=root Group=root # Needs write access to emit the .prom file and read/write the borg cache. # All other paths read-only by default ReadWritePaths=/var/lib/prometheus/node-exporter ReadWritePaths=/root/.cache/borg # Mount a private /tmp not shared with the rest of the system PrivateTmp=true # Mount a minimal /dev without the access to raw block or character devices PrivateDevices=true # ProtectSystem and ProtectHome are ineffective for root and intentionally omitted # Hide other processes in /proc ProtectProc=invisible # Limit /proc to PID-related files only ProcSubset=pid # Set predictable permissions for the written .prom file UMask=0022 # Restrict to the address families needed for SSH and local communication RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX # Kernel and system hardening ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectControlGroups=true ProtectHostname=true ProtectClock=true RestrictNamespaces=true RestrictRealtime=true RestrictSUIDSGID=true LockPersonality=true MemoryDenyWriteExecute=true RemoveIPC=true # Capabilites # Root always holds capabilites, but we restrict what child processes can inherit # CAP_DAC_OVERRIDE: needed by borg for file acess # CAP_NET_RAW: needed for SSH connections CapabilityBoundingSet=CAP_DAC_OVERRIDE CAP_NET_RAW AmbientCapabilities= # NoNewPrivileges is intentionally omitted as borg needs to exec SSH # Syscall filtering SystemCallArchitectures=native SystemCallFilter=@system-service SystemCallFilter=~@privileged @resources @mount @swap @reboot [Install] WantedBy=multi-user.target