[Unit] Description=Borgmatic Prometheus metrics exporter After=network-online.target Wants=network-online.target # Allow the initial attempt plus five retries. StartLimitIntervalSec=2h StartLimitBurst=6 [Service] Type=oneshot EnvironmentFile=/etc/conf.d/prometheus-borgmatic-exporter ExecStart=/usr/bin/prometheus-borgmatic-exporter $PROMETHEUS_BORGMATIC_EXPORTER_ARGS Restart=on-failure RestartPreventExitStatus=2 RestartSec=10min User=root Group=root # Needs write access to emit the .prom file and read/write the borg cache. # All other paths read-only by default ReadWritePaths=/var/lib/prometheus/node-exporter ReadWritePaths=/root/.cache/borg # Mount a private /tmp not shared with the rest of the system PrivateTmp=true # Mount a minimal /dev without the access to raw block or character devices PrivateDevices=true ProtectSystem=full ProtectHome=false # Hide other processes in /proc ProtectProc=invisible # Limit /proc to PID-related files only ProcSubset=pid # Set predictable permissions for the written .prom file UMask=0022 # Restrict to the address families needed for SSH and local communication RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX AF_NETLINK # Kernel and system hardening ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectControlGroups=true ProtectHostname=true ProtectClock=true RestrictNamespaces=true RestrictRealtime=true RestrictSUIDSGID=true LockPersonality=true MemoryDenyWriteExecute=true RemoveIPC=true # Capabilities # Root always holds capabilites, but we restrict what child processes can inherit CapabilityBoundingSet=CAP_DAC_OVERRIDE CAP_FOWNER CAP_NET_RAW AmbientCapabilities= # NoNewPrivileges is intentionally omitted as borg needs to exec SSH # Syscall filtering SystemCallArchitectures=native SystemCallFilter=@system-service SystemCallFilter=~@privileged @resources @mount @swap @reboot SystemCallFilter=setfsuid setfsgid