From 0f1d5637df9286af9999fc7d1c03025e82ffda34 Mon Sep 17 00:00:00 2001 From: Dennis Fink Date: Sun, 20 Sep 2026 00:38:55 +0200 Subject: feat(systemd): add service and timer units Add a hardened oneshot service for running the exporter with arguments loaded from /etc/conf.d/prometheus-pacman-exporter. Add a persistent daily timer for automatic metric collection and include a default empty configuration file for additional command-line options. --- contrib/prometheus-pacman-exporter.service | 58 ++++++++++++++++++++++++++++++ 1 file changed, 58 insertions(+) create mode 100644 contrib/prometheus-pacman-exporter.service (limited to 'contrib/prometheus-pacman-exporter.service') diff --git a/contrib/prometheus-pacman-exporter.service b/contrib/prometheus-pacman-exporter.service new file mode 100644 index 0000000..770295c --- /dev/null +++ b/contrib/prometheus-pacman-exporter.service @@ -0,0 +1,58 @@ +[Unit] +Description=Pacman Prometheus metrics exporter +After=network.target + +[Service] +Type=oneshot +EnvironmentFile=/etc/conf.d/prometheus-pacman-exporter +ExecStart=/usr/bin/prometheus-pacman-exporter $PROMETHEUS_PACMAN_EXPORTER_ARGS + +User=root +Group=root + +# Needs write access to emit the .prom file and read/write the borg cache. +# All other paths read-only by default +ReadWritePaths=/var/lib/prometheus/node-exporter +# Mount a private /tmp not shared with the rest of the system +PrivateTmp=true +# Mount a minimal /dev without the access to raw block or character devices +PrivateDevices=true +# ProtectSystem and ProtectHome are ineffective for root and intentionally omitted + +# Hide other processes in /proc +ProtectProc=invisible +# Limit /proc to PID-related files only +ProcSubset=pid +# Set predictable permissions for the written .prom file +UMask=0022 + +RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX + +# Kernel and system hardening +ProtectKernelTunables=true +ProtectKernelModules=true +ProtectKernelLogs=true +ProtectControlGroups=true +ProtectHostname=true +ProtectClock=true +RestrictNamespaces=true +RestrictRealtime=true +RestrictSUIDSGID=true +LockPersonality=true +MemoryDenyWriteExecute=true +RemoveIPC=true + +# Capabilites +# Root always holds capabilites, but we restrict what child processes can inherit +CapabilityBoundingSet=CAP_DAC_OVERRIDE +AmbientCapabilities= +NoNewPrivileges=true + +# Syscall filtering +SystemCallArchitectures=native +SystemCallFilter=@system-service +SystemCallFilter=~@privileged @resources @mount @swap @reboot +SystemCallFilter=setfsuid setfsgid + +[Install] +WantedBy=multi-user.target -- cgit v1.3.1