[Unit] Description=Pacman Prometheus metrics exporter After=network-online.target Wants=network-online.target # Allow the initial attempt plus five retries. StartLimitIntervalSec=2h StartLimitBurst=6 [Service] Type=oneshot EnvironmentFile=/etc/conf.d/prometheus-pacman-exporter ExecStart=/usr/bin/prometheus-pacman-exporter $PROMETHEUS_PACMAN_EXPORTER_ARGS Restart=on-failure RestartSec=10min User=root Group=root # Needs write access to emit the .prom file. # All other paths read-only by default ReadWritePaths=/var/lib/prometheus/node-exporter # Mount a private /tmp not shared with the rest of the system PrivateTmp=true # Mount a minimal /dev without the access to raw block or character devices PrivateDevices=true # Hide other processes in /proc ProtectProc=invisible # Limit /proc to PID-related files only ProcSubset=pid # Set predictable permissions for the written .prom file UMask=0022 RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX # Kernel and system hardening ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectControlGroups=true ProtectHostname=true ProtectClock=true RestrictNamespaces=true RestrictRealtime=true RestrictSUIDSGID=true LockPersonality=true MemoryDenyWriteExecute=true RemoveIPC=true # Capabilites # Root always holds capabilites, but we restrict what child processes can inherit CapabilityBoundingSet=CAP_DAC_OVERRIDE AmbientCapabilities= NoNewPrivileges=true # Syscall filtering SystemCallArchitectures=native SystemCallFilter=@system-service [Install] WantedBy=multi-user.target