add caps to container and nix

This commit is contained in:
XenGi 2024-08-08 00:50:33 +02:00
parent 1978208b61
commit adb0190b3f
Signed by: xengi
SSH key fingerprint: SHA256:jxWM2RTHvxxcncXycwwWkP7HCWb4VREN05UGJTbIPZg
2 changed files with 34 additions and 2 deletions

View file

@ -2,10 +2,11 @@
Description=sanic - chaos music control
[Container]
AddCapability=CAP_NET_BIND_SERVICE
AutoUpdate=registry
ContainerName=sanic
Group=sanic
HealthCmd=/usr/bin/curl localhost:8080/echo
HealthCmd=/usr/bin/curl localhost:443/echo
HealthInterval=2m
HealthOnFailure=restart
HealthRetries=5
@ -14,7 +15,7 @@ Image=registry.gitlab.com/xengi/sanic/sanic:latest
LogDriver=journald
Network=host
NoNewPrivileges=true
PublishPort=8080
PublishPort=443
Pull=always
User=sanic
Volume=/etc/sanic/config.ini:/config.ini
@ -25,3 +26,4 @@ TimeoutStartSec=900
[Install]
WantedBy=multi-user.target default.target