deploy: add systemd unit + env template, document service setup

also document WUTZ_TZ / WUTZ_DAY_CUTOFF_HOUR env vars
This commit is contained in:
müde 2026-06-14 22:00:13 +02:00
commit 179a231b58
3 changed files with 93 additions and 0 deletions

View file

@ -0,0 +1,18 @@
# Copy to /etc/wutzcalc/wutzcalc.env and edit.
# Keep it readable only by root / the service user — it holds the admin password:
# sudo install -m 600 -o root -g root deploy/wutzcalc.env.example /etc/wutzcalc/wutzcalc.env
# Required: backoffice login password.
ADMIN_PASSWORD=changeme
# SQLite database file. With StateDirectory=wutzcalc this dir is created for you.
DB_PATH=/var/lib/wutzcalc/wutz.db
# Network bind (defaults: 0.0.0.0:3000).
PORT=3000
HOST=0.0.0.0
# Sales-day handling (defaults shown). Hours before the cutoff count toward the
# previous business day, so a 03:00 sale lands on the night before.
#WUTZ_TZ=Europe/Berlin
#WUTZ_DAY_CUTOFF_HOUR=5

38
deploy/wutzcalc.service Normal file
View file

@ -0,0 +1,38 @@
[Unit]
Description=wutzcalc — festival drink-sale tracker
Documentation=https://git.berlin.ccc.de/vinzenz/wutzcalc
After=network-online.target
Wants=network-online.target
[Service]
Type=simple
User=wutzcalc
Group=wutzcalc
# Where `pnpm build` was run — adjust to your install location.
WorkingDirectory=/opt/wutzcalc
# `which node` may differ (e.g. /usr/local/bin/node or an nvm path).
ExecStart=/usr/bin/node server/dist/index.js
# Secrets and config live here, not in the unit. See wutzcalc.env.example.
EnvironmentFile=/etc/wutzcalc/wutzcalc.env
Restart=on-failure
RestartSec=5
# Creates/owns /var/lib/wutzcalc — point DB_PATH there.
StateDirectory=wutzcalc
# Hardening
NoNewPrivileges=true
ProtectSystem=strict
ProtectHome=true
PrivateTmp=true
PrivateDevices=true
ProtectKernelTunables=true
ProtectControlGroups=true
RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX
ReadWritePaths=/var/lib/wutzcalc
[Install]
WantedBy=multi-user.target