[Unit] Description=wutzcalc — festival drink-sale tracker Documentation=https://git.berlin.ccc.de/vinzenz/wutzcalc After=network-online.target Wants=network-online.target [Service] Type=simple User=wutzcalc Group=wutzcalc # Where `pnpm build` was run — adjust to your install location. WorkingDirectory=/opt/wutzcalc # `which node` may differ (e.g. /usr/local/bin/node or an nvm path). ExecStart=/usr/bin/node server/dist/index.js # Secrets and config live here, not in the unit. See wutzcalc.env.example. EnvironmentFile=/etc/wutzcalc/wutzcalc.env Restart=on-failure RestartSec=5 # Creates/owns /var/lib/wutzcalc — point DB_PATH there. StateDirectory=wutzcalc # Hardening NoNewPrivileges=true ProtectSystem=strict ProtectHome=true PrivateTmp=true PrivateDevices=true ProtectKernelTunables=true ProtectControlGroups=true RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX ReadWritePaths=/var/lib/wutzcalc [Install] WantedBy=multi-user.target