Diff
1diff --git a/.nfpm/postinstall.sh b/.nfpm/postinstall.sh
2new file mode 100755
3index 0000000000000000000000000000000000000000..929e3e821be5d5525c326bf7939b4321050bf223
4--- /dev/null
5+++ b/.nfpm/postinstall.sh
6@@ -0,0 +1,14 @@
7+#!/bin/sh
8+set -e
9+
10+if ! command -V systemctl >/dev/null 2>&1; then
11+ echo "Not running SystemD, ignoring"
12+ exit 0
13+fi
14+
15+echo "Enabling and starting soft.service"
16+systemctl daemon-reload
17+systemctl unmask soft.service
18+systemctl preset soft.service
19+systemctl enable soft.service
20+systemctl restart soft.service
21diff --git a/.nfpm/postremove.sh b/.nfpm/postremove.sh
22new file mode 100755
23index 0000000000000000000000000000000000000000..b94bb042bd461e2ee5ad1796df51ec36fa79dc11
24--- /dev/null
25+++ b/.nfpm/postremove.sh
26@@ -0,0 +1,6 @@
27+#!/bin/sh
28+set -e
29+
30+systemctl stop soft.service
31+systemctl disable soft.service
32+systemctl daemon-reload
33diff --git a/.nfpm/soft.conf b/.nfpm/soft.conf
34new file mode 100644
35index 0000000000000000000000000000000000000000..d50663825a1e09418939bb12dd5557a1650990a2
36--- /dev/null
37+++ b/.nfpm/soft.conf
38@@ -0,0 +1,6 @@
39+#SOFT_SERVE_PORT=23231
40+#SOFT_SERVE_HOST=domain.tld
41+#SOFT_SERVE_BIND_ADDRESS=0.0.0.0
42+#SOFT_SERVE_KEY_PATH=.ssh/soft_serve_server_ed25519
43+#SOFT_SERVE_INITIAL_ADMIN_KEYS='ssh-ed25519 AAAAC3NzaC1lZDI1...'
44+SOFT_SERVE_DATA_PATH=/var/local/lib/soft-serve
45diff --git a/.nfpm/soft.service b/.nfpm/soft.service
46new file mode 100644
47index 0000000000000000000000000000000000000000..4c292720a35d9ba178d5e538a198c14ae3bedc82
48--- /dev/null
49+++ b/.nfpm/soft.service
50@@ -0,0 +1,45 @@
51+[Unit]
52+Description=Soft Serve git server 🍦
53+Documentation=https://github.com/charmbracelet/soft-serve
54+Requires=network-online.target
55+After=network-online.target
56+
57+[Install]
58+WantedBy=multi-user.target
59+
60+# Hardening
61+ReadWritePaths=/var/lib/soft-serve
62+UMask=0027
63+NoNewPrivileges=true
64+LimitNOFILE=1048576
65+ProtectSystem=strict
66+ProtectHome=true
67+PrivateUsers=yes
68+PrivateTmp=true
69+PrivateDevices=true
70+ProtectHostname=true
71+ProtectClock=true
72+ProtectKernelTunables=true
73+ProtectKernelModules=true
74+ProtectKernelLogs=true
75+ProtectControlGroups=true
76+RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
77+RestrictNamespaces=true
78+LockPersonality=true
79+MemoryDenyWriteExecute=true
80+RestrictRealtime=true
81+RestrictSUIDSGID=true
82+RemoveIPC=true
83+CapabilityBoundingSet=
84+AmbientCapabilities=
85+SystemCallFilter=@system-service
86+SystemCallFilter=~@privileged @resources
87+SystemCallArchitectures=native
88+
89+[Service]
90+Type=simple
91+Restart=always
92+RestartSec=1
93+ExecStartPre=mkdir -p /var/local/lib/soft-serve
94+ExecStart=/usr/bin/soft serve
95+EnvironmentFile=-/etc/soft.conf