feat(go): advance validation sidecar toward production
This commit is contained in:
parent
6a06eba255
commit
f85c2e831a
92 changed files with 8881 additions and 91 deletions
48
systemd/enodia-sentinel-go-sidecar.service
Normal file
48
systemd/enodia-sentinel-go-sidecar.service
Normal file
|
|
@ -0,0 +1,48 @@
|
|||
[Unit]
|
||||
Description=Enodia Sentinel Go migration validation sidecar
|
||||
After=network.target
|
||||
Documentation=https://github.com/Enodia/enodia-sentinel
|
||||
|
||||
[Service]
|
||||
Type=notify
|
||||
NotifyAccess=main
|
||||
TimeoutStartSec=120
|
||||
# Keep this path independent from enodia-sentinel.service. The sidecar emits
|
||||
# enodia.event.v1 JSONL to the journal and owns only its separate state tree.
|
||||
ExecStart=/usr/bin/env enodia-sentinel-go --config /etc/enodia-sentinel.toml --state-dir /var/lib/enodia-sentinel-go --event-log /var/lib/enodia-sentinel-go/events.jsonl --event-log-max-bytes 67108864 --snapshot-dir /var/lib/enodia-sentinel-go --ebpf-exec --ebpf-syscall
|
||||
Restart=on-failure
|
||||
RestartSec=5
|
||||
StandardOutput=journal
|
||||
StandardError=journal
|
||||
StateDirectory=enodia-sentinel-go
|
||||
StateDirectoryMode=0750
|
||||
UMask=0077
|
||||
|
||||
# The embedded CO-RE programs do not need a compiler or writable executable
|
||||
# memory. The broad CAP_SYS_ADMIN fallback keeps tracepoint attachment working
|
||||
# on kernels predating the narrower CAP_BPF/CAP_PERFMON privilege split.
|
||||
ProtectSystem=strict
|
||||
ProtectHome=read-only
|
||||
InaccessiblePaths=-/var/log/enodia-sentinel
|
||||
NoNewPrivileges=yes
|
||||
PrivateDevices=yes
|
||||
PrivateMounts=yes
|
||||
ProtectClock=yes
|
||||
ProtectHostname=yes
|
||||
ProtectKernelLogs=yes
|
||||
ProtectKernelTunables=yes
|
||||
ProtectKernelModules=yes
|
||||
ProtectControlGroups=yes
|
||||
RestrictSUIDSGID=yes
|
||||
RestrictRealtime=yes
|
||||
MemoryDenyWriteExecute=yes
|
||||
LockPersonality=yes
|
||||
RestrictNamespaces=yes
|
||||
RestrictAddressFamilies=AF_UNIX AF_NETLINK
|
||||
SystemCallArchitectures=native
|
||||
CapabilityBoundingSet=CAP_SYS_PTRACE CAP_DAC_READ_SEARCH CAP_BPF CAP_PERFMON CAP_SYS_ADMIN CAP_SYS_RESOURCE
|
||||
AmbientCapabilities=CAP_SYS_PTRACE CAP_DAC_READ_SEARCH CAP_BPF CAP_PERFMON CAP_SYS_ADMIN CAP_SYS_RESOURCE
|
||||
LimitMEMLOCK=infinity
|
||||
|
||||
[Install]
|
||||
WantedBy=multi-user.target
|
||||
Loading…
Add table
Add a link
Reference in a new issue