This unit is provided by:
Options
-
[Install]
-
WantedBy=multi-user.target
-
-
[Service]
-
CapabilityBoundingSet=~CAP_SETUID CAP_SETGID CAP_SETPCAP CAP_SYS_ADMIN CAP_SYS_PTRACE CAP_KILL CAP_SYS_BOOT CAP_LINUX_IMMUTABLE CAP_CHOWN CAP_FSETID CAP_SETFCAP CAP_FOWNER CAP_IPC_OWNER CAP_NET_ADMIN CAP_IPC_LOCK CAP_SYS_CHROOT CAP_BLOCK_SUSPEND CAP_LEASE CAP_SYS_PACCT CAP_SYS_TTY_CONFIG CAP_WAKE_ALARM CAP_SYS_NICE CAP_SYS_RESOURCE CAP_DAC_OVERRIDE CAP_DAC_READ_SEARCH CAP_AUDIT_CONTROL CAP_AUDIT_READ CAP_AUDIT_WRITE CAP_MAC_ADMIN CAP_MAC_OVERRIDE CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_NET_RAW
-
ExecReload=/bin/kill -HUP $MAINPID
-
ExecReload=/usr/bin/kill -HUP $MAINPID
-
ExecStart=/usr/bin/icecast -b -c /etc/icecast.xml
-
ExecStart=/usr/bin/icecast -c /etc/icecast.xml
-
ExecStop=/bin/kill -TERM $MAINPID
-
Group=icecast
-
IPAccounting=yes
-
LockPersonality
Introduced in systemd 235=yes -
LogsDirectory=icecast
-
MemoryDenyWriteExecute
Introduced in systemd 231=yes -
NoNewPrivileges
Introduced in systemd 239=yes -
PIDFile=/var/run/icecast.pid
-
PrivateDevices
Introduced in systemd 209=yes -
PrivateTmp=yes
-
PrivateUsers=yes
-
ProtectClock
Introduced in systemd 245=yes -
ProtectControlGroups
Introduced in systemd 232=yes -
ProtectHome
Introduced in systemd 214=yes -
ProtectHostname
Introduced in systemd 242=yes -
ProtectKernelLogs
Introduced in systemd 244=yes -
ProtectKernelModules
Introduced in systemd 232=yes -
ProtectKernelTunables
Introduced in systemd 232=yes -
ProtectSystem
Introduced in systemd 214=full -
ProtectSystem
Introduced in systemd 214=strict -
ReadOnlyPaths=/etc/icecast.xml
-
RemoveIPC
Introduced in systemd 232=yes -
RestrictAddressFamilies=~AF_AX25 AF_IPX AF_APPLETALK AF_X25 AF_DECnet AF_KEY AF_NETLINK AF_PACKET AF_RDS AF_PPPOX AF_LLC AF_IB AF_MPLS AF_CAN AF_TIPC AF_BLUETOOTH AF_ALG AF_VSOCK AF_KCM AF_XDP AF_UNIX AF_INET AF_INET6
-
RestrictNamespaces
Introduced in systemd 233=yes -
RestrictRealtime
Introduced in systemd 231=yes -
RestrictSUIDSGID
Introduced in systemd 242=yes -
RuntimeDirectory=icecast
-
StateDirectory=icecast
-
SystemCallArchitectures=native
-
SystemCallFilter=@system-service ~@resources @privileged
-
Type=exec
-
Type=forking
-
UMask=177
-
User=icecast
-
-
[Unit]
-
After=network.target
-
After=var-run.mount network.target remote-fs.target time-sync.target
-
Description=Icecast Network Audio Streaming Server
-
Description=Icecast Server
-
Requires=var-run.mount network.target remote-fs.target time-sync.target
-
Additionnal notes
Nothing here.