This unit is provided by:
Options
-
[Service]
-
BindReadOnlyPaths=/nix/store /etc
-
CapabilityBoundingSet=
-
DeviceAllow=
-
DynamicUser=yes
-
Environment="SHIORI_DIR=/var/lib/shiori"
-
ExecStart=/usr/bin/shiori serve --address '' --port '8080'
-
LockPersonality
Introduced in systemd 235=yes -
MemoryDenyWriteExecute
Introduced in systemd 231=yes -
PrivateDevices
Introduced in systemd 209=yes -
PrivateUsers=yes
-
ProtectClock
Introduced in systemd 245=yes -
ProtectControlGroups
Introduced in systemd 232=yes -
ProtectHome
Introduced in systemd 214=yes -
ProtectHostname
Introduced in systemd 242=yes -
ProtectKernelLogs
Introduced in systemd 244=yes -
ProtectKernelModules
Introduced in systemd 232=yes -
ProtectKernelTunables
Introduced in systemd 232=yes -
RestrictAddressFamilies=AF_INET AF_INET6
-
RestrictNamespaces
Introduced in systemd 233=yes -
RestrictRealtime
Introduced in systemd 231=yes -
RestrictSUIDSGID
Introduced in systemd 242=yes -
RootDirectory=/run/shiori
-
RuntimeDirectory=shiori
-
StateDirectory=shiori
-
SystemCallArchitectures=native
-
SystemCallErrorNumber=EPERM
-
SystemCallFilter=@system-service ~@cpu-emulation ~@debug ~@keyring ~@memlock ~@obsolete ~@privileged ~@setuid
-
-
[Unit]
-
Description=Shiori simple bookmarks manager
-
Additionnal notes
Nothing here.