diff options
| author | Ben Sima <ben@bensima.com> | 2026-05-21 13:09:59 -0400 |
|---|---|---|
| committer | Ben Sima <ben@bensima.com> | 2026-05-21 13:09:59 -0400 |
| commit | 12dd309b8e334eaf19eae6d9eb9bb85024457b8a (patch) | |
| tree | cec44a34b39a4e33341fe9a6af92c3aba43019ec /slopbot.service | |
| parent | 6992c311c1b2289f17f2591f9fe0ad44f3fb549e (diff) | |
Convert to nix flake; fix systemd service to use nix run
- Add flake.nix with nixos-unstable nixpkgs, devShell and slopbot package
- Add flake.lock
- Update .envrc to 'use flake .'
- Update slopbot.service: use 'nix run' instead of nix-shell, remove
broken sandbox options (ProtectHome, InaccessiblePaths, ProtectSystem,
ReadOnlyPaths, ReadWritePaths, PrivateTmp) that block nix store access
- Delete shell.nix
- Add 'result' to .gitignore
- Restore openai to requirements.txt (was accidentally dropped)
Diffstat (limited to 'slopbot.service')
| -rw-r--r-- | slopbot.service | 29 |
1 files changed, 29 insertions, 0 deletions
diff --git a/slopbot.service b/slopbot.service new file mode 100644 index 0000000..396e9d0 --- /dev/null +++ b/slopbot.service @@ -0,0 +1,29 @@ +[Unit] +Description=slopbot Zulip bot +After=network-online.target +Wants=network-online.target + +[Service] +Type=simple +WorkingDirectory=/home/ben/src/bsima/slopbot +EnvironmentFile=-/home/ben/src/bsima/slopbot/.env +ExecStart=/run/current-system/sw/bin/nix --extra-experimental-features 'nix-command flakes' run /home/ben/src/bsima/slopbot#slopbot +Restart=on-failure +RestartSec=5 + +NoNewPrivileges=true +CapabilityBoundingSet= +LockPersonality=true +PrivateDevices=true +ProtectClock=true +ProtectControlGroups=true +ProtectKernelLogs=true +ProtectKernelModules=true +ProtectKernelTunables=true +RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 +RestrictNamespaces=true +RestrictRealtime=true +SystemCallArchitectures=native + +[Install] +WantedBy=multi-user.target |
