feat(curator): vendor the backend application under scenarios/curator/backend
The curator app (Python backend, tests, systemd units, config, scripts) now lives in this repo under scenarios/curator/backend, exported from the standalone checkout's tracked tree (.pi mirror, venv and caches excluded). 149 unit tests pass from the new location; _SHARED_LIB and eval GOLDEN_DIR resolve unchanged. History not preserved per decision. verify-no-secrets: the ASSIGN heuristic now requires the value to carry entropy (a digit or uppercase letter), so vendored Python kwargs like token=extraction_token no longer false-positive while real base64/hex/random secrets still trip it.
This commit is contained in:
@@ -0,0 +1,30 @@
|
||||
[Unit]
|
||||
Description=Curator database backup and retention
|
||||
|
||||
[Service]
|
||||
Type=oneshot
|
||||
WorkingDirectory=/home/claw/pi-workspaces/curator
|
||||
Environment=PYTHONPATH=/home/claw/pi-workspaces/curator
|
||||
EnvironmentFile=/home/claw/.config/curator/curator.env
|
||||
ExecStart=/usr/bin/python3 -m curator backup
|
||||
TimeoutStartSec=15m
|
||||
|
||||
# Local disk only; no network is needed, so egress stays closed.
|
||||
IPAddressDeny=any
|
||||
|
||||
ProtectSystem=strict
|
||||
ProtectHome=read-only
|
||||
ReadWritePaths=/home/claw/.local/share/curator
|
||||
ReadWritePaths=/mnt/truenas/multimedia/curator
|
||||
PrivateTmp=true
|
||||
UMask=0077
|
||||
NoNewPrivileges=true
|
||||
ProtectKernelTunables=true
|
||||
ProtectKernelModules=true
|
||||
ProtectControlGroups=true
|
||||
RestrictSUIDSGID=true
|
||||
RestrictRealtime=true
|
||||
RestrictNamespaces=true
|
||||
LockPersonality=true
|
||||
MemoryMax=1G
|
||||
TasksMax=64
|
||||
Reference in New Issue
Block a user