[Unit] Description=anchorage IPFS Pinning Service Documentation=https://git.anomalous.dev/alphacentri/anchorage Wants=network-online.target After=network.target network-online.target postgresql.service ipfs.service [Service] Type=simple User=anchorage Group=anchorage WorkingDirectory=/etc/anchorage LimitNOFILE=65536 ExecStart=/usr/bin/anchorage serve --config /etc/anchorage/anchorage.yaml Restart=on-failure RestartSec=5 StartLimitInterval=60 StartLimitBurst=3 # Security hardening — anchorage is a pure-Go HTTP/NATS daemon, no # special capabilities required. The writable paths are the state dir # (node.id, NATS JetStream data) and the log dir. ProtectSystem=strict ProtectHome=true PrivateTmp=true PrivateDevices=true ProtectKernelTunables=true ProtectKernelModules=true ProtectControlGroups=true RestrictSUIDSGID=true LockPersonality=true NoNewPrivileges=true RestrictRealtime=true RestrictNamespaces=true MemoryDenyWriteExecute=true SystemCallArchitectures=native SystemCallFilter=@system-service SystemCallFilter=~@privileged @resources @mount @debug ReadWritePaths=/var/lib/anchorage /var/log/anchorage # Allow binding to ports < 1024 (e.g. :443 behind a reverse proxy terminator). AmbientCapabilities=CAP_NET_BIND_SERVICE CapabilityBoundingSet=CAP_NET_BIND_SERVICE [Install] WantedBy=multi-user.target