Systemd Service Specification
The service unit ID comes from config.ini.system_id:
{
"system_id": "<system_id>"
}
The final system service must be:
<system_id>.service
Retained within the application installation directory:
/usr/local/<app_id>/init.d/<system_id>.service
Standard Service File:
Standard Service File (with security hardening):
[Unit]
Description=<service_description>
After=network.target
StartLimitBurst=5
StartLimitIntervalSec=60
[Service]
Type=simple
User=<appid>
Group=<appid>
WorkingDirectory=/usr/local/<appid>
ExecStart=/usr/local/<appid>/bin/<binary_name>
EnvironmentFile=/usr/local/<appid>/<appid>.env
TimeoutStartSec=30
TimeoutStopSec=10
AmbientCapabilities=CAP_NET_BIND_SERVICE
NoNewPrivileges=true
ProtectSystem=strict
ProtectHome=true
ReadWritePaths=/var/lib/<appid> /var/log/<appid>
LimitNOFILE=65536
[Install]
WantedBy=multi-user.target
Systemd Directive Reference:
| Directive | Value | Required | Description |
|---|---|---|---|
User | <appid> | ✅ Yes | Run the service as a dedicated non-root user |
Group | <appid> | ✅ Yes | Run the service with a dedicated group |
WorkingDirectory | /usr/local/<appid> | ✅ Yes | Working directory for the service |
NoNewPrivileges | true | ✅ Yes | Prevent privilege escalation |
ProtectSystem | strict | ✅ Yes | Mount /usr, /boot, /etc as read-only |
ProtectHome | true | ✅ Yes | Hide the /home directory |
TimeoutStartSec | 30 | ✅ Yes | Service startup timeout (seconds) |
TimeoutStopSec | 10 | ✅ Yes | Graceful stop timeout (seconds) |
AmbientCapabilities | CAP_NET_BIND_SERVICE | Conditional | Only needed when binding to ports below 1024 |
ReadWritePaths | /usr/local/<appid>/data /usr/local/<appid>/logs | ✅ Yes | Explicitly declare writable paths (the application's own data and log directories) |
LimitNOFILE | 65536 | Recommended | File descriptor limit |
StartLimitBurst | 5 | Optional | Maximum restart attempts within the interval (set according to your needs) |
StartLimitIntervalSec | 60 | Optional | Restart limit interval in seconds (set according to your needs) |
Restart | on-failure | Optional | When to restart the service (e.g., always, on-failure, no). The App Center executes the restart policy defined here |
RestartSec | 10 | Optional | Time to wait before restarting the service (seconds) |
Important
Developers may configure Restart= and RestartSec= in the service file according to their application's requirements. The App Center will execute the restart policy according to these developer-defined configurations. To prevent runaway crash loops, configure StartLimitBurst= and StartLimitIntervalSec= as needed.