mirror of
https://github.com/anand34577/ferrum.git
synced 2026-09-11 21:38:59 +00:00
7d3a1fa134
- .gitignore/.dockerignore: cover Go build artifacts, env files, logs, editor/OS cruft, and local runtime data (sqlite db/secret, config.yaml). - README: add a Screenshots section (captured against a mock Proxmox cluster) and a Deploying a release build section. - LICENSE: MIT. Deployable binaries: - cmd/ferrum: -version flag with build-time version/commit/date via -ldflags; -log-file flag (Windows services don't capture stdout/stderr the way systemd does); native Windows Service Control Manager support (service_windows.go) so ferrum.exe manages its own start/stop lifecycle under a Windows service, same graceful-shutdown path SIGTERM already used on Linux. - packaging/systemd/ferrum.service: hardened systemd unit. - scripts/build.sh, build.ps1: cross-compile linux/windows/darwin x amd64/arm64, package as .tar.gz/.zip with an install script and checksums.txt. - scripts/linux/install.sh, uninstall.sh: create a dedicated system user, install the binary, seed /etc/ferrum/config.yaml, enable + start the systemd service. - scripts/get.sh: one-line curl-pipeable installer (get.docker.com style) that resolves the latest release, verifies its checksum, and hands off to install.sh. - scripts/windows/install-service.ps1, uninstall-service.ps1: register/ remove the self-managing Windows service. - .github/workflows/release.yml: publish all platform archives + checksums as GitHub Release assets on a vX.Y.Z tag push. - .github/workflows/ci.yml: go vet/build/test, frontend lint/test/build, and shell-script syntax checks on push/PR.
32 lines
826 B
Desktop File
32 lines
826 B
Desktop File
[Unit]
|
|
Description=Ferrum — Proxmox VE fleet control
|
|
Documentation=https://github.com/anand34577/ferrum
|
|
After=network-online.target
|
|
Wants=network-online.target
|
|
|
|
[Service]
|
|
Type=simple
|
|
User=ferrum
|
|
Group=ferrum
|
|
ExecStart=/usr/local/bin/ferrum -config /etc/ferrum/config.yaml
|
|
WorkingDirectory=/var/lib/ferrum
|
|
Restart=on-failure
|
|
RestartSec=5s
|
|
|
|
# SIGTERM triggers the graceful shutdown path in cmd/ferrum/main.go
|
|
# (10s HTTP drain); give systemd a little more room than that before SIGKILL.
|
|
TimeoutStopSec=20s
|
|
|
|
# Hardening. Ferrum only needs to read its config and its own data
|
|
# directory, and to make outbound HTTPS calls to Proxmox hosts.
|
|
NoNewPrivileges=true
|
|
PrivateTmp=true
|
|
ProtectSystem=strict
|
|
ProtectHome=true
|
|
ReadWritePaths=/var/lib/ferrum
|
|
CapabilityBoundingSet=
|
|
AmbientCapabilities=
|
|
|
|
[Install]
|
|
WantedBy=multi-user.target
|