[Unit] Description=Continuous deployment webhook receiver (adnanh/webhook) Documentation=https://github.com/adnanh/webhook After=network-online.target Wants=network-online.target [Service] Type=simple # Placeholders are substituted by install/install.sh from targets.json. # -hotreload picks up a re-rendered hooks file without a restart, so adding an # environment is `cd-render-hooks` and nothing else. # -nopanic keeps the daemon alive if the hooks file is momentarily unreadable # mid-write rather than exiting and taking every other target down with it. ExecStart=@WEBHOOK_BIN@ \ -hooks @HOOKS_FILE@ \ -ip @BIND@ \ -port @PORT@ \ -hotreload \ -nopanic Restart=on-failure RestartSec=5s # The deploy itself is a child process that talks to the user's Docker socket, # so this stays deliberately unsandboxed apart from the cheap wins below. NoNewPrivileges=yes PrivateTmp=yes ProtectControlGroups=yes ProtectKernelTunables=yes [Install] WantedBy=default.target