Skip to content

deploy: systemd template unit for declarative multi-instance - #146

Merged
dolonet merged 3 commits into
dolonet:mainfrom
gorevds:feat/instance-template-unit
Jun 26, 2026
Merged

dolonet merged 3 commits into
dolonet:mainfrom
gorevds:feat/instance-template-unit

Conversation

@gorevds

@gorevds gorevds commented Jun 12, 2026

Copy link
Copy Markdown
Collaborator

What

Running a second websh instance (per team / per environment) means hand-editing a copy of the unit today. websh@.service makes it declarative:

cp websh@.service /etc/systemd/system/
printf 'PORT=8766\n' > /etc/websh/staging.env
systemctl enable --now websh@staging
  • One env file per instance (EnvironmentFile=/etc/websh/%i.env); PORT is the only mandatory knob (instances collide on the default otherwise), anything from configuration.md can ride along.
  • Per-instance writable state via StateDirectory=websh-%i (point WEBSH_CREDS_PATH there when enabling the vault).
  • EnvironmentFile is deliberately strict (no - prefix): a missing env file fails the unit loudly instead of booting a misconfigured instance.
  • Carries the exact hardening set of websh.service (diffed line-by-line); both files now cross-reference each other so future hardening changes land in both.
  • docs/deployment.md gains a Multiple instances section.

systemd-analyze verify passes for both units (incl. an instantiated websh@x.service). The single-instance websh.service remains the default path.

gorevds and others added 3 commits June 12, 2026 20:51
Running a second websh instance (per team / per environment) meant
hand-editing a copy of the unit. websh@.service makes it declarative:

  printf 'PORT=8766\n' > /etc/websh/staging.env
  systemctl enable --now websh@staging

One env file per instance; PORT is the only mandatory knob (instances
collide on the default otherwise) and anything from configuration.md
can ride along. Each instance gets its own writable state via
StateDirectory=websh-%i. A missing env file fails the unit loudly
instead of booting a misconfigured instance.

The template carries the exact hardening set of websh.service
(verified identical line-by-line); both files now cross-reference
each other so future hardening changes land in both. systemd-analyze
verify passes for both units.
@dolonet
dolonet merged commit b7f35a4 into dolonet:main Jun 26, 2026
8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants