- Makefile:web / sync-assets(go:embed 约束拷贝)/ build / linux / test / smoke / dev / vulncheck;版本信息 ldflags 注入 - scripts/smoke.sh:构建冒烟(§8.3-6)——起服务断言 SPA 资源 200 + 正确 MIME、meta 注入、安全头、私有不可见(19 项断言) - deploy:pure-note.service(沙箱加固)、每日 gc+backup 的 maint service/timer(03:00 Persistent)、Caddyfile 反代示例 - docs/decisions.md:35 条实施决策留档(D1–D35) - docs/acceptance.md:§9.3 检查单逐项证据、§13 测试组映射、 §12 里程碑门、浏览器端到端走查记录 - README.md:快速开始、测试、部署与升级/恢复 SOP
27 lines
627 B
Desktop File
27 lines
627 B
Desktop File
# /etc/systemd/system/pure-note.service
|
||
[Unit]
|
||
Description=Pure Note - minimalist high-security private notes + blog
|
||
After=network.target
|
||
|
||
[Service]
|
||
User=purenote
|
||
WorkingDirectory=/opt/pure-note
|
||
ExecStart=/opt/pure-note/pure-note serve --addr 127.0.0.1:8080 \
|
||
--data-dir /opt/pure-note/data --behind-proxy
|
||
Restart=on-failure
|
||
RestartSec=5
|
||
|
||
# 沙箱加固(§10.2)
|
||
NoNewPrivileges=true
|
||
PrivateTmp=true
|
||
ProtectSystem=strict
|
||
ProtectHome=true
|
||
ReadWritePaths=/opt/pure-note/data
|
||
MemoryDenyWriteExecute=true
|
||
ProtectKernelTunables=true
|
||
ProtectControlGroups=true
|
||
RestrictSUIDSGID=true
|
||
|
||
[Install]
|
||
WantedBy=multi-user.target
|