From bde87fe82383ae67e1d4122e6844b9463c51eb70 Mon Sep 17 00:00:00 2001 From: Michael Engel Date: Thu, 30 Jul 2026 15:14:34 +0200 Subject: [PATCH] refactor(rpm): Moved openshell-gateway.service from RPM to dedicated file The inline heredocs in the `openshell.spec` is hard to lint, diff, and edit. Therefore, moving it into a dedicated file so it gets proper syntax highlighting, can be validated by `systemd-analyze verify` and is easier to review in isolation. This also aligns with the .deb packaging. Signed-off-by: Michael Engel --- deploy/rpm/openshell-gateway.service | 45 ++++++++++++++++++++++++++ openshell.spec | 48 +--------------------------- 2 files changed, 46 insertions(+), 47 deletions(-) create mode 100644 deploy/rpm/openshell-gateway.service diff --git a/deploy/rpm/openshell-gateway.service b/deploy/rpm/openshell-gateway.service new file mode 100644 index 0000000000..8dd665313d --- /dev/null +++ b/deploy/rpm/openshell-gateway.service @@ -0,0 +1,45 @@ +[Unit] +Description=OpenShell Gateway (user) +Documentation=https://github.com/NVIDIA/OpenShell +After=podman.socket +Wants=podman.socket + +[Service] +Type=exec +# On first start the unit seeds a default TOML config and generates PKI. +# Client certs are placed in ~/.config/openshell/gateways/openshell/mtls/ so +# the CLI discovers them automatically. +# See /usr/share/doc/openshell-gateway/ for details. + +# Seed a default TOML config on first start. On upgrade, replace only the exact +# schema-v1 config previously seeded by this package; preserve edited files. +# %%E expands to $XDG_CONFIG_HOME (~/.config) in user units. +ExecStartPre=%{_libexecdir}/%{name}-gateway-migrate-config %%E/openshell/gateway.toml /usr/share/openshell-gateway/gateway.toml.default /usr/share/openshell-gateway/gateway.toml.default.v1 + +# Reject an invalid selected configuration before generating certificates or +# starting the gateway. The environment file below applies to every command. +ExecStartPre=/usr/bin/openshell-gateway config preflight + +# Auto-generate PKI on first start if not present. +# The default local TLS dir uses %%h because %%S resolves differently across +# systemd user-manager versions. gateway.env may override this path. +Environment=OPENSHELL_LOCAL_TLS_DIR=%%h/.local/state/openshell/tls +ExecStartPre=/usr/bin/openshell-gateway generate-certs --output-dir ${OPENSHELL_LOCAL_TLS_DIR} --server-san host.openshell.internal + +# gateway.env is honored for backward compatibility with pre-1415 installs. +# New installs use runtime defaults; create gateway.toml to override. +# See TROUBLESHOOTING.md for the env-to-TOML migration guide. +EnvironmentFile=-%%E/openshell/gateway.env +ExecStart=/usr/bin/openshell-gateway +StateDirectory=openshell +Restart=on-failure +RestartSec=5 + +# Security hardening +NoNewPrivileges=yes +ProtectSystem=strict +PrivateTmp=yes +RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX + +[Install] +WantedBy=default.target diff --git a/openshell.spec b/openshell.spec index ee9d7d5f5a..6f62518cef 100644 --- a/openshell.spec +++ b/openshell.spec @@ -129,53 +129,7 @@ install -Dpm 0755 deploy/rpm/migrate-gateway-config.sh %{buildroot}%{_libexecdir # Installed to the systemd user unit directory so any user can run: # systemctl --user enable --now openshell-gateway.service install -d %{buildroot}%{_userunitdir} -cat > %{buildroot}%{_userunitdir}/%{name}-gateway.service << 'EOF' -[Unit] -Description=OpenShell Gateway (user) -Documentation=https://github.com/NVIDIA/OpenShell -After=podman.socket -Wants=podman.socket - -[Service] -Type=exec -# On first start the unit seeds a default TOML config and generates PKI. -# Client certs are placed in ~/.config/openshell/gateways/openshell/mtls/ so -# the CLI discovers them automatically. -# See /usr/share/doc/openshell-gateway/ for details. - -# Seed a default TOML config on first start. On upgrade, replace only the exact -# schema-v1 config previously seeded by this package; preserve edited files. -# %%E expands to $XDG_CONFIG_HOME (~/.config) in user units. -ExecStartPre=%{_libexecdir}/%{name}-gateway-migrate-config %%E/openshell/gateway.toml /usr/share/openshell-gateway/gateway.toml.default /usr/share/openshell-gateway/gateway.toml.default.v1 - -# Reject an invalid selected configuration before generating certificates or -# starting the gateway. The environment file below applies to every command. -ExecStartPre=/usr/bin/openshell-gateway config preflight - -# Auto-generate PKI on first start if not present. -# The default local TLS dir uses %%h because %%S resolves differently across -# systemd user-manager versions. gateway.env may override this path. -Environment=OPENSHELL_LOCAL_TLS_DIR=%%h/.local/state/openshell/tls -ExecStartPre=/usr/bin/openshell-gateway generate-certs --output-dir ${OPENSHELL_LOCAL_TLS_DIR} --server-san host.openshell.internal - -# gateway.env is honored for backward compatibility with pre-1415 installs. -# New installs use runtime defaults; create gateway.toml to override. -# See TROUBLESHOOTING.md for the env-to-TOML migration guide. -EnvironmentFile=-%%E/openshell/gateway.env -ExecStart=/usr/bin/openshell-gateway -StateDirectory=openshell -Restart=on-failure -RestartSec=5 - -# Security hardening -NoNewPrivileges=yes -ProtectSystem=strict -PrivateTmp=yes -RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX - -[Install] -WantedBy=default.target -EOF +install -Dpm 0644 deploy/rpm/%{name}-gateway.service %{buildroot}%{_userunitdir}/%{name}-gateway.service # --- Gateway documentation --- install -d %{buildroot}%{_docdir}/%{name}-gateway