diff --git a/roles/aurweb/templates/aurweb-aurblup.service.j2 b/roles/aurweb/templates/aurweb-aurblup.service.j2 index b409792866a30450044148f9b0e6fff856df5b3d..2f0452c15799373b7a8e196a275c328222195c78 100644 --- a/roles/aurweb/templates/aurweb-aurblup.service.j2 +++ b/roles/aurweb/templates/aurweb-aurblup.service.j2 @@ -6,7 +6,8 @@ After=mysqld.service [Service] Type=oneshot User={{ aurweb_user }} -ExecStart=/usr/local/bin/aurweb-aurblup +WorkingDirectory={{ aurweb_dir }} +ExecStart=/usr/bin/poetry run aurweb-aurblup ReadWritePaths={{ aurweb_dir }} NoNewPrivileges=true diff --git a/roles/aurweb/templates/aurweb-mkpkglists.service.j2 b/roles/aurweb/templates/aurweb-mkpkglists.service.j2 index a205d02c0298a0849930234405e496a317856d9e..50b25756e4a5ae2614d3f0e04868c4251fdd278a 100644 --- a/roles/aurweb/templates/aurweb-mkpkglists.service.j2 +++ b/roles/aurweb/templates/aurweb-mkpkglists.service.j2 @@ -6,7 +6,8 @@ After=mysqld.service [Service] Type=oneshot User={{ aurweb_user }} -ExecStart=/usr/local/bin/aurweb-mkpkglists --extended +WorkingDirectory={{ aurweb_dir }} +ExecStart=/usr/bin/poetry run aurweb-mkpkglists --extended NoNewPrivileges=true LockPersonality=true diff --git a/roles/aurweb/templates/aurweb-pkgmaint.service.j2 b/roles/aurweb/templates/aurweb-pkgmaint.service.j2 index 1c1ca12fd6a674d710e133734a1e5e3a3353ffa2..7db71c195bddb5ba9f08cbb2885a4c4bfb3aefe0 100644 --- a/roles/aurweb/templates/aurweb-pkgmaint.service.j2 +++ b/roles/aurweb/templates/aurweb-pkgmaint.service.j2 @@ -6,7 +6,8 @@ After=mysqld.service [Service] Type=oneshot User={{ aurweb_user }} -ExecStart=/usr/local/bin/aurweb-pkgmaint +WorkingDirectory={{ aurweb_dir }} +ExecStart=/usr/bin/poetry run aurweb-pkgmaint NoNewPrivileges=true LockPersonality=true diff --git a/roles/aurweb/templates/aurweb-popupdate.service.j2 b/roles/aurweb/templates/aurweb-popupdate.service.j2 index 99e3aa6abdad66b7bc6936cbcaa089670ebb99e6..346c13b0162e1db97a466ad301ce69d909d4722c 100644 --- a/roles/aurweb/templates/aurweb-popupdate.service.j2 +++ b/roles/aurweb/templates/aurweb-popupdate.service.j2 @@ -6,7 +6,8 @@ After=mysqld.service [Service] Type=oneshot User={{ aurweb_user }} -ExecStart=/usr/local/bin/aurweb-popupdate +WorkingDirectory={{ aurweb_dir }} +ExecStart=/usr/bin/poetry run aurweb-popupdate NoNewPrivileges=true LockPersonality=true diff --git a/roles/aurweb/templates/aurweb-tuvotereminder.service.j2 b/roles/aurweb/templates/aurweb-tuvotereminder.service.j2 index 3497e651585804795855943ec82708806ae2d1ca..f7510a8687ffb0c0a6084b4e8ac3d0361500c7e8 100644 --- a/roles/aurweb/templates/aurweb-tuvotereminder.service.j2 +++ b/roles/aurweb/templates/aurweb-tuvotereminder.service.j2 @@ -6,7 +6,8 @@ After=mysqld.service [Service] Type=oneshot User={{ aurweb_user }} -ExecStart=/usr/local/bin/aurweb-tuvotereminder +WorkingDirectory={{ aurweb_dir }} +ExecStart=/usr/bin/poetry run aurweb-tuvotereminder NoNewPrivileges=true LockPersonality=true diff --git a/roles/aurweb/templates/aurweb-usermaint.service.j2 b/roles/aurweb/templates/aurweb-usermaint.service.j2 index f5691a414bbd624b1f6d966eca685297ec3b7098..46dd3c3bf82d86ac0c1835eadd87e39eb92e0e70 100644 --- a/roles/aurweb/templates/aurweb-usermaint.service.j2 +++ b/roles/aurweb/templates/aurweb-usermaint.service.j2 @@ -6,7 +6,8 @@ After=mysqld.service [Service] Type=oneshot User={{ aurweb_user }} -ExecStart=/usr/local/bin/aurweb-usermaint +WorkingDirectory={{ aurweb_dir }} +ExecStart=/usr/bin/poetry run aurweb-usermaint NoNewPrivileges=true LockPersonality=true