diff --git a/roles/archwiki/tasks/main.yml b/roles/archwiki/tasks/main.yml index 6a8a80b02d88f55faf74611e680e014693a24d8b..215f49e53a62aedb77e1ce9eadb4de939155adb1 100644 --- a/roles/archwiki/tasks/main.yml +++ b/roles/archwiki/tasks/main.yml @@ -83,12 +83,18 @@ notify: - restart php-fpm@{{ archwiki_user }} -- name: install archwiki memcached service - template: src="archwiki-memcached.service.j2" dest="/etc/systemd/system/archwiki-memcached.service" owner=root group=root mode=0644 - - name: start and enable systemd socket service: name=php-fpm@{{ archwiki_user }}.socket state=started enabled=true +- name: create memcached.service.d drop-in directory + file: path=/etc/systemd/system/memcached@archwiki.service.d state=directory owner=root group=root mode=0755 + +- name: install memcached.service drop-in + template: src="memcached.service.d-archwiki.conf.j2" dest="/etc/systemd/system/memcached@archwiki.service.d/archwiki.conf" owner=root group=root mode=0644 + +- name: start and enable memcached service + service: name=memcached@archwiki.service state=started enabled=true daemon_reload=true + - name: install systemd services/timers template: src="{{ item }}.j2" dest="/etc/systemd/system/{{ item }}" owner=root group=root mode=0644 loop: @@ -98,7 +104,6 @@ - archwiki-prune-cache.service - archwiki-prune-cache.timer - archwiki-question-updater.service - - archwiki-memcached.service - name: start and enable archwiki timers and services systemd: @@ -110,7 +115,6 @@ - archwiki-runjobs.timer - archwiki-prune-cache.timer - archwiki-runjobs-wait.service - - archwiki-memcached.service - name: create question answer file systemd: diff --git a/roles/archwiki/templates/archwiki-memcached.service.j2 b/roles/archwiki/templates/archwiki-memcached.service.j2 deleted file mode 100644 index 37c00bd852a5953f5807d06b6f6638e8a9c08ac9..0000000000000000000000000000000000000000 --- a/roles/archwiki/templates/archwiki-memcached.service.j2 +++ /dev/null @@ -1,21 +0,0 @@ -[Unit] -Description=Archwiki Memcached Daemon -After=network.target - -[Service] -User={{ archwiki_user }} -Group=memcached -ExecStart=/usr/bin/memcached -s {{ archwiki_memcached_socket }} -m {{ archwiki_memcached_memory }} -o modern -a 770 -Restart=always -NoNewPrivileges=yes -PrivateTmp=yes -ProtectHome=true -PrivateDevices=yes -ProtectSystem=full -ProtectKernelTunables=true -ProtectKernelModules=true -ProtectControlGroups=true -MemoryDenyWriteExecute=yes - -[Install] -WantedBy=multi-user.target diff --git a/roles/archwiki/templates/memcached.service.d-archwiki.conf.j2 b/roles/archwiki/templates/memcached.service.d-archwiki.conf.j2 new file mode 100644 index 0000000000000000000000000000000000000000..50acbb88aafc18fa5b6cbdb92f6cfeda5dc3a191 --- /dev/null +++ b/roles/archwiki/templates/memcached.service.d-archwiki.conf.j2 @@ -0,0 +1,6 @@ +[Service] +User={{ archwiki_user }} +Group=memcached +Environment=CACHESIZE={{ archwiki_memcached_memory }} +Environment=LISTEN="-s {{ archwiki_memcached_socket }} -a 770" +ProtectHome=true