Systemctl : Créer un fichier sécurisé pour les clés API

De www.yakakliker.org

Objectif : Créer un fichier avec les clés API pour ne pas les afficher en clair dans le fichier systemctl

  • Créer un dossier dédié pour stocker la ou les fichiers contenant les clés. (Exemple : .auth)
    • mkdir .auth
  • Modification des droits sur le dossier
    • chmod 700 .auth
  • Créer le fichier. (Exemple : api-key)
    • touch api-key
  • Modification des droits sur le fichier
    • chmod 600 /.auth/api-key

Exemple de contenu du fichier monservice.service

[Unit]
Description=monservice
After=network.target
StartLimitIntervalSec=10min
StartLimitBurst=5



		‎<html>
<a href="https://www.compteurdevisite.com" title="compteur web gratuit sans pub"><img src="https://counter6.optistats.ovh/private/compteurdevisite.php?c=b4epghealnwlf7wuq7gn3ygll9aywrfx" border="0" title="compteur web gratuit sans pub" alt="compteur web gratuit sans pub"></a>
		‎</html>

‎		<html>
<script src='https://storage.ko-fi.com/cdn/scripts/overlay-widget.js'></script>
<script>
  kofiWidgetOverlay.draw('yakakliker', {
    'type': 'floating-chat',
    'floating-chat.donateButton.text': 'Café',
    'floating-chat.donateButton.background-color': '#00b9fe',
    'floating-chat.donateButton.text-color': '#fff'
  });
</script>
		‎</html>


[Service]
Type=simple
User=monservice
WorkingDirectory=/home/monservice
Environment=PYTHONUNBUFFERED=1
EnvironmentFile=/home/monservice/.auth/api-key
ExecStart=/home/monservice/.pyenv/versions/monservice/bin/python -m monservice.app

StandardOutput=append:/home/monservice/logs/monservice.log
StandardError=append:/home/monservice/logs/monservice_error.log

Restart=on-failure
RestartSec=10

[Install]
WantedBy=multi-user.target