agama/rust/share/agama-web-server.service
Ladislav Slezák 8ff52c8717
Use inst.remote=0 for disabling the remote access to Agama (#3336)
## Problem

- Using the new `inst.listen_on` boot option to disable remote access to
the server looks inconsistent (for disabling the SSH access you can use
the `systemd.mask=sshd.service` boot option)
- Simplify the implementation, limiting access to some interface or IP
address was not requested
- Related to https://github.com/agama-project/agama/pull/3269

## Solution

- Use systemd services to implement disabling the remote access
- ~~Implement new `agama-web-server-local` and `agama-web-server-remote`
services~~
- ~~By default the remote service is enabled, but the user can disable
it and enable the local service instead using the
`systemd.mask=agama-web-server-remote.service
systemd.wants=agama-web-server-local.service` boot parameters.~~
- Support new `inst.remote=0` boot option

## Testing

- Tested manually

## Notes

I tried several approaches but either they did not work or were a bit
hacky:

1. First a wanted to be the both local and remote services enabled by
default. Because of conflicts only one of them should be running at a
time. I used `Before` and `After` so the remote service starts first and
the conflict should block the local service from running. Disabling the
remote service allows running the local service automatically.
The problem was that there is probably some race condition and sometimes
the local service was actually running instead of the remote by default.
I tried several changes but nothing helped.
2. Then I added code to the local service to explicitly check whether
the remote service is disabled or not (using `ExecCondition` attribute).
But that feels a bit hacky and it is a hidden magic.
3. Then I realized that the same way how you can disable a service at
boot using `systemd.mask` option you can also enable a disabled service
using the `systemd.wants` parameter. So instead of enabling both
services enable only the default remote one. The users then can
explicitly disable the remote service and enable the local one using the
`systemd.mask=agama-web-server-remote.service
systemd.wants=agama-web-server-local.service` boot options. But that
turned out to be quite complicated.
4. So let's implement simple `inst.remote=0` boot option which disables
the remotes access to the Agama installer. The SSH service can be
disabled using the standard `systemd.mask=sshd.service` option.
2026-04-13 17:10:54 +02:00

19 lines
822 B
Desktop File

[Unit]
Description=Agama Web Server
# agama-hostname might change the host name which is used when creating
# a self signed certificate, run it before the web server
After=network-online.target agama.service agama-hostname.service
BindsTo=agama.service
[Service]
EnvironmentFile=-/run/agama/environment.conf
Environment="AGAMA_LOG=debug,zbus=info"
Type=notify
# listen only on the loopback interface if the inst.remote=0 boot option is set
ExecStart=/usr/bin/bash -c "grep -q '\\binst.remote=0\\b' /run/agama/cmdline.d/agama.conf && exec /usr/bin/agama-web-server serve --address ::1:80,127.0.0.1:80 --address ::1:443,127.0.0.1:443 || exec /usr/bin/agama-web-server serve --address :::80,0.0.0.0:80 --address :::443,0.0.0.0:443"
PIDFile=/run/agama/web.pid
User=root
TimeoutStopSec=5
[Install]
WantedBy=multi-user.target