burp-client: Switch from cron to systemd timer

systemd timer units are supported on all relevant OS versions now.
There is no longer any reason to use cron.
This commit is contained in:
2023-04-06 22:49:49 -05:00
parent cd1f7b354b
commit 66d0a9157f
7 changed files with 64 additions and 9 deletions

View File

@@ -0,0 +1,27 @@
# vim: set ft=systemd :
[Unit]
Description=BURP client
After=network-online.target
Wants=network-online.target
[Service]
Type=exec
ExecStart=/usr/sbin/burp -a t -Q
SuccessExitStatus=3
CapabilityBoundingSet=CAP_BLOCK_SUSPEND CAP_DAC_OVERRIDE CAP_DAC_READ_SEARCH
CapabilityBoundingSet=CAP_FOWNER CAP_LEASE CAP_SETGID CAP_SETUID
NoNewPrivileges=yes
PrivateDevices=yes
PrivateTmp=yes
ProcSubset=pid
ProtectClock=yes
ProtectControlGroups=yes
ProtectHostname=yes
ProtectKernelLogs=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
ProtectProc=noaccess
ProtectSystem=full
SystemCallArchitectures=native
SystemCallFilter=@system-service @privileged @mount
SystemCallFilter=~@clock @debug @module @reboot @swap