Files
wizwar6e/deploy/wizwar.service
T
Eric WagonerandClaude Opus 5.5 811d5f84cb Wiz-War's host follows the hall's shared layout: its own Caddy site file, its own access log, a memory cap for a shared box
The host's Caddyfile gathers each game's site from /etc/caddy/sites/;
Wiz-War's is rendered from deploy/Caddyfile.tmpl and logs to
wizwar-access.log, which the rollup and the pulse read. The server's memory
cap drops from 700M to 350M (it runs in about 125M), so a runaway cannot
starve other games sharing the box. Applied on the live droplet with its
logs renamed in place.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01Jm2auWk6RP71CjaAb4FMoG
2026-09-29 12:37:06 -04:00

37 lines
1.1 KiB
Desktop File

[Unit]
Description=Wiz-War game server
After=network.target
[Service]
Type=simple
User=wizwar
WorkingDirectory=/opt/wizwar/packages/server
Environment=PORT=8787
# Caddy terminates TLS; the plaintext port must not face the internet.
Environment=HOST=127.0.0.1
Environment=WIZWAR_DATA_DIR=/var/lib/wizwar/rooms
Environment=WIZWAR_STATIC_DIR=/opt/wizwar/packages/web/dist
Environment=WIZWAR_KEEPER_TZ=America/New_York
Environment=SENTRY_DSN=https://a47ea012dff08b52dd230a95ccbe7414@o4509525984149504.ingest.us.sentry.io/4512011462049793
ExecStart=/opt/wizwar/node_modules/.bin/tsx src/index.ts
Restart=always
RestartSec=3
# Sandbox: the process reads /opt/wizwar and writes only its data dir.
NoNewPrivileges=yes
PrivateTmp=yes
ProtectSystem=strict
ProtectHome=yes
ReadWritePaths=/var/lib/wizwar
ProtectKernelTunables=yes
ProtectKernelModules=yes
ProtectControlGroups=yes
RestrictSUIDSGID=yes
# A runaway process gets killed and restarted before it can take the box, or
# the other games sharing it, down. The server runs in about 125M.
MemoryMax=350M
LimitNOFILE=4096
[Install]
WantedBy=multi-user.target