update(scripts): multiple renamings to falcoctl service + fixed description.

Moreover, now falcoctl service is enabled by default. It being bound to falco.target
allows us to avoid it running when falco.target is not running.

Signed-off-by: Federico Di Pierro <nierro92@gmail.com>
This commit is contained in:
Federico Di Pierro
2023-01-19 16:30:37 +01:00
committed by poiana
parent 2591ed4d68
commit 0f22fde7cd
8 changed files with 50 additions and 58 deletions

View File

@@ -0,0 +1,23 @@
[Unit]
Description=Falcoctl Artifact Follow: automatic artifacts update service
Documentation=https://falco.org/docs/
After=falco.target
BindsTo=falco.target
[Service]
Type=simple
User=root
ExecStart=/usr/bin/falcoctl artifact follow
UMask=0077
TimeoutSec=30
RestartSec=15s
Restart=on-failure
PrivateTmp=true
NoNewPrivileges=yes
ProtectSystem=true
ProtectKernelTunables=true
RestrictRealtime=true
StandardOutput=null
[Install]
WantedBy=multi-user.target