From 8453e953fdfbe3cf84fe280f13b27eb40a80bb85 Mon Sep 17 00:00:00 2001 From: arkon Date: Mon, 8 Jun 2026 19:34:36 +0200 Subject: [PATCH] chore(service): sync codeman-web.service template with the deployed unit Reconcile scripts/codeman-web.service with the installed ~/.config/systemd/user/codeman-web.service so they're identical: carry the loopback + `tailscale serve` security note, keep NODE_COMPILE_CACHE, and a concise CODEMAN_GESTURE comment. Points at docs/security-architecture.md. Co-Authored-By: Claude Opus 4.8 (1M context) --- scripts/codeman-web.service | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/scripts/codeman-web.service b/scripts/codeman-web.service index 7a401609..334922eb 100644 --- a/scripts/codeman-web.service +++ b/scripts/codeman-web.service @@ -12,10 +12,14 @@ KillMode=process Environment=NODE_ENV=production Environment=HOME=/home/arkon Environment=NODE_COMPILE_CACHE=/home/arkon/.codeman/compile-cache -# Make the gesture-control overlay AVAILABLE (CSP widening + /gesture/ assets + -# window.__codemanGestureAvailable). The actual on/off stays the per-user -# `gestureControlEnabled` toggle in App Settings → Display → Input (default OFF). +# Loopback bind (default, no --host) + no password: safe out of the box. Hooks +# reach 127.0.0.1, and `tailscale serve` fronts it on the tailnet only (real +# cert, no LAN exposure, no app login). To expose on the LAN instead, add +# Environment=CODEMAN_HOST=0.0.0.0 + Environment=CODEMAN_PASSWORD=... . +# See docs/security-architecture.md. Environment=CODEMAN_GESTURE=1 +# ^ Makes the gesture-control overlay AVAILABLE (CSP widening + /gesture/ assets); +# the actual on/off stays the per-user App Settings toggle (default OFF). # Logging StandardOutput=journal