mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-09-30 12:39:42 +02:00
chore(service): sync codeman-web.service template with the deployed unit
Reconcile scripts/codeman-web.service with the installed ~/.config/systemd/user/codeman-web.service so they're identical: carry the loopback + `tailscale serve` security note, keep NODE_COMPILE_CACHE, and a concise CODEMAN_GESTURE comment. Points at docs/security-architecture.md. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -12,10 +12,14 @@ KillMode=process
|
||||
Environment=NODE_ENV=production
|
||||
Environment=HOME=/home/arkon
|
||||
Environment=NODE_COMPILE_CACHE=/home/arkon/.codeman/compile-cache
|
||||
# Make the gesture-control overlay AVAILABLE (CSP widening + /gesture/ assets +
|
||||
# window.__codemanGestureAvailable). The actual on/off stays the per-user
|
||||
# `gestureControlEnabled` toggle in App Settings → Display → Input (default OFF).
|
||||
# Loopback bind (default, no --host) + no password: safe out of the box. Hooks
|
||||
# reach 127.0.0.1, and `tailscale serve` fronts it on the tailnet only (real
|
||||
# cert, no LAN exposure, no app login). To expose on the LAN instead, add
|
||||
# Environment=CODEMAN_HOST=0.0.0.0 + Environment=CODEMAN_PASSWORD=... .
|
||||
# See docs/security-architecture.md.
|
||||
Environment=CODEMAN_GESTURE=1
|
||||
# ^ Makes the gesture-control overlay AVAILABLE (CSP widening + /gesture/ assets);
|
||||
# the actual on/off stays the per-user App Settings toggle (default OFF).
|
||||
|
||||
# Logging
|
||||
StandardOutput=journal
|
||||
|
||||
Reference in New Issue
Block a user