mirror of
https://github.com/go-gost/gost.git
synced 2026-10-08 03:55:45 +00:00
Add DEB and RPM packages for easier installation (#906)
* Add systemd service file * Add DEB and RPM packages for amd64, amd64v3 and arm64 architectures * Remove GOMEMLIMIT from systemd service * Fix packaged systemd service defaults
This commit is contained in:
+48
-4
@@ -1,3 +1,5 @@
|
|||||||
|
version: 2
|
||||||
|
|
||||||
# This is an example .goreleaser.yml file with some sensible defaults.
|
# This is an example .goreleaser.yml file with some sensible defaults.
|
||||||
# Make sure to check the documentation at https://goreleaser.com
|
# Make sure to check the documentation at https://goreleaser.com
|
||||||
before:
|
before:
|
||||||
@@ -7,7 +9,8 @@ before:
|
|||||||
# you may remove this if you don't need go generate
|
# you may remove this if you don't need go generate
|
||||||
# - go generate ./...
|
# - go generate ./...
|
||||||
builds:
|
builds:
|
||||||
- env:
|
- id: gost
|
||||||
|
env:
|
||||||
- CGO_ENABLED=0
|
- CGO_ENABLED=0
|
||||||
main: ./cmd/gost
|
main: ./cmd/gost
|
||||||
targets:
|
targets:
|
||||||
@@ -38,6 +41,16 @@ builds:
|
|||||||
- android_arm64
|
- android_arm64
|
||||||
ldflags:
|
ldflags:
|
||||||
- "-s -w -X 'main.version={{ .Tag }}'"
|
- "-s -w -X 'main.version={{ .Tag }}'"
|
||||||
|
- id: gost-packages
|
||||||
|
env:
|
||||||
|
- CGO_ENABLED=0
|
||||||
|
main: ./cmd/gost
|
||||||
|
targets:
|
||||||
|
- linux_amd64
|
||||||
|
- linux_amd64_v3
|
||||||
|
- linux_arm64
|
||||||
|
ldflags:
|
||||||
|
- "-s -w -X 'main.version={{ .Tag }}'"
|
||||||
|
|
||||||
upx:
|
upx:
|
||||||
- # UPX compression. Disabled by default (see #863): upx --best/--lzma/--brute
|
- # UPX compression. Disabled by default (see #863): upx --best/--lzma/--brute
|
||||||
@@ -46,18 +59,49 @@ upx:
|
|||||||
enabled: false
|
enabled: false
|
||||||
|
|
||||||
archives:
|
archives:
|
||||||
- format: tar.gz
|
- ids:
|
||||||
|
- gost
|
||||||
|
formats:
|
||||||
|
- tar.gz
|
||||||
builds_info:
|
builds_info:
|
||||||
group: root
|
group: root
|
||||||
owner: root
|
owner: root
|
||||||
# use zip for windows archives
|
# use zip for windows archives
|
||||||
format_overrides:
|
format_overrides:
|
||||||
- goos: windows
|
- goos: windows
|
||||||
format: zip
|
formats:
|
||||||
|
- zip
|
||||||
|
|
||||||
|
nfpms:
|
||||||
|
- id: packages
|
||||||
|
package_name: gost
|
||||||
|
ids:
|
||||||
|
- gost-packages
|
||||||
|
vendor: go-gost
|
||||||
|
homepage: https://gost.run/
|
||||||
|
maintainer: go-gost contributors
|
||||||
|
description: GO Simple Tunnel
|
||||||
|
license: MIT
|
||||||
|
formats:
|
||||||
|
- deb
|
||||||
|
- rpm
|
||||||
|
bindir: /usr/bin
|
||||||
|
contents:
|
||||||
|
- src: gost.service
|
||||||
|
dst: /usr/lib/systemd/system/gost.service
|
||||||
|
- src: README.md
|
||||||
|
dst: /usr/share/doc/gost/README.md
|
||||||
|
- src: README_en.md
|
||||||
|
dst: /usr/share/doc/gost/README_en.md
|
||||||
|
- src: LICENSE
|
||||||
|
dst: /usr/share/doc/gost/LICENSE
|
||||||
|
- src: gost.yml
|
||||||
|
dst: /usr/share/doc/gost/examples/gost.yml
|
||||||
|
|
||||||
checksum:
|
checksum:
|
||||||
name_template: 'checksums.txt'
|
name_template: 'checksums.txt'
|
||||||
snapshot:
|
snapshot:
|
||||||
name_template: "{{ incpatch .Version }}-next"
|
version_template: "{{ incpatch .Version }}-next"
|
||||||
changelog:
|
changelog:
|
||||||
sort: asc
|
sort: asc
|
||||||
filters:
|
filters:
|
||||||
|
|||||||
@@ -0,0 +1,43 @@
|
|||||||
|
[Unit]
|
||||||
|
Description=GO Simple Tunnel
|
||||||
|
Documentation=https://gost.run/
|
||||||
|
After=network-online.target nss-lookup.target
|
||||||
|
ConditionPathExists=/etc/gost/gost.yml
|
||||||
|
|
||||||
|
[Service]
|
||||||
|
Type=simple
|
||||||
|
WorkingDirectory=/run/gost
|
||||||
|
ExecStart=/usr/bin/gost -C /etc/gost/gost.yml
|
||||||
|
ExecReload=/bin/kill -SIGHUP $MAINPID
|
||||||
|
|
||||||
|
User=nobody
|
||||||
|
RuntimeDirectory=gost
|
||||||
|
LogsDirectory=gost
|
||||||
|
TimeoutStopSec=5s
|
||||||
|
Restart=on-failure
|
||||||
|
RestartSec=1s
|
||||||
|
|
||||||
|
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
|
||||||
|
|
||||||
|
PrivateTmp=yes
|
||||||
|
PrivateDevices=no
|
||||||
|
ProtectSystem=full
|
||||||
|
ProtectHostname=yes
|
||||||
|
ProtectHome=yes
|
||||||
|
ProtectKernelTunables=yes
|
||||||
|
ProtectKernelLogs=yes
|
||||||
|
ProtectKernelModules=yes
|
||||||
|
ProtectControlGroups=yes
|
||||||
|
ProtectClock=yes
|
||||||
|
MemoryDenyWriteExecute=yes
|
||||||
|
NoNewPrivileges=yes
|
||||||
|
|
||||||
|
SystemCallFilter=~@mount @debug @cpu-emulation @obsolete
|
||||||
|
SystemCallErrorNumber=EPERM
|
||||||
|
SystemCallArchitectures=native
|
||||||
|
RestrictNamespaces=yes
|
||||||
|
RestrictSUIDSGID=yes
|
||||||
|
LockPersonality=yes
|
||||||
|
|
||||||
|
[Install]
|
||||||
|
WantedBy=multi-user.target
|
||||||
Reference in New Issue
Block a user