Add DEB and RPM packages for easier installation (#906)

* Add systemd service file

* Add DEB and RPM packages for amd64, amd64v3 and arm64 architectures

* Remove GOMEMLIMIT from systemd service

* Fix packaged systemd service defaults
This commit is contained in:
iBug
2026-09-21 21:01:26 +08:00
committed by GitHub
parent ece7770ad7
commit 2a6ba4df85
2 changed files with 91 additions and 4 deletions
+48 -4
View File
@@ -1,3 +1,5 @@
version: 2
# This is an example .goreleaser.yml file with some sensible defaults.
# Make sure to check the documentation at https://goreleaser.com
before:
@@ -7,7 +9,8 @@ before:
# you may remove this if you don't need go generate
# - go generate ./...
builds:
- env:
- id: gost
env:
- CGO_ENABLED=0
main: ./cmd/gost
targets:
@@ -38,6 +41,16 @@ builds:
- android_arm64
ldflags:
- "-s -w -X 'main.version={{ .Tag }}'"
- id: gost-packages
env:
- CGO_ENABLED=0
main: ./cmd/gost
targets:
- linux_amd64
- linux_amd64_v3
- linux_arm64
ldflags:
- "-s -w -X 'main.version={{ .Tag }}'"
upx:
- # UPX compression. Disabled by default (see #863): upx --best/--lzma/--brute
@@ -46,18 +59,49 @@ upx:
enabled: false
archives:
- format: tar.gz
- ids:
- gost
formats:
- tar.gz
builds_info:
group: root
owner: root
# use zip for windows archives
format_overrides:
- goos: windows
format: zip
formats:
- zip
nfpms:
- id: packages
package_name: gost
ids:
- gost-packages
vendor: go-gost
homepage: https://gost.run/
maintainer: go-gost contributors
description: GO Simple Tunnel
license: MIT
formats:
- deb
- rpm
bindir: /usr/bin
contents:
- src: gost.service
dst: /usr/lib/systemd/system/gost.service
- src: README.md
dst: /usr/share/doc/gost/README.md
- src: README_en.md
dst: /usr/share/doc/gost/README_en.md
- src: LICENSE
dst: /usr/share/doc/gost/LICENSE
- src: gost.yml
dst: /usr/share/doc/gost/examples/gost.yml
checksum:
name_template: 'checksums.txt'
snapshot:
name_template: "{{ incpatch .Version }}-next"
version_template: "{{ incpatch .Version }}-next"
changelog:
sort: asc
filters:
+43
View File
@@ -0,0 +1,43 @@
[Unit]
Description=GO Simple Tunnel
Documentation=https://gost.run/
After=network-online.target nss-lookup.target
ConditionPathExists=/etc/gost/gost.yml
[Service]
Type=simple
WorkingDirectory=/run/gost
ExecStart=/usr/bin/gost -C /etc/gost/gost.yml
ExecReload=/bin/kill -SIGHUP $MAINPID
User=nobody
RuntimeDirectory=gost
LogsDirectory=gost
TimeoutStopSec=5s
Restart=on-failure
RestartSec=1s
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
PrivateTmp=yes
PrivateDevices=no
ProtectSystem=full
ProtectHostname=yes
ProtectHome=yes
ProtectKernelTunables=yes
ProtectKernelLogs=yes
ProtectKernelModules=yes
ProtectControlGroups=yes
ProtectClock=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
SystemCallFilter=~@mount @debug @cpu-emulation @obsolete
SystemCallErrorNumber=EPERM
SystemCallArchitectures=native
RestrictNamespaces=yes
RestrictSUIDSGID=yes
LockPersonality=yes
[Install]
WantedBy=multi-user.target