[Unit] Description=HAPX-UI unattended auto-update (check + verified backup + apply + auto-rollback) Documentation=https://gitea.itm-technologies.de/ITMGmbH/HAPX-UI After=network-online.target hapx-ui.service Wants=network-online.target ConditionPathExists=/usr/local/sbin/hapx-ui-update [Service] # Oneshot, runs as ROOT (no sudoers): `auto` gates on the operator config + # maintenance window + crashloop guard, then reuses the same build+activate verbs # as the manual UI path (verified restore-point, health-gate, binary-first # rollback). No [Install] — enabled via the .timer, never started at boot itself. Type=oneshot ExecStart=/usr/local/sbin/hapx-ui-update auto # The download/build/network-fetch is bounded by the helper's own curl timeouts; # cap the whole run so a hung apply can never wedge the timer forever. TimeoutStartSec=600