[Unit] Description=HAPX-UI CrowdSec provisioning — install + configure + bouncer (+enroll) # Triggered by the web UI via `systemctl start --no-block`. Runs the fixed root # helper `hapx-ui-crowdsec setup`, which reads its request (mode/token) from # /var/lib/hapx-ui/crowdsec-setup-request.json and reports progress via # /var/lib/hapx-ui/crowdsec-setup-state.json + crowdsec-setup.log. # # Runs as its own transient unit under PID 1 (own cgroup), independent of # hapx-ui.service — so the (possible) engine restart it triggers, and its own # apt run, are never killed by hapx-ui's KillMode=control-group. After=network-online.target Wants=network-online.target [Service] Type=oneshot ExecStart=/usr/local/sbin/hapx-ui-crowdsec setup # No [Install] section — this unit is started on demand, never enabled at boot.