You are not logged in.
An app uses "DynamicUser=yes" in its systemd service unit but also has plaintext password inside its configuration file. It doesn't have the ability to interact with systemd-creds, passwords inside config seems about the only way.
How do you make the config not world-readable but still readable by the unit?
I tried "ConfigurationDirectory=", but unless you let systemd create the directory, it won't be able to access it. The systemd created dir is owned by some temporary user. So the directory is not shippable, and users can't put in the config file before starting the service.
I tired "ReadOnlyPaths=" but it's just not accessible likely due to the 700 permission on the directory.
I found using "LoadCredential=" and it works, but somehow I vaguely remember systemd's doc saying "Do not use this to pass large data(base)", so it feels like a misuse. I couldn't find the sentence now, though there is indeed a 1MB limit on the file.
Last edited by Beemo (2026-09-29 20:25:19)
Offline
https://man.archlinux.org/man/systemd.s … en#OPTIONS
"OpenFile=" ?
Online
I just tried "OpenFile=" but it gives a file descriptor instead of path. The app wants a path to the config file.
I tried just passing the descriptor name, or "/dev/fd/(name here)" but they didn't work. The descriptor seems to be stored somewhere else and there is no documentation on how to access it by path (only code), maybe it's not allowed...
Offline
/dev/fd will contain numbered symlinks to the actual files.
The easiest most straight forward solution would be to simply forego the DynamicUser and feel good about it.
https://chromic.org/blog/systemd-dynamic-users/
https://ihatesystemd.com/bad/#dynamicusers
What can the app™ actually handle?
You could use the StateDirectory and keep its data there.
https://0pointer.net/blog/dynamic-users … stemd.html
Alternatively ExecStartPre=/usr/bin/chown … or a bind mount might help you out?
Online
Yea I don't like DynamicUser either. Other packages I saw create dedicated users to own the config file (if it shouldn't be readable by all). Though this creates friction to use the systemd unit on distros where it's not packaged.
The unit started as user-contributed and the DynamicUser stuck.
The app just does "app -c /path/to/config".
I thought about StateDirectory too, but Reddit says no, also the config will then be in /var/lib/...
I think I might settle for LoadCredential=, maybe I hallucinated the warning... It currently says:
LoadCredential=ID[:PATH]
but can be freely used to pass any kind of limited-size information to a service
Last edited by Beemo (2026-09-29 20:24:30)
Offline