You are not logged in.

#1 2026-09-29 06:47:11

Beemo
Member
Registered: 2024-12-20
Posts: 182

[SOLVED] Plain-text password and DynamicUser

An app uses "DynamicUser=yes" in its systemd service unit but also has plaintext password inside its configuration file. It doesn't have the ability to interact with systemd-creds, passwords inside config seems about the only way.
How do you make the config not world-readable but still readable by the unit?

I tried "ConfigurationDirectory=", but unless you let systemd create the directory, it won't be able to access it. The systemd created dir is owned by some temporary user. So the directory is not shippable, and users can't put in the config file before starting the service.
I tired "ReadOnlyPaths=" but it's just not accessible likely due to the 700 permission on the directory.

I found using "LoadCredential=" and it works, but somehow I vaguely remember systemd's doc saying "Do not use this to pass large data(base)", so it feels like a misuse. I couldn't find the sentence now, though there is indeed a 1MB limit on the file.

Last edited by Beemo (2026-09-29 20:25:19)

Offline

#2 2026-09-29 08:04:58

seth
Member
From: Won't reply 2 private help req
Registered: 2012-09-03
Posts: 78,066

Online

#3 2026-09-29 19:19:01

Beemo
Member
Registered: 2024-12-20
Posts: 182

Re: [SOLVED] Plain-text password and DynamicUser

I just tried "OpenFile=" but it gives a file descriptor instead of path. The app wants a path to the config file.
I tried just passing the descriptor name, or "/dev/fd/(name here)" but they didn't work. The descriptor seems to be stored somewhere else and there is no documentation on how to access it by path (only code), maybe it's not allowed...

Offline

#4 2026-09-29 20:02:06

seth
Member
From: Won't reply 2 private help req
Registered: 2012-09-03
Posts: 78,066

Re: [SOLVED] Plain-text password and DynamicUser

/dev/fd will contain numbered symlinks to the actual files.

The easiest most straight forward solution would be to simply forego the DynamicUser and feel good about it.
https://chromic.org/blog/systemd-dynamic-users/
https://ihatesystemd.com/bad/#dynamicusers

What can the app™ actually handle?
You could use the StateDirectory and keep its data there.
https://0pointer.net/blog/dynamic-users … stemd.html

Alternatively ExecStartPre=/usr/bin/chown … or a bind mount might help you out?

Online

#5 2026-09-29 20:23:37

Beemo
Member
Registered: 2024-12-20
Posts: 182

Re: [SOLVED] Plain-text password and DynamicUser

Yea I don't like DynamicUser either. Other packages I saw create dedicated users to own the config file (if it shouldn't be readable by all). Though this creates friction to use the systemd unit on distros where it's not packaged.
The unit started as user-contributed and the DynamicUser stuck.

The app just does "app -c /path/to/config".

I thought about StateDirectory too, but Reddit says no, also the config will then be in /var/lib/...

I think I might settle for LoadCredential=, maybe I hallucinated the warning... It currently says:

LoadCredential=ID[:PATH]
but can be freely used to pass any kind of limited-size information to a service

Last edited by Beemo (2026-09-29 20:24:30)

Offline

Board footer

Powered by FluxBB