# Dangerous Pi Systemd Service This directory contains systemd service files and installation scripts for running Dangerous Pi as a system service. ## Files - `dangerous-pi.service` - Main systemd service unit file - `dangerous-pi.env.example` - Environment configuration template - `install-service.sh` - Installation script - `uninstall-service.sh` - Uninstallation script ## Installation ### Automated Installation Run the installation script as root: ```bash cd /path/to/dangerous-pi/systemd sudo ./install-service.sh ``` This will: 1. Copy the service file to `/etc/systemd/system/` 2. Create the environment configuration file at `/opt/dangerous-pi/.env` 3. Create data and logs directories 4. Add the `pi` user to required hardware access groups 5. Enable the service to start on boot ### Manual Installation If you prefer to install manually: ```bash # Copy service file sudo cp dangerous-pi.service /etc/systemd/system/ # Copy environment template sudo cp dangerous-pi.env.example /opt/dangerous-pi/.env # Create directories sudo mkdir -p /opt/dangerous-pi/data /opt/dangerous-pi/logs sudo chown -R pi:pi /opt/dangerous-pi/data /opt/dangerous-pi/logs # Add pi user to groups sudo usermod -a -G i2c,bluetooth,gpio,dialout pi # Reload systemd and enable service sudo systemctl daemon-reload sudo systemctl enable dangerous-pi ``` ## Configuration Edit the environment file to customize your installation: ```bash sudo nano /opt/dangerous-pi/.env ``` Available configuration options: - `PM3_DEVICE` - Proxmark3 device path (default: `/dev/ttyACM0`) - `PM3_TIMEOUT` - PM3 command timeout in seconds - `SESSION_TIMEOUT` - User session timeout in seconds - `HOST` - Server bind address (default: `0.0.0.0`) - `PORT` - Server port (default: `8000`) - `GITHUB_REPO` - GitHub repository for updates - `UPS_I2C_ADDRESS` - I2C address for UPS HAT - `BLE_ENABLED` - Enable/disable BLE notifications - `AUTH_ENABLED` - Enable/disable authentication - See `dangerous-pi.env.example` for all options ## Service Management ### Start the service ```bash sudo systemctl start dangerous-pi ``` ### Stop the service ```bash sudo systemctl stop dangerous-pi ``` ### Restart the service ```bash sudo systemctl restart dangerous-pi ``` ### Check service status ```bash sudo systemctl status dangerous-pi ``` ### View service logs ```bash # View recent logs sudo journalctl -u dangerous-pi # Follow logs in real-time sudo journalctl -u dangerous-pi -f # View logs since boot sudo journalctl -u dangerous-pi -b ``` ### Enable service (start on boot) ```bash sudo systemctl enable dangerous-pi ``` ### Disable service (don't start on boot) ```bash sudo systemctl disable dangerous-pi ``` ## Uninstallation Run the uninstallation script as root: ```bash cd /path/to/dangerous-pi/systemd sudo ./uninstall-service.sh ``` This will: 1. Stop the service if running 2. Disable the service 3. Remove the service unit file 4. Reload systemd daemon Note: Application files in `/opt/dangerous-pi` are NOT removed automatically. ## Security Features The service includes security hardening: - Runs as non-root user (`pi`) - Private `/tmp` directory - Protected system directories - Read-only application directory (except for `data` and `logs`) - Resource limits (memory, CPU, file descriptors) - No new privileges allowed ## Hardware Access The service is configured to access the following hardware: - I2C devices (for UPS HAT) via `i2c` group - Bluetooth (for BLE notifications) via `bluetooth` group - GPIO pins via `gpio` group - Serial devices (for Proxmark3) via `dialout` group ## Troubleshooting ### Service fails to start Check the logs for errors: ```bash sudo journalctl -u dangerous-pi -n 50 ``` ### Permission denied errors Ensure the `pi` user is in the required groups: ```bash groups pi ``` Should include: `i2c`, `bluetooth`, `gpio`, `dialout` ### Port already in use The default port (8000) conflicts with ttyd-bash from pi-pm3. See the main README for resolution options. ### Can't access Proxmark3 Ensure the PM3 device path is correct in `/opt/dangerous-pi/.env`: ```bash PM3_DEVICE=/dev/ttyACM0 ``` Check that the device exists: ```bash ls -l /dev/ttyACM* ``` ## Advanced Configuration ### Custom Installation Directory To use a different installation directory, edit the service file before installation: ```bash WorkingDirectory=/your/custom/path ReadWritePaths=/your/custom/path/data /your/custom/path/logs ``` ### Different User/Group To run as a different user, edit the service file: ```bash User=your-user Group=your-group ``` Don't forget to add the user to required hardware groups. ### Resource Limits Adjust resource limits in the service file: ```bash MemoryMax=1G # Maximum memory CPUQuota=100% # CPU usage limit LimitNOFILE=131072 # Max open files ``` ## Integration with pi-pm3 When running alongside the existing pi-pm3 setup: 1. **Port Conflict**: Port 8000 is used by ttyd-bash. Options: - Change Dangerous Pi port in `.env`: `PORT=8001` - Disable ttyd-bash: `sudo systemctl disable ttyd-bash` 2. **RaspAP Compatibility**: Dangerous Pi WiFi manager can coexist with RaspAP or replace it. 3. **PM3 Access**: Only one service should access PM3 at a time. Disable ttyd-pm3 if using Dangerous Pi's PM3 interface.