systemd service unit evaluation differences local RHEL vs production
0 reputation · 26 Oct 2023, 19:31 UTC
A design review is needed for systemd service units on RHEL 8 and RHEL 9 where the same unit file is intended to run in a local development context and in a production environment. The goal is to clarify which configuration behaviors are deterministic across environments and which are dependent on host policy.
Relevant constraints include systemd service hardening directives, SELinux enforcement levels and contexts, resolution of User=, Group= and WorkingDirectory= directives, availability of environment variables set in shell profiles to the service process, and network namespace isolation in containers or cloud deployments. Behavior is known to vary between RHEL 7, 8 and 9 due to systemd and SELinux updates, and production environments often apply additional security modules or compliance policies not present locally.
Which systemd unit directives are evaluated differently when SELinux is enforcing in production compared with a local setup? Does systemd inherit any environment from interactive shell profiles for a service unit on RHEL 8/9, and under what conditions is WorkingDirectory= resolved relative to the service manager? What determines the SELinux context applied to a service process started by systemd in production?