+ # FIXME Clean up old service
+ service "mapserv-fcgi-#{new_resource.site}@" do
+ provider Chef::Provider::Service::Systemd
+ action [:stop, :disable]
+ end
+
+ # FIXME Clean up old service
+ systemd_service "mapserv-fcgi-#{new_resource.site}@" do
+ action :delete
+ end
+
+ systemd_service "mapserv-fcgi-#{new_resource.site}@" do
+ description "Map server for #{new_resource.site} layer"
+ environment "MS_MAP_PATTERN" => "^/srv/imagery/mapserver/",
+ "=" => "0",
+ "MS_ERRORFILE" => "stderr",
+ "GDAL_CACHEMAX" => "512"
+ limit_nofile 16384
+ memory_high "512M"
+ memory_max "1G"
+ user "imagery"
+ group "imagery"
+ exec_start "/usr/bin/multiwatch -f 4 -- /usr/lib/cgi-bin/mapserv"
+ standard_input "socket"
+ private_tmp true
+ private_devices true
+ private_network true
+ protect_system "full"
+ protect_home true
+ no_new_privileges true
+ end
+
+ systemd_socket "mapserv-fcgi-#{new_resource.site}" do
+ description "Map server for #{new_resource.site} layer socket"
+ socket_user "imagery"
+ socket_group "imagery"
+ listen_stream "/run/mapserver-fastcgi/layer-#{new_resource.site}.socket"
+ end
+
+ systemd_unit "mapserv-fcgi-#{new_resource.site}.socket" do
+ action [:enable, :start]
+ subscribes :restart, "systemd_socket[mapserv-fcgi-#{new_resource.site}]"
+ end
+