Operations
systemd
install.sh writes /etc/systemd/system/sudoterm.service from a template at /opt/sudoterm/assets/sudoterm.service. The unit handles startup, restart on crash, and clean shutdown.
Defaults
User=<install-user>— drops root after the install stepRestart=on-failure,RestartSec=5— restart up to 20× on crashWorkingDirectory=/opt/sudotermExecStart=/opt/sudoterm/bin/sudoterm-daemon
Hardening
NoNewPrivileges=trueProtectSystem=full— only/etc,/var,/runwritableProtectHome=read-onlywith an explicitReadWritePathsexception for
~/.sudoterm
PrivateTmp=true
Day-to-day
sudoterm start | stop | restart | status
sudoterm logs # tail journalctl
sudoterm logs --since "10 minutes ago"The sudoterm CLI wraps systemctl and journalctl so you don't have to remember unit names. For raw access:
sudo systemctl status sudoterm
sudo journalctl -u sudoterm -fCloudflared lifecycle
The daemon manages cloudflared as a child process — *not* a separate systemd unit. That keeps tunnel lifecycle tied to the daemon's. If cloudflared crashes, the daemon restarts it with exponential backoff (1s → 2s → 5s → 10s → 30s, max 20 attempts).