# Example systemd unit for a gradio app on RHEL 9.6. # # useradd -r -s /sbin/nologin -d /var/lib/gradio gradio # mkdir -p /var/lib/gradio/tmp /opt/gradio-app # chown -R gradio:gradio /var/lib/gradio # cp gradio-app.service.example /etc/systemd/system/gradio-app.service # # edit the paths below, then: # systemctl daemon-reload && systemctl enable --now gradio-app # # The venv is created by: # /opt/gradio-template/scripts/install-gradio.sh 3.12 /opt/gradio-app/venv [Unit] Description=Gradio application (offline) After=network-online.target Wants=network-online.target [Service] Type=simple User=gradio Group=gradio WorkingDirectory=/opt/gradio-app # Keep gradio and huggingface_hub from attempting outbound calls. Without # these, each start stalls until the connection attempts time out. Environment=GRADIO_ANALYTICS_ENABLED=False Environment=DO_NOT_TRACK=1 Environment=HF_HUB_OFFLINE=1 Environment=HF_HUB_DISABLE_TELEMETRY=1 Environment=GRADIO_SHARE=False # Loopback must bypass any site proxy or the startup self-check fails with # "When localhost is not accessible, a shareable link must be created". Environment=no_proxy=127.0.0.1,localhost,::1 Environment=NO_PROXY=127.0.0.1,localhost,::1 # Headless matplotlib, and writable scratch space for a nologin account. Environment=MPLBACKEND=Agg Environment=MPLCONFIGDIR=/var/lib/gradio/tmp/matplotlib Environment=GRADIO_TEMP_DIR=/var/lib/gradio/tmp Environment=HF_HOME=/var/lib/gradio/huggingface # Bind loopback only; put a reverse proxy in front for external access. Environment=GRADIO_SERVER_NAME=127.0.0.1 Environment=GRADIO_SERVER_PORT=7860 ExecStart=/opt/gradio-app/venv/bin/python /opt/gradio-app/app.py Restart=on-failure RestartSec=5 # Hardening. ReadWritePaths must cover every directory above, or writes fail # with EROFS once ProtectSystem=strict is on. NoNewPrivileges=yes PrivateTmp=yes ProtectSystem=strict ProtectHome=yes ReadWritePaths=/var/lib/gradio [Install] WantedBy=multi-user.target