[Unit] Description=Vestibule kiosk (cage + LibreWolf) Documentation=file:/opt/vestibule/docs/DEPLOYMENT.md # The cage compositor takes a VT and runs LibreWolf as the kiosk user in # a full-screen, no-chrome Wayland session. No display manager is needed: # this unit IS the graphical session, started directly at boot. After=systemd-user-sessions.service dbus.service Conflicts=getty@tty__TTY__.service [Service] Type=simple User=__KIOSK_USER__ # PAMName=login gives the service login-session semantics: pam_systemd # creates the runtime directory (XDG_RUNTIME_DIR) that Wayland needs. # The account's password stays locked — nothing authenticates to get in. PAMName=login TTYPath=/dev/tty__TTY__ StandardInput=tty StandardOutput=journal StandardError=journal UtmpIdentifier=tty__TTY__ # The launcher reads /etc/vestibule/kiosk.env (home URL, LibreWolf # flavor, cage args) and execs: dbus-run-session -- cage -- librewolf. ExecStart=/usr/local/bin/vestibule-kiosk-launch Restart=always RestartSec=5 [Install] WantedBy=multi-user.target