I run everything as the ubuntu user (I should probably have a dedicated datasette user instead).
I created a virtual environment like this:
cd /home/ubuntu
python3 -mvenv datasette-venv
Then I installed Datasette like so:
/home/ubuntu/datasette-venv/bin/pip install datasette
My database files (twitter.db, healthkit.db, github.db) all live in the /home/ubuntu directory. So does a metadata.json file.
When I need to restart Datasette (due to changes to the service file or metadata) i run this:
sudo systemctl daemon-reload
sudo systemctl restart datasette.service
If you're on a recent version of Ubuntu, you can do something like this to avoid running as the
ubuntuuser without the hassle of setting up a new user:This will create an ephemeral user for the service and create a writable directory in
/var/lib/datasettethat you can use to store state.https://www.freedesktop.org/software/systemd/man/systemd.exec.html#DynamicUser=
https://www.freedesktop.org/software/systemd/man/systemd.exec.html#RuntimeDirectory=
There's a few extra settings you can use for easy security wins. I wrote about them here.
I also usually add these which gives you some extra info on resource usage: