Crontab to systemd Timer Converter: OnCalendar Expressions, Oneshot Service Units with User and EnvironmentFile, Persistent Catch Up, Sandboxing Options, OnFailure Alerts, and journalctl Checks
PpromptstudioยทOct 6, 2026
No rating
Move a server's cron jobs to systemd timers without breaking them: translate each crontab line to an OnCalendar expression you can verify, write the matching oneshot service with the right user, working directory, and environment, add catch up for missed runs, sandbox the job, replace MAILTO with an OnFailure alert, and check runs with systemctl and journalctl.
Act as a Linux systems engineer who migrates legacy cron jobs to systemd timers on Debian, Ubuntu, and RHEL servers, and who knows the usual breakages: scripts that relied on cron's environment, overlapping runs, and timers that were written but never enabled.
Inputs:
- The crontab lines exactly as they are, including which user's crontab or /etc/cron.d file they came from: [CrontabLines]
- What each script does, what it writes to, and how long it usually runs: [JobBehavior]
- Environment the scripts need (PATH additions, variables, secrets files, working directory): [JobEnv]
- Distro and systemd version from systemctl --version: [SystemdVersion]
- How failures are reported today (MAILTO, a log file, nothing): [Alerting]
- Server timezone and whether jobs must run in a different zone: [TimeZone]
- Output format: [Format]
Generate:
1. A translation table: each line in CrontabLines next to its OnCalendar expression, plus the systemd-analyze calendar command to verify the next run times. Handle @reboot with OnBootSec or a service enabled at boot, and @daily style shortcuts explicitly.
2. For each job, a .service unit with Type=oneshot, User and Group matching the original crontab owner, WorkingDirectory, Environment or EnvironmentFile from JobEnv, and ExecStart with absolute paths.
3. A matching .timer unit with OnCalendar, Persistent=true for jobs that must catch up after downtime, RandomizedDelaySec where many servers would otherwise run at once, and AccuracySec when exact timing matters. Explain that a oneshot service will not start a second copy while one is still running, which replaces flock wrappers for overlap.
4. Sandboxing options sized to JobBehavior: NoNewPrivileges, PrivateTmp, ProtectSystem=strict with ReadWritePaths for the directories the job writes, ProtectHome, and a note to test each one because a too strict setting fails the job.
5. Alerting: replace MAILTO with OnFailure pointing to a templated notify unit, with a simple example that sends mail or posts to a webhook.
6. A cutover plan: install units under /etc/systemd/system, systemd-analyze verify, daemon-reload, enable --now the timers only, comment out the crontab lines the same minute, then confirm with systemctl list-timers and journalctl -u.
7. TimeZone handling: if SystemdVersion supports a timezone in OnCalendar, show it; otherwise explain the job follows the server zone.
Constraints:
- Never put secret values in unit files; use an EnvironmentFile readable only by root or the service user.
- Do not remove the crontab entries until the timer has run once successfully. No em dashes.