Run hik as a systemd service on MOS/ROSA.
What's added: hik.service: runs as a non-root user hik, data in /var/lib/hik, UMask=0077, auto-restart hik.sh launcher (/usr/bin/hik): checks dependencies, installs HCNetSDK and python module via pkexec/sudo, starts the service and opens the web UI hik.sysusers.conf: creates user/group hik at install time hikvison.py: stores DB, uploads and certs under HIK_DATA_DIR instead of the script directory TLS cert generated by cert-sh (standard Alt/ROSA mechanism) on first start, key 0600 owned by hik; renews near expiry; falls back to a self-signed cert if cert-sh is missing README: install/usage section for the packaged version
Why: No identical certs baked into installation images (generated on first start) Use the standard cert-sh mechanism instead of custom %post logic Run the web UI under an unprivileged user