Change systemd options
This commit is contained in:
parent
c844888514
commit
586440fe8d
@ -31,8 +31,11 @@ in
|
|||||||
ExecStart = "${pkgs.labmon}/bin/labmon ${settingsFile}";
|
ExecStart = "${pkgs.labmon}/bin/labmon ${settingsFile}";
|
||||||
DynamicUser = true;
|
DynamicUser = true;
|
||||||
Restart = "always";
|
Restart = "always";
|
||||||
|
RuntimeDirectory = "labmon";
|
||||||
|
RuntimeDirectoryMode = "0700";
|
||||||
|
|
||||||
# Hardening
|
# Hardening
|
||||||
|
DeviceAllow = [ "/dev/null rw" ];
|
||||||
DevicePolicy = "strict";
|
DevicePolicy = "strict";
|
||||||
LockPersonality = true;
|
LockPersonality = true;
|
||||||
MemoryDenyWriteExecute = true;
|
MemoryDenyWriteExecute = true;
|
||||||
@ -53,6 +56,7 @@ in
|
|||||||
RestrictAddressFamilies = [
|
RestrictAddressFamilies = [
|
||||||
"AF_INET"
|
"AF_INET"
|
||||||
"AF_INET6"
|
"AF_INET6"
|
||||||
|
"AF_UNIX"
|
||||||
];
|
];
|
||||||
RestrictNamespaces = true;
|
RestrictNamespaces = true;
|
||||||
RestrictRealtime = true;
|
RestrictRealtime = true;
|
||||||
|
Loading…
x
Reference in New Issue
Block a user