Enable simple sandboxing in Bookwyrm systemd unit
This commit is contained in:
parent
4bba2eccca
commit
547697c231
1 changed files with 15 additions and 0 deletions
|
@ -24,6 +24,21 @@ with pkgs . kernelmaft ;
|
|||
|
||||
User=bookwyrm
|
||||
Group=bookwyrm
|
||||
|
||||
ProtectSystem=strict
|
||||
ProtectHome=tmpfs
|
||||
PrivateTmp=disconnected
|
||||
PrivateDevices=true
|
||||
PrivateIPC=true
|
||||
ProtectHostname=true
|
||||
ProtectClock=true
|
||||
ProtectKernelTunables=true
|
||||
ProtectKernelModules=true
|
||||
ProtectControlGroups=strict
|
||||
RestrictNamespaces=true
|
||||
LockPersonality=true
|
||||
RestrictRealtime=true
|
||||
RestrictSUIDSGID=true
|
||||
'' ;
|
||||
} ;
|
||||
} ;
|
||||
|
|
Loading…
Add table
Reference in a new issue