Browse Source

Harden systemd unit file

master
Simon Marsh 1 year ago
parent
commit
2d5839e044
Signed by: burble GPG Key ID: 7B9FE8780CFB6593
1 changed files with 11 additions and 0 deletions
  1. +11
    -0
      contrib/dn42regsrv.service

+ 11
- 0
contrib/dn42regsrv.service View File

@@ -14,6 +14,17 @@ User=regsrv
Group=registry
Type=simple
Restart=on-failure
# service hardening
ProtectSystem=strict
ReadOnlyPaths=/home/regsrv/go/src/git.dn42.us/burble/dn42regsrv/StaticRoot
ReadWritePaths=/home/regsrv/registry
NoNewPrivileges=yes
ProtectControlGroups=yes
PrivateTmp=yes
PrivateDevices=yes
DevicePolicy=closed
MemoryDenyWriteExecute=yes
#
ExecStart=/home/regsrv/go/bin/dn42regsrv \
-s /home/regsrv/go/src/git.dn42.us/burble/dn42regsrv/StaticRoot \
-d /home/regsrv/registry


Loading…
Cancel
Save