Harden systemd unit

Improves https://github.com/dadevel/wg-netns/issues/13
pull/16/head
Marek Küthe 1 year ago
parent 2bbc743d9b
commit 05c9580285
No known key found for this signature in database
GPG Key ID: 7E869146699108C7

@ -4,6 +4,36 @@ Wants=network-online.target nss-lookup.target
After=network-online.target nss-lookup.target
[Service]
RestrictNamespaces=
ProtectSystem=strict
ProtectHome=true
PrivateDevices=true
ProtectKernelTunables=true
ProtectKernelModules=true
ProtectControlGroups=true
PrivateTmp=true
PrivateMounts=true
ProtectClock=true
ProtectControlGroups=true
ProtectKernelLogs=true
ProtectProc=true
ProtectSystem=true
RestrictSUIDSGID=true
SystemCallFilter=
AmbientCapabilities=
LockPersonality=true
RemoveIPC=true
MemoryDenyWriteExecute=true
ProtectHostname=true
ProcSubset=
NoNewPrivileges=true
RestrictRealtime=true
UMask=600
LimitNOFILE=1048576
LimitNPROC=512
CapabilityBoundingSet=CAP_SYS_ADMIN CAP_NET_ADMIN
Type=oneshot
Environment=WG_ENDPOINT_RESOLUTION_RETRIES=infinity
Environment=WG_VERBOSE=1

Loading…
Cancel
Save