We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent 5f27755 commit ddc2e22Copy full SHA for ddc2e22
1 file changed
systemd/system/rspamd.service.d/override.conf
@@ -1,5 +1,27 @@
1
[Service]
2
+CapabilityBoundingSet=
3
+LockPersonality=yes
4
+NoNewPrivileges=yes
5
+PrivateDevices=yes
6
+PrivateTmp=yes
7
+PrivateIPC=yes
8
+ProcSubset=pid
9
+ProtectClock=yes
10
+ProtectControlGroups=yes
11
+ProtectHome=yes
12
+ProtectHostname=yes
13
+ProtectKernelLogs=yes
14
+ProtectKernelModules=yes
15
+ProtectKernelTunables=yes
16
+ProtectProc=invisible
17
+ProtectSystem=strict
18
+ReadWritePaths=/run/valkey /var/lib/rspamd /var/log/rspamd /var/spool/postfix/rspamd
19
Restart=always
20
RestartMaxDelaySec=10s
21
RestartSec=100ms
22
RestartSteps=5
23
+RestrictAddressFamilies=AF_INET AF_INET6 AF_NETLINK AF_UNIX
24
+RestrictNamespaces=yes
25
+RestrictRealtime=yes
26
+RestrictSUIDSGID=yes
27
+SystemCallArchitectures=native
0 commit comments