Introduce systemd.exec restrictions for better security

This commit is contained in:
Daniel Winzen
2018-12-07 21:54:44 +01:00
parent 8e155012a7
commit 4f6539b31d
8 changed files with 120 additions and 0 deletions

View File

@ -1,2 +1,18 @@
[Service]
LimitNOFILE=100000
ProtectSystem=strict
PrivateTmp=true
NoNewPrivileges=true
ProtectHome=true
PrivateDevices=true
PrivateUsers=true
ProtectKernelTunables=true
ProtectKernelModules=true
ProtectControlGroups=true
LockPersonality=true
SystemCallArchitectures=native
BindPaths=/var/log/mysql/
BindPaths=/var/lib/mysql/
BindPaths=/var/run/mysqld/
BindPaths=/run/mysqld/
InaccessiblePaths=/var/www/