Harden systemd service unit #6

Closed
opened 2026-02-02 10:00:56 +01:00 by qwc · 0 comments
Owner

Phase 1: Security Hardening

Tasks

  • Add sandboxing directives: ProtectSystem=strict, ProtectHome=read-only, PrivateTmp=yes, NoNewPrivileges=yes, SystemCallFilter, ReadWritePaths for mount points, logs, db
  • Fix placeholder WorkingDirectory

Files

  • systemd/backive.service
## Phase 1: Security Hardening ### Tasks - Add sandboxing directives: `ProtectSystem=strict`, `ProtectHome=read-only`, `PrivateTmp=yes`, `NoNewPrivileges=yes`, `SystemCallFilter`, `ReadWritePaths` for mount points, logs, db - Fix placeholder `WorkingDirectory` ### Files - `systemd/backive.service`
qwc closed this issue 2026-02-02 14:23:02 +01:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
qwc-open/backive#6
No description provided.