Update collabore-tunnel.service

This commit is contained in:
Gaëtan L. H.-F. 2023-05-24 14:51:37 +02:00
parent ac1b5209e8
commit 8fba5f8ecb

View File

@ -34,6 +34,7 @@ PrivateDevices=true
ProtectControlGroups=true
ProtectKernelModules=true
ProtectKernelTunables=true
ProtectKernelLogs=true
ReadWritePaths=
# network
@ -54,7 +55,7 @@ ProtectClock=true
ProtectProc=invisible
# capabilities
RestrictNamespaces=uts ipc pid cgroup
RestrictNamespaces=yes
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
AmbientCapabilities=