graphene-os-server-infrastr.../systemd
Daniel Micay 8ac489c9aa allow nginx master process to use CAP_CHOWN
This is required for it to create the /var directories it uses when the
master process is running as root. It would be possible to run the nginx
master process as non-root but it doesn't drop ambient capabilities when
it spawns the workers so running the master process as non-root will end
up giving the workers higher privileges due to them ending up getting
the CAP_NET_BIND_SERVICE capability passed through.
2023-07-06 05:30:35 -04:00
..
network silence systemd-networkd address prefix warning 2023-07-06 04:39:16 -04:00
system allow nginx master process to use CAP_CHOWN 2023-07-06 05:30:35 -04:00
journald.conf set log retention time per server 2023-07-06 00:17:05 -04:00
networkd.conf add systemd directory 2021-09-08 17:53:20 -04:00
sleep.conf update sleep.conf 2023-02-17 17:51:41 -05:00
system.conf update systemd/system.conf 2023-03-30 03:17:00 -04:00