graphene-os-server-infrastr.../systemd/system
Daniel Micay 8ac489c9aa allow nginx master process to use CAP_CHOWN
This is required for it to create the /var directories it uses when the
master process is running as root. It would be possible to run the nginx
master process as non-root but it doesn't drop ambient capabilities when
it spawns the workers so running the master process as non-root will end
up giving the workers higher privileges due to them ending up getting
the CAP_NET_BIND_SERVICE capability passed through.
2023-07-06 05:30:35 -04:00
..
certbot-renew.service.d drop mail server specific certbot configuration 2023-06-30 15:47:33 -04:00
nginx.service.d allow nginx master process to use CAP_CHOWN 2023-07-06 05:30:35 -04:00
sshd.service.d add new file limit configuration for sshd 2022-02-25 19:31:35 -05:00
certbot-ocsp-fetcher.service move units to systemd directory 2021-09-08 17:57:50 -04:00
certbot-ocsp-fetcher.timer move units to systemd directory 2021-09-08 17:57:50 -04:00