extend matterbridge service hardening

This commit is contained in:
Daniel Micay 2022-08-09 06:18:21 -04:00
parent 28c063bdc2
commit 5a4b71ed29

View File

@ -0,0 +1,8 @@
[Service]
# use a persistent user so that nftables can use it for skuid rules
DynamicUser=false
MemoryDenyWriteExecute=true
RemoveIPC=true
ProcSubset=pid
ProtectProc=invisible