matrix.grapheneos.org/systemd/system/matterbridge.service.d/local.conf
2024-04-27 09:14:28 -04:00

10 lines
192 B
Plaintext

[Service]
# use a persistent user so that nftables can use it for skuid rules
DynamicUser=false
MemoryDenyWriteExecute=true
RemoveIPC=true
ProcSubset=pid
ProtectProc=invisible
Restart=always