matrix.grapheneos.org/systemd/system/matterbridge.service.d/local.conf
2024-02-08 03:58:57 -05:00

9 lines
177 B
Plaintext

[Service]
# use a persistent user so that nftables can use it for skuid rules
DynamicUser=false
MemoryDenyWriteExecute=true
RemoveIPC=true
ProcSubset=pid
ProtectProc=invisible