diff options
| author | Géza Búza <bghome@gmail.com> | 2023-01-16 14:36:15 +0100 |
|---|---|---|
| committer | Géza Búza <bghome@gmail.com> | 2023-01-17 14:57:28 +0100 |
| commit | b3c825d1eff82e1f9789d8ac620659f873956cf6 (patch) | |
| tree | 28590c490c48cc42093cf19d84e22683edfcb648 /pkgs/development/python-modules/rangehttpserver | |
| parent | 94897428db22089d3bed71fd3e609b873ad5004b (diff) | |
nixos/jackett: add Systemd sandboxing configuration
Apply security sandboxing via Systemd service configuration:
- All unnecessary privileges are dropped.
- The only writable directories are /tmp and the home of the jackett user.
- Only can execute installed applications from the Nix store.
- Network access is not restricted as the setup can vary across users. So it should be configured in the firewall.
Diffstat (limited to 'pkgs/development/python-modules/rangehttpserver')
0 files changed, 0 insertions, 0 deletions
