Change haproxy user to varnish one (temp) and fix some namespaces in transmission
This commit is contained in:
parent
92e702c2ee
commit
af44cfba00
|
@ -2,8 +2,8 @@
|
|||
StartLimitIntervalSec=0
|
||||
|
||||
[Service]
|
||||
User=nobody
|
||||
Group=nogroup
|
||||
User=varnish
|
||||
Group=varnish
|
||||
|
||||
Restart=always
|
||||
RestartSec=10
|
||||
|
@ -17,7 +17,6 @@ PrivateTmp=yes
|
|||
PrivateDevices=yes
|
||||
RuntimeDirectory=haproxy
|
||||
|
||||
SecureBits=noroot
|
||||
NoNewPrivileges=true
|
||||
RestrictSUIDSGID=yes
|
||||
MemoryDenyWriteExecute=yes
|
||||
|
|
|
@ -12,10 +12,10 @@ ProtectSystem=strict
|
|||
PrivateUsers=true
|
||||
NoNewPrivileges=yes
|
||||
|
||||
ReadWritePaths={{ global.seedbox.transmission.root_dir }}
|
||||
ReadWritePaths={{ transmission.root_dir }}
|
||||
BindReadOnlyPaths=/usr /lib /lib64
|
||||
TemporaryFileSystem=/:ro
|
||||
Environment=TRANSMISSION_HOME={{ global.seedbox.transmission.root_dir }}/.config
|
||||
Environment=TRANSMISSION_HOME={{ transmission.root_dir }}/.config
|
||||
|
||||
ProtectControlGroups=yes
|
||||
ProtectKernelModules=yes
|
||||
|
|
Reference in New Issue