Try reducing scope of systemd services

This commit is contained in:
Rory& 2025-01-12 06:34:30 +00:00
commit 045d6763d0

View file

@ -172,11 +172,11 @@ in
ExecStart = lib.getExe config.services.matrix-ooye.package; ExecStart = lib.getExe config.services.matrix-ooye.package;
WorkingDirectory = "/var/lib/matrix-ooye"; WorkingDirectory = "/var/lib/matrix-ooye";
StateDirectory = "matrix-ooye"; StateDirectory = "matrix-ooye";
ProtectSystem = "strict"; #ProtectSystem = "strict";
ProtectHome = true; #ProtectHome = true;
PrivateTmp = true; #PrivateTmp = true;
NoNewPrivileges = true; #NoNewPrivileges = true;
PrivateDevices = true; #PrivateDevices = true;
Restart = "on-failure"; Restart = "on-failure";
DynamicUser = true; DynamicUser = true;
}; };