Commit 26d0023f authored by Felix Singer's avatar Felix Singer
Browse files

nixos/gerrit: Enable PrivateMounts hardening in service config

parent 40d07fb1
Loading
Loading
Loading
Loading
+1 −0
Original line number Diff line number Diff line
@@ -232,6 +232,7 @@ in
        LockPersonality = true;
        NoNewPrivileges = true;
        PrivateDevices = true;
        PrivateMounts = true;
        PrivateTmp = true;
        ProtectClock = true;
        ProtectControlGroups = true;