Unverified Commit e1e7ee89 authored by Jonathan Davies's avatar Jonathan Davies
Browse files

nixos/prometheus: Enable CapabilityBoundingSet hardening

parent 46ce9a46
Loading
Loading
Loading
Loading
+1 −0
Original line number Diff line number Diff line
@@ -1980,6 +1980,7 @@ in
        StateDirectory = cfg.stateDir;
        StateDirectoryMode = "0700";
        # Hardening
        CapabilityBoundingSet = [ "" ];
        DeviceAllow = [ "/dev/null rw" ];
        DevicePolicy = "strict";
        LockPersonality = true;