-
Notifications
You must be signed in to change notification settings - Fork 109
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
ccc3a70 service hardening: add more restrictions (nixbitcoin) 3fbfa98 service hardening: replace obtuse SystemCallFilter with @System-service (nixbitcoin) e34d1c8 service hardening: Add PrivateUsers (nixbitcoin) 1c75543 clightning: add user and group options (nixbitcoin) 5f3f362 lnd: add strict hardening (Erik Arvstedt) a040e52 All modules: ProtectSystem = strict (nixbitcoin) adc71b8 Remove PermissionStartOnly where possible and replace with bitcoinrpc (nixbitcoin) 91b6b2c All modules with preStart: Use systemd.tmpfiles.rules (nixbitcoin) 423ebf8 lnd: only enable bitcoind zmqpub if lnd.enable (nixbitcoin) 81a1c3f service hardening: Add CapabilityBoundingSets (nixbitcoin) 3cd6150 webindex & onion-chef: Run non-network-facing services in PrivateNetwork (nixbitcoin) 7c70dd4 All modules: Give service config precedence over defaultHardening (nixbitcoin) Pull request description: ACKs for top commit: erikarvstedt: ACK ccc3a70 jonasnick: ACK ccc3a70 very nice Tree-SHA512: 069f74b11b46b17fd180e9da5328a3b9952aa90100b5077251d1e56a4d64f03ba64587adf153ddc6cf42f750c13a168f9f0fe43bc379bcd4a9f6709e635e512a
- Loading branch information
Showing
14 changed files
with
173 additions
and
129 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.