Merge pull request #118 from andreaso/restrict-systemd-service

Make example systemd service more restrictive
This commit is contained in:
Alexander Neumann 2020-09-13 16:13:37 +02:00 committed by GitHub
commit 037fe06973
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -7,9 +7,16 @@ After=network.target
Type=simple
User=www-data
Group=www-data
ExecStart=/usr/local/bin/rest-server --path /tmp/restic
ExecStart=/usr/local/bin/rest-server --path /path/to/backups
Restart=always
RestartSec=5
# Optional security enhancements
NoNewPrivileges=yes
PrivateTmp=yes
ProtectSystem=strict
ProtectHome=yes
ReadWritePaths=/path/to/backups
[Install]
WantedBy=multi-user.target