]> git.openstreetmap.org Git - chef.git/blobdiff - cookbooks/matomo/recipes/default.rb
Improve sandboxing of matomo archiver
[chef.git] / cookbooks / matomo / recipes / default.rb
index c72f7aac440312f265a37a2b0b8cd45df2131805..9cea5099d67a24f8cdda8462b682f505bdb79cf1 100644 (file)
@@ -201,9 +201,10 @@ end
 
 systemd_service "matomo-archive" do
   description "Matomo report archiving"
-  exec_start "/usr/bin/php /srv/matomo.openstreetmap.org/console core:archive --quiet --url=https://matomo.openstreetmap.org/"
+  exec_start "/usr/bin/php /srv/matomo.openstreetmap.org/console core:archive --url=https://matomo.openstreetmap.org/"
   user "www-data"
   sandbox true
+  proc_subset "all"
   memory_deny_write_execute false
   restrict_address_families "AF_UNIX"
   read_write_paths "/opt/matomo-#{version}/matomo/tmp"