end
end
+package "initramfs-tools"
+
execute "update-initramfs" do
action :nothing
command "update-initramfs -u -k all"
prometheus_collector "smart" do
interval "15m"
user "root"
- capability_bounding_set "CAP_SYS_ADMIN"
+ capability_bounding_set %w[CAP_DAC_OVERRIDE CAP_SYS_ADMIN CAP_SYS_RAWIO]
private_devices false
private_users false
protect_clock false
interval "15m"
user "root"
proc_subset "all"
- capability_bounding_set "CAP_SYS_ADMIN"
+ capability_bounding_set %w[CAP_DAC_OVERRIDE CAP_SYS_ADMIN]
private_devices false
private_users false
protect_clock false