private_devices true
protect_system "full"
protect_home true
+ no_new_privileges true
restart "on-failure"
pid_file "#{node[:web][:pid_directory]}/cgimap.pid"
end
-if %w(database_offline api_offline).include?(node[:web][:status])
+if %w[database_offline api_offline].include?(node[:web][:status])
service "cgimap" do
action :stop
end