description "Update list of users accepting CTs"
user "planet"
exec_start "/usr/local/bin/users-agreed"
+ nice 10
private_tmp true
private_devices true
- protect_system "full"
+ protect_system "strict"
protect_home true
+ read_write_paths "/store/planet/users_agreed"
restrict_address_families %w[AF_INET AF_INET6]
no_new_privileges true
end
description "Update list of deleted users"
user "planet"
exec_start "/usr/local/bin/users-deleted"
+ nice 10
private_tmp true
private_devices true
- protect_system "full"
+ protect_system "strict"
protect_home true
+ read_write_paths "/store/planet/users_deleted"
restrict_address_families %w[AF_INET AF_INET6]
no_new_privileges true
end
exec_start "/usr/local/bin/replicate-changesets /etc/replication/changesets.conf"
private_tmp true
private_devices true
- protect_system "full"
+ protect_system "strict"
protect_home true
+ read_write_paths [
+ "/run/replication",
+ "/store/planet/replication/changesets"
+ ]
restrict_address_families %w[AF_INET AF_INET6]
no_new_privileges true
end
exec_start "/usr/local/bin/replicate-minute"
private_tmp true
private_devices true
- protect_system "full"
+ protect_system "strict"
protect_home true
+ read_write_paths [
+ "/run/replication",
+ "/store/replication/minute",
+ "/store/planet/replication/minute",
+ "/var/lib/replication/minute"
+ ]
restrict_address_families %w[AF_INET AF_INET6]
no_new_privileges true
end
environment "LD_PRELOAD" => "/opt/flush/flush.so"
private_tmp true
private_devices true
- protect_system "full"
+ protect_system "strict"
protect_home true
+ read_write_paths [
+ "/store/planet/replication/hour",
+ "/var/lib/replication/hour"
+ ]
restrict_address_families %w[AF_INET AF_INET6]
no_new_privileges true
end
environment "LD_PRELOAD" => "/opt/flush/flush.so"
private_tmp true
private_devices true
- protect_system "full"
+ protect_system "strict"
protect_home true
+ read_write_paths [
+ "/store/planet/replication/day",
+ "/var/lib/replication/day"
+ ]
restrict_address_families %w[AF_INET AF_INET6]
no_new_privileges true
end
private_tmp true
private_devices true
private_network true
- protect_system "full"
+ protect_system "strict"
protect_home true
+ read_write_paths "/var/lib/replication"
no_new_privileges true
end