]> git.openstreetmap.org Git - chef.git/commitdiff
Use default sandboxing for the supybot service
authorTom Hughes <tom@compton.nu>
Wed, 9 Nov 2022 19:23:46 +0000 (19:23 +0000)
committerTom Hughes <tom@compton.nu>
Wed, 9 Nov 2022 19:23:46 +0000 (19:23 +0000)
cookbooks/supybot/recipes/default.rb

index 6b6d2661e2dbf29d203308edca5c534775d59ffb..7545ff331767bd814742ac281c72f176bf5e7b40 100644 (file)
@@ -131,12 +131,8 @@ systemd_service "supybot" do
   after "network.target"
   user "supybot"
   exec_start "/usr/bin/supybot /etc/supybot/supybot.conf"
-  private_tmp true
-  private_devices true
-  protect_system "strict"
-  protect_home true
+  sandbox :enable_network => true
   read_write_paths ["/etc/supybot", "/var/lib/supybot", "/var/log/supybot"]
-  no_new_privileges true
   restart "on-failure"
 end