From: Tom Hughes Date: Mon, 14 Nov 2022 22:48:50 +0000 (+0000) Subject: Use default sandboxing for the gps-update service X-Git-Url: https://git.openstreetmap.org./chef.git/commitdiff_plain/0bf6d143b646c0e95dcead057a2782890c0c10ef Use default sandboxing for the gps-update service --- diff --git a/cookbooks/gps-tile/recipes/default.rb b/cookbooks/gps-tile/recipes/default.rb index f82327c9f..d71d04ade 100644 --- a/cookbooks/gps-tile/recipes/default.rb +++ b/cookbooks/gps-tile/recipes/default.rb @@ -94,12 +94,8 @@ systemd_service "gps-update" do working_directory "/srv/gps-tile.openstreetmap.org" exec_start "/srv/gps-tile.openstreetmap.org/updater/update" nice 10 - private_tmp true - private_devices true - protect_system "strict" - protect_home true + sandbox :enable_network => true read_write_paths "/srv/gps-tile.openstreetmap.org" - no_new_privileges true restart "on-failure" end