diff --git a/conf/systemd.service b/conf/systemd.service index 939a604..d43f554 100644 --- a/conf/systemd.service +++ b/conf/systemd.service @@ -31,6 +31,7 @@ ProtectControlGroups=yes ProtectKernelModules=no ProtectKernelTunables=no LockPersonality=no +#SystemCallFilter= # Denying access to capabilities that should not be relevant for webapps # Doc: https://man7.org/linux/man-pages/man7/capabilities.7.html