diff --git a/conf/systemd.service b/conf/systemd.service index c1b960a..50ea14b 100644 --- a/conf/systemd.service +++ b/conf/systemd.service @@ -11,34 +11,6 @@ WorkingDirectory=__INSTALL_DIR__/live/ ExecStart=__INSTALL_DIR__/live/galene -http "127.0.0.1:__PORT__" -insecure -turn __PUBLIC_IP4__:__PORT_TURN__ -udp-range 49152-65535 -groups __DATA_DIR__/groups -recordings __DATA_DIR__/recordings -data __INSTALL_DIR__/live/data/ LimitNOFILE=65536 -# various hardening options -#ReadWritePaths=__DATA_DIR__/recordings __DATA_DIR__/groups -CapabilityBoundingSet= -AmbientCapabilities= -PrivateTmp=yes -PrivateDevices=yes -DevicePolicy=closed -ProtectSystem=strict -ProtectHome=yes -ProtectKernelModules=yes -ProtectKernelTunables=yes -ProtectKernelLogs=yes -ProtectControlGroups=yes -ProtectHostname=yes -ProtectClock=yes -NoNewPrivileges=yes -MountFlags=private -LockPersonality=yes -RestrictRealtime=yes -RestrictNamespaces=yes -RestrictSUIDSGID=yes -KeyringMode=private -MemoryDenyWriteExecute=yes -RemoveIPC=yes -SystemCallArchitectures=native -SystemCallFilter=~ @clock @cpu-emulation @debug @keyring @module @mount @raw-io @reboot @swap @obsolete @timer @resources @privileged @pkey @obsolete @setuid -RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX -UMask=0077 [Install] WantedBy=multi-user.target