diff --git a/conf/systemd.service b/conf/systemd.service index e5ba5d2..7e1d6f4 100644 --- a/conf/systemd.service +++ b/conf/systemd.service @@ -7,34 +7,8 @@ After=network.service User=__APP__ Group=__APP__ DynamicUser=yes -# Default Values -Environment=ADDRESS=127.0.0.1 -Environment=PORT=__PORT__ -# Optional Override EnvironmentFile=-__INSTALL_DIR__/libreddit.conf -ExecStart=__INSTALL_DIR__/libreddit -a ${ADDRESS} -p ${PORT} - -# Hardening -DeviceAllow= -LockPersonality=yes -MemoryDenyWriteExecute=yes -PrivateDevices=yes -ProcSubset=pid -ProtectClock=yes -ProtectControlGroups=yes -ProtectHome=yes -ProtectHostname=yes -ProtectKernelLogs=yes -ProtectKernelModules=yes -ProtectKernelTunables=yes -ProtectProc=invisible -RestrictAddressFamilies=AF_INET AF_INET6 -RestrictNamespaces=yes -RestrictRealtime=yes -RestrictSUIDSGID=yes -SystemCallArchitectures=native -SystemCallFilter=@system-service ~@privileged ~@resources -UMask=0077 +ExecStart=__INSTALL_DIR__/libreddit -a 127.0.0.1 -p __PORT__ [Install] WantedBy=multi-user.target