Skip to content
Unverified Commit 353a8b58 authored by Félix Baylac-Jacqué's avatar Félix Baylac-Jacqué
Browse files

nixos/prosody: leverage systemd sandbox features to harden service

We are leveraging the systemd sandboxing features to prevent the
service accessing locations it shouldn't do. Most notably, we are here
preventing the prosody service from accessing /home and providing it
with a private /dev and /tmp.

Please consult man systemd.exec for further informations.
parent 8aea5288
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment