Commit ce1c92ed authored by nono's avatar nono 💻
Browse files

Fix service file

parent 41ee317d
......@@ -15,27 +15,29 @@ Environment=NODE_ENV=production
Restart=always
RestartSec=2s
ExecStart=npm start --production
CapabilityBoundingSet=
NoNewPrivileges=true
PrivateDevices=true
RemoveIPC=true
LockPersonality=true
ProtectControlGroups=true
ProtectKernelTunables=true
ProtectKernelModules=true
ProtectKernelLogs=true
ProtectClock=true
ProtectHostname=true
ProtectProc=noaccess
RestrictRealtime=true
RestrictSUIDSGID=true
RestrictNamespaces=true
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
ProtectSystem=strict
ProtectHome=true
PrivateTmp=true
SystemCallArchitectures=native
SystemCallFilter=@system-service
# CapabilityBoundingSet=
# NoNewPrivileges=true
# PrivateDevices=true
# RemoveIPC=true
# LockPersonality=true
# ProtectControlGroups=true
# ProtectKernelTunables=true
# ProtectKernelModules=true
# ProtectKernelLogs=true
# ProtectClock=true
# ProtectHostname=true
# ProtectProc=noaccess
# RestrictRealtime=true
# RestrictSUIDSGID=true
# RestrictNamespaces=true
# RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
# ProtectSystem=strict
# ProtectHome=true
# PrivateTmp=true
# SystemCallArchitectures=native
# SystemCallFilter=@system-service
StartLimitIntervalSec=120
StartLimitBurst=5
# You may have to adjust these settings
User=hedgedocs
......
Markdown is supported
0% or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment