Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Fully unpriviledged systemd service #73

Open
JGoutin opened this issue May 31, 2023 · 0 comments
Open

Fully unpriviledged systemd service #73

JGoutin opened this issue May 31, 2023 · 0 comments
Assignees
Labels
enhancement New feature or request security Related to security hardening

Comments

@JGoutin
Copy link
Owner

JGoutin commented May 31, 2023

Currently, we keep the way Fedora is running the service by default but add some sandboxing on it.

But, systemd allows running services fully rootless. Mainly by using DynamicUser= and sockets units.

Notes:

  • Make this optional ?
  • There are maybe some issues with socket sharing between services.
  • For each software, check if there is some extra requirements for running them with root
  • Also use chroot to restrict path accesses ? RootDirectory=
@JGoutin JGoutin added enhancement New feature or request security Related to security hardening labels May 31, 2023
@JGoutin JGoutin self-assigned this May 31, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request security Related to security hardening
Projects
None yet
Development

No branches or pull requests

1 participant