File tree 2 files changed +5
-9
lines changed
2 files changed +5
-9
lines changed Original file line number Diff line number Diff line change @@ -6,19 +6,12 @@ After=network.target
6
6
Type =simple
7
7
User =derper
8
8
Group =derper
9
- ExecStart =/usr/bin/derper
9
+ ExecStart =/usr/bin/derper -c /etc/derper/derper.conf
10
10
Restart =on-failure
11
11
RestartSec =5
12
12
LimitNOFILE =1048576
13
13
14
14
# Hardening measures
15
- PrivateTmp =yes
16
- ProtectSystem =full
17
- NoNewPrivileges =yes
18
- ProtectHome =yes
19
- ProtectKernelTunables =yes
20
- ProtectKernelModules =yes
21
- ProtectControlGroups =yes
22
15
AmbientCapabilities =CAP_NET_BIND_SERVICE
23
16
CapabilityBoundingSet =CAP_NET_BIND_SERVICE
24
17
Original file line number Diff line number Diff line change 2
2
getent group xdpderper > /dev/null || groupadd -r xdpderper
3
3
getent passwd xdpderper > /dev/null || useradd -r -g xdpderper -s /bin/bash -c " XDPDERP server" xdpderper
4
4
getent group derper > /dev/null || groupadd -r derper
5
- getent passwd derper > /dev/null || useradd -r -g derper -s /bin/bash -c " DERP server" derper
5
+ getent passwd derper > /dev/null || useradd -r -g derper -s /bin/bash -c " DERP server" derper
6
+
7
+ mkdir /etc/derper
8
+ chown -R derper:derper /etc/derper
You can’t perform that action at this time.
0 commit comments