From a9fd82ae18eb67f6288d46d40bc893598922d181 Mon Sep 17 00:00:00 2001 From: metamuffin Date: Sat, 12 Oct 2024 16:39:21 +0200 Subject: add existing pkgbuilds --- gnix-git/gnix.service | 34 ++++++++++++++++++++++++++++++++++ 1 file changed, 34 insertions(+) create mode 100644 gnix-git/gnix.service (limited to 'gnix-git/gnix.service') diff --git a/gnix-git/gnix.service b/gnix-git/gnix.service new file mode 100644 index 0000000..95593f5 --- /dev/null +++ b/gnix-git/gnix.service @@ -0,0 +1,34 @@ +[Unit] +Description=gnix http reverse proxy +After=network.target +Wants=network-online.target + +[Service] +AmbientCapabilities=CAP_NET_BIND_SERVICE +CapabilityBoundingSet=CAP_NET_BIND_SERVICE +ExecStart=/usr/bin/gnix /etc/gnix.yaml +User=gnix +LockPersonality=yes +MemoryDenyWriteExecute=yes +NoNewPrivileges=yes +PrivateDevices=true +PrivateTmp=true +ProtectClock=yes +ProtectControlGroups=yes +ProtectHome=true +ProtectHostname=yes +ProtectKernelLogs=yes +ProtectKernelModules=yes +ProtectKernelTunables=yes +ProtectSystem=full +RestrictAddressFamilies=~AF_PACKET AF_NETLINK +RestrictNamespaces=yes +RestrictSUIDSGID=yes +RestrictRealtime=yes +Restart=always +SystemCallArchitectures=native +SystemCallFilter=@system-service +Type=simple + +[Install] +WantedBy=multi-user.target -- cgit v1.2.3-70-g09d2