]> git.openstreetmap.org Git - chef.git/blobdiff - cookbooks/gps-tile/recipes/default.rb
Use default sandboxing for the gps-update service
[chef.git] / cookbooks / gps-tile / recipes / default.rb
index f82327c9fe2e6fe2ff1a115d69a5d5f11b35444c..d71d04ade74c74d8c7eb9fc19ca5e777e3b22db7 100644 (file)
@@ -94,12 +94,8 @@ systemd_service "gps-update" do
   working_directory "/srv/gps-tile.openstreetmap.org"
   exec_start "/srv/gps-tile.openstreetmap.org/updater/update"
   nice 10
-  private_tmp true
-  private_devices true
-  protect_system "strict"
-  protect_home true
+  sandbox :enable_network => true
   read_write_paths "/srv/gps-tile.openstreetmap.org"
-  no_new_privileges true
   restart "on-failure"
 end