]> git.openstreetmap.org Git - chef.git/blobdiff - cookbooks/supybot/recipes/default.rb
Use default sandboxing for the supybot service
[chef.git] / cookbooks / supybot / recipes / default.rb
index 6b6d2661e2dbf29d203308edca5c534775d59ffb..7545ff331767bd814742ac281c72f176bf5e7b40 100644 (file)
@@ -131,12 +131,8 @@ systemd_service "supybot" do
   after "network.target"
   user "supybot"
   exec_start "/usr/bin/supybot /etc/supybot/supybot.conf"
   after "network.target"
   user "supybot"
   exec_start "/usr/bin/supybot /etc/supybot/supybot.conf"
-  private_tmp true
-  private_devices true
-  protect_system "strict"
-  protect_home true
+  sandbox :enable_network => true
   read_write_paths ["/etc/supybot", "/var/lib/supybot", "/var/log/supybot"]
   read_write_paths ["/etc/supybot", "/var/lib/supybot", "/var/log/supybot"]
-  no_new_privileges true
   restart "on-failure"
 end
 
   restart "on-failure"
 end