X-Git-Url: https://git.openstreetmap.org/chef.git/blobdiff_plain/db8cff3ccb090c53b831f7f5e0b3a7f7e3d858c8..12a47e290b2a7f9862a9723357d849f2efb8f35e:/cookbooks/dns/recipes/default.rb diff --git a/cookbooks/dns/recipes/default.rb b/cookbooks/dns/recipes/default.rb index d25c45731..f61975b52 100644 --- a/cookbooks/dns/recipes/default.rb +++ b/cookbooks/dns/recipes/default.rb @@ -35,13 +35,14 @@ package %w[ libwww-perl libxml-treebuilder-perl libxml-writer-perl + libyaml-perl libyaml-libyaml-perl lockfile-progs ] cache_dir = Chef::Config[:file_cache_path] -dnscontrol_version = "3.21.0" +dnscontrol_version = "3.26.0" dnscontrol_arch = if arm? "arm64" @@ -173,12 +174,9 @@ systemd_service "dns-check" do description "Rebuild DNS zones with GeoDNS changes" exec_start "/usr/local/bin/dns-check" user "git" - private_tmp true - private_devices true - protect_system "strict" - protect_home true + sandbox :enable_network => true + proc_subset "all" read_write_paths "/var/lib/dns" - no_new_privileges true end systemd_timer "dns-check" do