]> git.openstreetmap.org Git - chef.git/commitdiff
Use default sandboxing for dev services
authorTom Hughes <tom@compton.nu>
Tue, 15 Nov 2022 18:45:34 +0000 (18:45 +0000)
committerTom Hughes <tom@compton.nu>
Tue, 15 Nov 2022 18:45:34 +0000 (18:45 +0000)
cookbooks/dev/recipes/default.rb

index 9ad37bfc9b30f57732011b0d1afc7162f0e7b9a6..385c3a002129718c3de06476fead7de0416cb3ae 100644 (file)
@@ -290,12 +290,8 @@ if node[:postgresql][:clusters][:"14/main"]
     exec_start "#{node[:ruby][:bundle]} exec rails jobs:work"
     restart "on-failure"
     nice 10
-    private_tmp true
-    private_devices true
-    protect_system "strict"
-    protect_home true
+    sandbox :enable_network => true
     read_write_paths "/srv/%i.apis.dev.openstreetmap.org/logs"
-    no_new_privileges true
   end
 
   systemd_service "cgimap@" do
@@ -305,12 +301,8 @@ if node[:postgresql][:clusters][:"14/main"]
     user "apis"
     exec_start "/srv/%i.apis.dev.openstreetmap.org/cgimap/openstreetmap-cgimap --daemon --port $CGIMAP_PORT --instances 5"
     exec_reload "/bin/kill -HUP $MAINPID"
-    private_tmp true
-    private_devices true
-    protect_system "strict"
-    protect_home true
+    sandbox :enable_network => true
     read_write_paths ["/srv/%i.apis.dev.openstreetmap.org/logs", "/srv/%i.apis.dev.openstreetmap.org/rails/tmp"]
-    no_new_privileges true
     restart "on-failure"
   end