]> git.openstreetmap.org Git - chef.git/commitdiff
Use default sandboxing for the blogs-update service
authorTom Hughes <tom@compton.nu>
Wed, 9 Nov 2022 20:26:16 +0000 (20:26 +0000)
committerTom Hughes <tom@compton.nu>
Wed, 9 Nov 2022 20:26:16 +0000 (20:26 +0000)
cookbooks/blogs/recipes/default.rb

index c4d425a5634151cecb93e54beb0169908c3feeae..6b181f2090714e70b1d461e4f45d2e61cf24dc20 100644 (file)
@@ -82,12 +82,8 @@ systemd_service "blogs-update" do
   description "Update blog aggregator"
   exec_start "/usr/local/bin/blogs-update"
   user "blogs"
-  private_tmp true
-  private_devices true
-  protect_system "strict"
-  protect_home true
+  sandbox :enable_network => true
   read_write_paths "/srv/blogs.openstreetmap.org"
-  no_new_privileges true
 end
 
 systemd_timer "blogs-update" do