bundlewrap/README.md
2022-03-26 13:55:59 +01:00

1,011 B

TODO

  • dont spamfilter forwarded mails
  • gollum wiki
  • blog?
  • fix dkim not working sometimes
  • LDAP
  • oauth2/OpenID
  • icinga

Raspberry pi as soundcard

systemd hardening

[Unit] Description=TEST

[Service] Type=oneshot ExecStart=/opt/test

ProtectSystem=strict ProtectHome=yes PrivateTmp=yes PrivateDevices=yes PrivateNetwork=yes PrivateUsers=yes ProtectHostname=yes ProtectClock=yes ProtectKernelTunables=yes ProtectKernelModules=yes ProtectKernelLogs=yes ProtectControlGroups=yes RestrictAddressFamilies=none RestrictFileSystems=ext4 tmpfs zfs RestrictNamespaces=yes LockPersonality=yes MemoryDenyWriteExecute=yes RestrictRealtime=yes RestrictSUIDSGID=yes RemoveIPC=yes PrivateMounts=yes SystemCallFilter= SystemCallArchitectures=native CapabilityBoundingSet=

ReadOnlyPaths=/

NoExecPaths=/ ExecPaths=/opt/test /bin/bash /lib

[Install] WantedBy=multi-user.target