NoNewPrivileges on most containers. drop all caps on a few others

This commit is contained in:
zenfyr 2026-01-11 14:11:56 +07:00
commit b3e4af5aca
Signed by: melontini
SSH key fingerprint: SHA256:TtcIcnTnoAB5mqHofsaOxIgiMzfVBxej1AXT7DQdrTE
36 changed files with 80 additions and 1 deletions

View file

@ -21,6 +21,8 @@ Volume=/var/containers/ejabberd/config:/opt/ejabberd/conf:ro,Z
Volume=/var/containers/ejabberd/files:/opt/ejabberd/upload:Z
Volume=/var/containers/ejabberd/database:/opt/ejabberd/database:Z
Volume=/etc/certs:/etc/letsencrypt/live:ro,z
# Security
NoNewPrivileges=true
[Service]
Restart=always