NoNewPrivileges on most containers. drop all caps on a few others

This commit is contained in:
zenfyr 2026-01-11 14:11:56 +07:00
commit b3e4af5aca
Signed by: melontini
SSH key fingerprint: SHA256:TtcIcnTnoAB5mqHofsaOxIgiMzfVBxej1AXT7DQdrTE
36 changed files with 80 additions and 1 deletions

View file

@ -18,6 +18,8 @@ PublishPort=127.0.0.1:47815:3002
Volume=/var/containers/sharkey/files:/sharkey/files:z
Volume=/var/containers/sharkey/activity:/sharkey/.config:z
Volume=/var/containers/sharkey/default.yml:/sharkey/.config/default.yml:ro,z
# Security
NoNewPrivileges=true
[Service]
Restart=always

View file

@ -17,6 +17,8 @@ PublishPort=127.0.0.1:60628:3001
Volume=/var/containers/sharkey/files:/sharkey/files:z
Volume=/var/containers/sharkey/api:/sharkey/.config:z
Volume=/var/containers/sharkey/default.yml:/sharkey/.config/default.yml:ro,z
# Security
NoNewPrivileges=true
[Service]
Restart=always

View file

@ -17,6 +17,8 @@ HealthCmd=redis-cli ping
HealthOnFailure=kill
HealthStartPeriod=10s
Notify=healthy
# Security
NoNewPrivileges=true
[Service]
Restart=always

View file

@ -18,6 +18,8 @@ PublishPort=127.0.0.1:57378:3003
Volume=/var/containers/sharkey/files:/sharkey/files:z
Volume=/var/containers/sharkey/media:/sharkey/.config:z
Volume=/var/containers/sharkey/default.yml:/sharkey/.config/default.yml:ro,z
# Security
NoNewPrivileges=true
[Service]
Restart=always

View file

@ -15,6 +15,8 @@ Network=postgresql.network
Volume=/var/containers/sharkey/files:/sharkey/files:z
Volume=/var/containers/sharkey/worker:/sharkey/.config:z
Volume=/var/containers/sharkey/default.yml:/sharkey/.config/default.yml:ro,z
# Security
NoNewPrivileges=true
[Service]
Restart=always