3
0
Fork 0
forked from mirrors/nixpkgs

nixos/redis: allow access to runtime and state directories to only redis user

This commit is contained in:
Izorkin 2021-03-24 13:33:34 +03:00
parent 86d8b31e00
commit 9d4aaf2366
No known key found for this signature in database
GPG key ID: 1436C1B3F3679F09

View file

@ -283,11 +283,18 @@ in
serviceConfig = {
ExecStart = "${cfg.package}/bin/redis-server /run/redis/redis.conf";
RuntimeDirectory = "redis";
StateDirectory = "redis";
Type = "notify";
# User and group
User = "redis";
Group = "redis";
# Runtime directory and mode
RuntimeDirectory = "redis";
RuntimeDirectoryMode = "0750";
# State directory and mode
StateDirectory = "redis";
StateDirectoryMode = "0700";
# Access write directories
UMask = "0077";
};
};
};