3
0
Fork 0
forked from mirrors/nixpkgs
nixpkgs/nixos/modules/services
Félix Baylac-Jacqué 353a8b58e6
nixos/prosody: leverage systemd sandbox features to harden service
We are leveraging the systemd sandboxing features to prevent the
service accessing locations it shouldn't do. Most notably, we are here
preventing the prosody service from accessing /home and providing it
with a private /dev and /tmp.

Please consult man systemd.exec for further informations.
2020-04-30 20:40:00 +02:00
..
admin nixos/oxidized: add missing slash to PIDFile path 2020-01-06 16:58:54 +01:00
amqp treewide: add bool type to enable options, or make use of mkEnableOption 2020-04-21 08:55:36 +02:00
audio mopidy: Create a mopidyPackages set 2020-04-17 12:39:03 +01:00
backup treewide: add bool type to enable options, or make use of mkEnableOption 2020-04-21 08:55:36 +02:00
cluster The systemd unit for k3s should differ between agents and servers 2020-04-23 07:55:23 +02:00
computing nixos/boinc: create boinc group 2020-03-25 13:26:31 +01:00
continuous-integration hydra: wrap executables with hydra env vars 2020-04-11 14:36:42 +02:00
databases treewide: add bool type to enable options, or make use of mkEnableOption 2020-04-21 08:55:36 +02:00
desktops Merge pull request #83400 from jtojnar/malcontent-0.7 2020-04-08 17:38:17 +02:00
development nixos/jupyter: Fix documentation example for jupyter.kernels (#56415) 2020-01-31 15:30:02 +01:00
editors treewide: use attrs instead of list for types.loaOf options 2020-01-06 10:39:18 -05:00
games nixos/factorio: add extraSettings and package options 2020-01-10 23:36:14 +00:00
hardware treewide: add bool type to enable options, or make use of mkEnableOption 2020-04-21 08:55:36 +02:00
logging treewide: use attrs instead of list for types.loaOf options 2020-01-06 10:39:18 -05:00
mail treewide: add bool type to enable options, or make use of mkEnableOption 2020-04-21 08:55:36 +02:00
misc treewide: add bool type to enable options, or make use of mkEnableOption 2020-04-21 08:55:36 +02:00
monitoring nixos/datadog-agent: Fix restartTriggers 2020-04-23 09:58:18 +02:00
network-filesystems treewide: add bool type to enable options, or make use of mkEnableOption 2020-04-21 08:55:36 +02:00
networking nixos/prosody: leverage systemd sandbox features to harden service 2020-04-30 20:40:00 +02:00
printing treewide: use attrs instead of list for types.loaOf options 2020-01-06 10:39:18 -05:00
scheduling atd: systemd-udev-settle serves no purpose 2020-03-21 11:15:06 +08:00
search solr: drop 7.x series 2020-01-18 08:50:35 -05:00
security Merge pull request #79840 from knl/update-oauth2_proxy-to-5.0.0 2020-04-22 12:15:07 +02:00
system nixos/nscd: be more specific in the nscd.enable description on what breaks 2020-04-25 18:11:10 +02:00
torrent nixos/deluge: support 2.x 2020-04-18 02:00:04 +02:00
ttys treewide: use attrs instead of list for types.loaOf options 2020-01-06 10:39:18 -05:00
wayland nixos/cage: move ConditionPathExists to service config 2020-03-09 00:47:49 +01:00
web-apps nixos/dokuwiki: change default of aclFile and usersFile 2020-04-18 23:37:19 +02:00
web-servers Merge pull request #85043 from aanderse/httpd-2020 2020-04-25 20:04:05 -04:00
x11 Merge master into staging-next 2020-04-21 19:59:56 +02:00