diff --git a/etc/systemd/system/drone.service b/etc/systemd/system/drone.service index e55adce..83ab5e4 100644 --- a/etc/systemd/system/drone.service +++ b/etc/systemd/system/drone.service @@ -22,7 +22,7 @@ SystemCallFilter=~memfd_create @reboot @swap @resources @cpu-emulation @debug @m ProtectProc=invisible ProcSubset=pid ProtectHome=true -RestrictNamespaces=uts ipc pid user cgroup +RestrictNamespaces=true NoNewPrivileges=True # SecureBits=noroot-locked ProtectSystem=strict