diff --git a/etc/systemd/system/drone.service b/etc/systemd/system/drone.service index e8e9b75..51ca8e3 100644 --- a/etc/systemd/system/drone.service +++ b/etc/systemd/system/drone.service @@ -37,6 +37,7 @@ ProtectKernelLogs=true ProtectControlGroups=true LockPersonality=true MemoryDenyWriteExecute=true +RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 RestrictRealtime=true RestrictSUIDSGID=true SystemCallArchitectures=native