diff --git a/contrib/i2pd.service b/contrib/i2pd.service index 1ab46979..1eb8a92b 100644 --- a/contrib/i2pd.service +++ b/contrib/i2pd.service @@ -34,5 +34,20 @@ LimitNOFILE=8192 # To enable write of coredump uncomment this #LimitCORE=infinity +#hardening +ProtectHostname=true +ProtectKernelLogs=true +ProtectControlGroups=true +ProtectKernelModules=true +ProtectKernelTunables=true +ProtectProc=invisible +ProcSubset=pid +PrivateTmp=true +PrivateUsers=true +PrivateDevices=true +PrivateIPC=true +NoNewPrivileges=true +RestrictNamespaces=true + [Install] WantedBy=multi-user.target