nixos/gerrit: Enable PrivateMounts hardening in service config

Signed-off-by: Felix Singer <felixsinger@posteo.net>
This commit is contained in:
Felix Singer 2025-10-04 11:58:09 +02:00
parent 40d07fb1a0
commit 26d0023f71

View file

@ -232,6 +232,7 @@ in
LockPersonality = true;
NoNewPrivileges = true;
PrivateDevices = true;
PrivateMounts = true;
PrivateTmp = true;
ProtectClock = true;
ProtectControlGroups = true;