Files
aur-packages/adguardhome/adguardhome.service
Giovanni Harting 87509e9cdb upgpkg: adguardhome 1:0.107.46-2
more systemd service hardening
2024-03-23 18:08:17 +01:00

26 lines
620 B
Desktop File

[Unit]
Description=AdGuard Home: Network-level blocker
After=syslog.target network-online.target
[Service]
DynamicUser=true
StateDirectory=adguardhome
WorkingDirectory=/var/lib/adguardhome
AmbientCapabilities=CAP_NET_BIND_SERVICE CAP_NET_RAW
CapabilityBoundingSet=CAP_NET_BIND_SERVICE CAP_NET_RAW
ExecStart=/usr/bin/adguardhome -w /var/lib/adguardhome -l syslog
PrivateTmp=true
ProtectSystem=strict
ProtectHome=true
PrivateDevices=true
ProtectKernelTunables=true
ProtectControlGroups=true
NoNewPrivileges=true
MemoryDenyWriteExecute=true
LockPersonality=true
ProtectHostname=true
[Install]
WantedBy=multi-user.target