Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- RootDirectory=/mnt/clerk
- MountFlags=private
- TemporaryFileSystem=/run:ro
- BindPaths=/run/clerk
- BindPaths=/data/clerk:/data
- BindReadOnlyPaths=/sys:/sys
- BindReadOnlyPaths=/proc:/proc:norbind
- BindReadOnlyPaths=/dev:/dev:norbind
- BindReadOnlyPaths=/run/dspd
- BindReadOnlyPaths=/run/updater
- BindReadOnlyPaths=/usr/share/zoneinfo
- BindReadOnlyPaths=/etc/passwd
- BindReadOnlyPaths=/etc/group
- BindReadOnlyPaths=/personality
- BindReadOnlyPaths=/run/systemd/journal/socket
- BindReadOnlyPaths=/run/systemd/notify
- BindReadOnlyPaths=/run/systemd/resolve
- BindReadOnlyPaths=/run/dbus
- DevicePolicy=closed
- DeviceAllow=/dev/uio/adc-buffer r
- NoNewPrivileges=yes
- CapabilityBoundingSet=CAP_NET_BIND_SERVICE
- AmbientCapabilities=CAP_NET_BIND_SERVICE
- User=clerk
- Group=clerk
- SupplementaryGroups=dspd updater
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement