mirror of
https://github.com/xcat2/confluent.git
synced 2024-11-28 20:39:40 +00:00
Remove PrivateDevices from unit file
PrivateDevices breaks pam_unix, for some reason. Remove this protection. We still have DevicePolicy closed and running as non-root, so this should still be relatively safe.i
This commit is contained in:
parent
4437e81e04
commit
c0cd6de4f7
@ -18,7 +18,6 @@ AmbientCapabilities=CAP_NET_BIND_SERVICE CAP_SETUID CAP_SETGID CAP_CHOWN
|
||||
User=confluent
|
||||
Group=confluent
|
||||
DevicePolicy=closed
|
||||
PrivateDevices=true
|
||||
ProtectControlGroups=true
|
||||
ProtectSystem=true
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user