summaryrefslogtreecommitdiff
path: root/analytics/analytics.service
diff options
context:
space:
mode:
Diffstat (limited to 'analytics/analytics.service')
-rw-r--r--analytics/analytics.service28
1 files changed, 28 insertions, 0 deletions
diff --git a/analytics/analytics.service b/analytics/analytics.service
new file mode 100644
index 0000000..461a940
--- /dev/null
+++ b/analytics/analytics.service
@@ -0,0 +1,28 @@
+[Unit]
+Description=analytics server
+
+[Service]
+Type=simple
+ExecStart=/usr/sbin/analytics
+
+LockPersonality=yes
+MemoryDenyWriteExecute=yes
+NoNewPrivileges=yes
+CapabilityBoundingSet=
+PrivateDevices=yes
+PrivateNetwork=yes
+PrivateTmp=yes
+ProtectClock=yes
+ProtectControlGroups=yes
+ProtectHome=yes
+ProtectHostname=yes
+ProtectKernelModules=yes
+ProtectKernelTunables=yes
+ProtectKernelLogs=yes
+ProtectSystem=strict
+RestrictAddressFamilies=AF_UNIX
+RestrictNamespaces=yes
+RestrictRealtime=yes
+RestrictSUIDSGID=yes
+SystemCallArchitectures=native
+SystemCallFilter=@system-service