feat: complete nx9-wg v0.8.0 platform
This commit is contained in:
1 parent
c75e5c4e71
commit
c8a9b7cde6
52 files changed
+7751
-725
No files matched your search
+19
-6
@@ -9,10 +9,11 @@ Type=simple
|
||||
User=root
|
||||
Group=root
|
||||
|
||||
# Environment configuration file
|
||||
# Environment configuration file (optional override)
|
||||
EnvironmentFile=-/etc/nx9-wg/nx9-wg.env
|
||||
|
||||
# Executable location and invocation
|
||||
# Working directory and execution
|
||||
WorkingDirectory=/var/lib/nx9-wg
|
||||
ExecStart=/usr/local/bin/nx9-wg --config /etc/nx9-wg/config.toml --data-dir /var/lib/nx9-wg serve
|
||||
|
||||
# Process management and restart policy
|
||||
@@ -21,18 +22,30 @@ RestartSec=5s
|
||||
KillMode=process
|
||||
TimeoutStopSec=15s
|
||||
|
||||
# Security Hardening & Linux Capability Bounds
|
||||
# Linux Capabilities for Native Netlink & Port Binding
|
||||
CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
|
||||
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
|
||||
NoNewPrivileges=true
|
||||
|
||||
# Filesystem Isolation
|
||||
# Sandboxing and System Hardening
|
||||
ProtectSystem=strict
|
||||
ProtectHome=true
|
||||
PrivateTmp=true
|
||||
ProtectKernelTunables=false
|
||||
ProtectControlGroups=true
|
||||
ReadWritePaths=/var/lib/nx9-wg /etc/nx9-wg /var/log
|
||||
RestrictSUIDSGID=true
|
||||
LockPersonality=true
|
||||
MemoryDenyWriteExecute=false
|
||||
RestrictRealtime=true
|
||||
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK
|
||||
|
||||
# Kernel procfs IP forwarding management requires procfs writes
|
||||
ProtectKernelTunables=false
|
||||
|
||||
# Systemd managed state, configuration, and log directories
|
||||
StateDirectory=nx9-wg
|
||||
ConfigurationDirectory=nx9-wg
|
||||
LogsDirectory=nx9-wg
|
||||
ReadWritePaths=/var/lib/nx9-wg /etc/nx9-wg /var/log/nx9-wg /proc/sys/net
|
||||
|
||||
# Resource Limits
|
||||
LimitNOFILE=65536
|
||||
|
||||
Reference in new issue
Block a user