14 lines
383 B
Text
14 lines
383 B
Text
|
{{ ansible_managed | comment }}
|
||
|
|
||
|
[Service]
|
||
|
PrivateDevices=yes
|
||
|
PrivateTmp=yes
|
||
|
ProtectHome=read-only
|
||
|
ProtectSystem=strict
|
||
|
ReadWritePaths=-/var/run/fail2ban
|
||
|
ReadWritePaths=-/var/lib/fail2ban
|
||
|
ReadWritePaths=-/var/log/fail2ban
|
||
|
ReadWritePaths=-/var/spool/postfix/maildrop
|
||
|
ReadWritePaths=-/run/xtables.lock
|
||
|
CapabilityBoundingSet=CAP_AUDIT_READ CAP_DAC_READ_SEARCH CAP_NET_ADMIN CAP_NET_RAW
|