3 ms·
I create a separate user for each app, and use the systemd exec configuration [1] for sandboxing [2]. Some apps only get read-only access to their own files, an
by LaputanMachine 4y ago
I create a separate user for each app, and use the systemd exec configuration [1] for sandboxing [2]. Some apps only get read-only access to their own files, and no Internet access, for example (along with many other restrictions). I have some systemd drop-in units that I frequently reuse.
For standard services, I use Apparmor with the default `apparmor-profiles`, as well as fail2ban with some additional firewall rules.
[1]: https://man.archlinux.org/man/systemd.exec.5 https://man.archlinux.org/man/systemd.exec.5
[2]: https://wiki.archlinux.org/title/User:NetSysFire/systemd_sandboxing https://wiki.archlinux.org/title/User:NetSysFire/systemd_san...