From 726b9d2b2c95d1ae3c839aca8fd0f214432eddde Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?=F0=9D=95=8D=F0=9D=95=96=F0=9D=95=9D=F0=9D=95=A0?= =?UTF-8?q?=F0=9D=95=94=F0=9D=95=9A=F0=9D=95=97=F0=9D=95=AA=F0=9D=95=96?= =?UTF-8?q?=F0=9D=95=A3?= Date: Sun, 19 Oct 2025 14:20:10 -0400 Subject: [PATCH] Add sandboxing to ntfy.service. See [systemd.exec(5)](https://man.archlinux.org/man/systemd.exec.5) to find out what the options mean! --- server/ntfy.service | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/server/ntfy.service b/server/ntfy.service index 8bf250a5..df420404 100644 --- a/server/ntfy.service +++ b/server/ntfy.service @@ -10,6 +10,18 @@ ExecReload=/bin/kill --signal HUP $MAINPID Restart=on-failure AmbientCapabilities=CAP_NET_BIND_SERVICE LimitNOFILE=10000 +PrivateDevices=true +ProtectClock=true +ProtectKernelTunables=true +ProtectKernelModules=true +ProtectKernelLogs=true +RestrictRealtime=true +ProtectHostname=true + +# These will be added in a future update. +# ProtectSystem=full +# PrivateTmp=true + [Install] WantedBy=multi-user.target