add cap_net_bind_service to systemd unit

this allows running on port 80 as non privileged user.
This commit is contained in:
Jeff 2021-05-08 15:50:22 -04:00 committed by GitHub
parent f6867e7666
commit 4450ce7f8a
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 2 additions and 0 deletions

View File

@ -7,6 +7,8 @@ StartLimitInterval=0
[Service]
User=_loki
Type=simple
CapabilityBoundingSet=CAP_NET_BIND_SERVICE
AmbientCapabilities=CAP_NET_BIND_SERVICE
ExecStart=/usr/bin/session-open-group-server
WorkingDirectory=/var/lib/session-open-group-server
Restart=on-failure