nixos/typesense: disable MemoryDenyWriteExecute which is needed since 0.25.1

also adjust default state directory mode to allow typesense group
This commit is contained in:
oddlama 2023-09-23 16:37:23 +02:00
parent 9edb077ace
commit 11d4f6e4a8
No known key found for this signature in database
GPG Key ID: 14EFE510775FE39A

View File

@ -83,12 +83,12 @@ in {
Group = "typesense";
StateDirectory = "typesense";
StateDirectoryMode = "0700";
StateDirectoryMode = "0750";
# Hardening
CapabilityBoundingSet = "";
LockPersonality = true;
MemoryDenyWriteExecute = true;
# MemoryDenyWriteExecute = true; needed since 0.25.1
NoNewPrivileges = true;
PrivateUsers = true;
PrivateTmp = true;