From 28028b26b3371756811e95d894f709f4b1207c00 Mon Sep 17 00:00:00 2001 From: Michael Biebl Date: Wed, 18 Dec 2019 18:29:24 +0100 Subject: New upstream version 1.22.0 --- clients/cloud-setup/nm-cloud-setup.service.in | 36 +++++++++++++++++++++++++++ 1 file changed, 36 insertions(+) create mode 100644 clients/cloud-setup/nm-cloud-setup.service.in (limited to 'clients/cloud-setup/nm-cloud-setup.service.in') diff --git a/clients/cloud-setup/nm-cloud-setup.service.in b/clients/cloud-setup/nm-cloud-setup.service.in new file mode 100644 index 00000000..69a1a29c --- /dev/null +++ b/clients/cloud-setup/nm-cloud-setup.service.in @@ -0,0 +1,36 @@ +[Unit] +Description=Automatically configure NetworkManager in cloud +After=NetworkManager.service + +[Service] +Type=oneshot +ExecStart=@libexecdir@/nm-cloud-setup + +#Environment=NM_CLOUD_SETUP_LOG=TRACE + +# Cloud providers are disabled by default. You need to +# Opt-in by setting the right environment variable for +# the provider. +#Environment=NM_CLOUD_SETUP_EC2=yes + +CapabilityBoundingSet= +LockPersonality=yes +MemoryDenyWriteExecute=yes +NoNewPrivileges=yes +PrivateDevices=yes +PrivateTmp=yes +ProtectControlGroups=yes +ProtectHome=yes +ProtectHostname=yes +ProtectKernelLogs=yes +ProtectKernelModules=yes +ProtectKernelTunables=yes +ProtectSystem=strict +RestrictAddressFamilies=AF_UNIX AF_NETLINK AF_INET AF_INET6 +RestrictNamespaces=yes +RestrictRealtime=yes +RestrictSUIDSGID=yes +SystemCallFilter=@system-service + +[Install] +WantedBy=NetworkManager.service -- cgit 1.3.0-6-gf8a5