فهرست منبع

Update sample systemd service file comments about more granular read-only filesystem settings.

Dan Helfman 3 سال پیش
والد
کامیت
1004500d65
2فایلهای تغییر یافته به همراه5 افزوده شده و 4 حذف شده
  1. 1 0
      NEWS
  2. 4 4
      sample/systemd/borgmatic.service

+ 1 - 0
NEWS

@@ -1,4 +1,5 @@
 1.5.19.dev0
+ * Update sample systemd service file with more granular read-only filesystem settings.
  * Move Gitea and GitHub hosting from a personal namespace to an organization for better
    collaboration with related projects.
  * 1k ★s on GitHub!

+ 4 - 4
sample/systemd/borgmatic.service

@@ -32,10 +32,10 @@ RestrictSUIDSGID=yes
 SystemCallArchitectures=native
 SystemCallFilter=@system-service
 SystemCallErrorNumber=EPERM
-# Restrict write access
-# Change to 'ProtectSystem=strict' and uncomment 'ProtectHome' to make the whole file
-# system read-only be default and uncomment 'ReadWritePaths' for the required write access.
-# Add local repositroy paths to the list of 'ReadWritePaths' like '-/mnt/my_backup_drive'.
+# To restrict write access further, change "ProtectSystem" to "strict" and uncomment
+# "ReadWritePaths", "ReadOnlyPaths", "ProtectHome", and "BindPaths". Then add any local repository
+# paths to the list of "ReadWritePaths" and local backup source paths to "ReadOnlyPaths". This
+# leaves most of the filesystem read-only to borgmatic.
 ProtectSystem=full
 # ReadWritePaths=-/mnt/my_backup_drive
 # ReadOnlyPaths=-/var/lib/my_backup_source