Add CAP_NET_RAW and CAP_DAC_READ_SEARCH capabilities

This commit is contained in:
Jamil Bou Kheir
2021-01-27 17:29:42 -08:00
parent 3a5c0eecbf
commit 89dd732bda

View File

@@ -7,7 +7,7 @@ After=postgresql.service
Restart=on-failure
RestartSec=1
User=fireguard
AmbientCapabilities=CAP_NET_ADMIN
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_RAW CAP_DAC_READ_SEARCH
EnvironmentFile=/opt/fireguard/config.env
ExecStartPre=/opt/fireguard/bin/fireguard eval "FgHttp.Release.migrate"
ExecStart=/opt/fireguard/bin/fireguard start