Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

feat: limit /etc to readonly #1451

Open
wants to merge 3 commits into
base: develop
Choose a base branch
from

Conversation

staaldraad
Copy link

@staaldraad staaldraad commented Feb 18, 2025

What kind of change does this PR introduce?

Feature

What is the current behavior?

Please link any relevant issues here.

What is the new behavior?

https://www.freedesktop.org/software/systemd/man/latest/systemd.exec.html#ReadWritePaths=

Prevent postgres, or child-process of, from writing to /etc

@staaldraad staaldraad requested a review from a team as a code owner February 18, 2025 10:05
Copy link

linear bot commented Feb 18, 2025

@staaldraad staaldraad force-pushed the etienne/sec-197-use-nonewpriviliges-for-postgres branch from 51b7090 to e4f3d5e Compare February 18, 2025 14:21
@staaldraad staaldraad changed the title feat: no new priviliges for postgres feat: limit /etc to readonly Feb 18, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant