Merge pull request #283298 from mkg20001/rustdesk-dynamic

rustdesk-server: use DynamicUser

Changed files
+1 -5
nixos
modules
services
monitoring
+1 -5
nixos/modules/services/monitoring/rustdesk-server.nix
···
Slice = "system-rustdesk.slice";
User = "rustdesk";
Group = "rustdesk";
+
DynamicUser = "yes";
Environment = [];
WorkingDirectory = "/var/lib/rustdesk";
StateDirectory = "rustdesk";
StateDirectoryMode = "0750";
LockPersonality = true;
-
NoNewPrivileges = true;
PrivateDevices = true;
PrivateMounts = true;
-
PrivateTmp = true;
PrivateUsers = true;
ProtectClock = true;
ProtectControlGroups = true;
···
ProtectKernelModules = true;
ProtectKernelTunables = true;
ProtectProc = "invisible";
-
ProtectSystem = "strict";
-
RemoveIPC = true;
RestrictNamespaces = true;
-
RestrictSUIDSGID = true;
};
};
in lib.mkIf cfg.enable {