-
Notifications
You must be signed in to change notification settings - Fork 293
Open
Labels
enhancementneeds triageWaiting for discussion / prioritization by teamWaiting for discussion / prioritization by team
Description
Hello!
- Vote on this issue by adding a 👍 reaction
- If you want to implement this feature, comment to let us know (we'll work with you on design, scheduling, etc.)
Issue details
The systemd service examples in https://github.com/smallstep/cli/tree/master/systemd lack sandboxing options.
Why is this needed?
There's no need to run step with so many capabilities and it creates unnecessary security risk.
Happy to submit a PR for this as I've already done the work to figure out the minimum set of capabilities needed.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementneeds triageWaiting for discussion / prioritization by teamWaiting for discussion / prioritization by team