P6-01 + P6-02: agent self-update + fleet update #19
@@ -52,7 +52,12 @@ ProtectSystem=full
|
|||||||
# whenever a new SecretsKey is minted, so we need a targeted
|
# whenever a new SecretsKey is minted, so we need a targeted
|
||||||
# write-exemption for that dir. No exemption for the rest of /etc:
|
# write-exemption for that dir. No exemption for the rest of /etc:
|
||||||
# the agent has no business editing /etc/passwd, /etc/sudoers, etc.
|
# the agent has no business editing /etc/passwd, /etc/sudoers, etc.
|
||||||
ReadWritePaths=/etc/restic-manager
|
#
|
||||||
|
# /usr/local/bin is writable so the self-update flow (P6-01) can
|
||||||
|
# atomic-rename a fresh binary over the running one. Permitting the
|
||||||
|
# whole directory (rather than just the binary path) is required
|
||||||
|
# because os.Rename takes a write lock on the parent dir.
|
||||||
|
ReadWritePaths=/etc/restic-manager /usr/local/bin
|
||||||
ProtectHostname=true
|
ProtectHostname=true
|
||||||
ProtectKernelTunables=true
|
ProtectKernelTunables=true
|
||||||
ProtectKernelModules=true
|
ProtectKernelModules=true
|
||||||
|
|||||||
Reference in New Issue
Block a user