Spyke

Adding PrivateNetwork=yes to your systemd units is a game changer for services that don't need network access - it completly isolates the service from the network and prevents any outbound connections.

4

Good callout! You're absolutely right, and here I was primarily focused on publicly accessible services. Thanks for the addition.

2
piefed.social

I definitely learnt (more than) a few things from your write up, thank you sir!

3

Very glad to gear it! Learning new stuff with Linux is the fun part of the journey.

2

You reached the end

Systemd Service Hardening | Spyke