Post #3024023
2026-04-30 11:57 UTC
@s0@cathode.church basically you want to lock as much down as you can for each service without impacting functionality. less kernel surface area exposed = less bugs you have to care about
Replies (2)
-
@s0@cathode.church 2026-04-30 11:58
@hailey@hails.org yeah makes sense, but I’m also not going to have time to define 200 options for dozens of services/PCs for homeserver stuff, so arch repos are helpful to crib off.
-
@trisschen@plural.cafe 2026-05-07 22:27
@hailey@hails.org @s0@cathode.church I also found systemd-analyze security [unit] to be useful to get an idea of what’s more important to look into, and to check whether I missed something when writing a unit file