roles/common: Harden fail2ban service on Ubuntu 20.04

This commit is contained in:
Alan Orth 2020-04-25 14:22:46 +03:00
parent 96f62a17d1
commit 870bdbfcc3
1 changed files with 2 additions and 2 deletions

View File

@ -2,14 +2,14 @@
PrivateDevices=yes
PrivateTmp=yes
ProtectHome=read-only
{% if ansible_distribution == 'Ubuntu' and ansible_distribution_major_version is version('18','==') %}
{% if ansible_distribution == 'Ubuntu' and ansible_distribution_major_version is version('18','>=') %}
ProtectSystem=strict
{% else %}
{# Older systemd versions don't have ProtectSystem=strict #}
ProtectSystem=full
{% endif %}
NoNewPrivileges=yes
{% if ansible_distribution == 'Ubuntu' and ansible_distribution_major_version is version('18','==') %}
{% if ansible_distribution == 'Ubuntu' and ansible_distribution_major_version is version('18','>=') %}
ReadWritePaths=-/var/run/fail2ban
ReadWritePaths=-/var/lib/fail2ban
ReadWritePaths=-/var/log/fail2ban.log