▲ | jcgl 7 days ago | |||||||
> this will not take off I'm afraid, because locking these unitfiles down is offloaded to the end-user Maybe your point is that this isn't done by the vendor in practice. And I'm sure there's room for lots of improvement. However, one of the great things about how systemd units can be provided by the vendor and seamlessly tweaked by the administrator is that the vendor (i.e. packager and/or distro) can set these up easily. There definitely are packages that ship with locked-down files. Tor and powerdns (pdns) are two off the top of my head.
| ||||||||
▲ | DyslexicAtheist 7 days ago | parent [-] | |||||||
I think it should be done by the maintainer of the software not by the distro. My concern is that these features are available since at least 5 years and it has not yet caught on (regardless of what this blog article recommends). It would be great to see it implemented but for now at least on Debian/sid the situation is as follows:
| ||||||||
|