systemd Service Hardening: Security-Optionen für Production
Issue Complete - Ready for Merge
Implementation: 6 security lines in furt.service
Testing: Debian + Arch successful
Documentation: Included in issue description
**Performance…
systemd Service Hardening: Security-Optionen für Production
systemd Service Hardening: Security-Optionen für Production
Issue #110: systemd Service Hardening - Pragmatische Security-Optionen
State: open
Labels: effort/small, priority/medium, status/to-go, type/security
Milestone: v0.1.2 -…
systemd Service Hardening: Security-Optionen für Production
Multi-Distro Testing: COMPLETE ✅
Testing Results:
johann (Debian 12, systemd 247): ✅ All features working klaus (Arch Linux, systemd ~256): ✅ All features working
**S…
systemd Service Hardening: Security-Optionen für Production
Debian Testing: SUCCESS ✅
johann (Debian 12, systemd 247):
- Service starts normally with all security options
- API responds on localhost:7811
- Memory usage: 812K (no performance…
systemd Service Hardening: Security-Optionen für Production
Issue-Scope Reduction
Nach Review reduziert auf pragmatische Security-Optionen:
Entfernt: SystemCallFilter, Capabilities, IPv6, Memory-Protection Grund: Security-Theater vs.…
validate-config.sh: False-positive 'server port not configured' error
Fix confirmed working on werner:
- validate-config.sh now works correctly with POSIX regex
- Configuration validation passes successfully
- Service health check confirms functionality -…
validate-config.sh: False-positive 'server port not configured' error
Service-Management: pexp-Pattern durch PID-File ersetzen
✅ Issue #100 Successfully Completed
Implementation completed and tested on werner (OpenBSD):
✅ Changes Made
- PID-directory creation in setup-directories.sh (/var/run/furt/…
Service-Management: pexp-Pattern durch PID-File ersetzen
install.sh: Add --update-services parameter for service script updates
validate-config.sh: False-positive 'server port not configured' error