| Commit message (Collapse) | Author | Age | Files | 
| | 
| 
| 
| 
| 
|  | 
Use unit overrides on top of upstream's service files instead of
overriding entire service files.  In particular, upstream uses flag `-P`
so we don't need to use RuntimeDirectory= anymore.
 | 
| |  | 
 | 
| |  | 
 | 
| | 
| 
| 
| 
| 
| 
| 
| 
|  | 
* Use nftables sets with a timeout
 * Start daemon with a hardened unit file and restricted Capability
   Bounding Set.  (This requires to change the log path to
   /var/log/fail2ban/*.)
 * Skip database as we don't care about persistence.
 * Refactor jail.local
 | 
| |  | 
 | 
| | 
| 
| 
|  | 
Inspired from /lib/systemd/system/bacula-fd.service.
 | 
| | 
| 
| 
|  | 
And remove ‘ReadOnlyDirectories=/’ as it's implied by ‘ProtectSystem=strict’.
 | 
|    | 
 |