|  | Commit message (Collapse) | Author | Age | Files | 
|---|
| | 
| 
| 
| 
| 
| | Use unit overrides on top of upstream's service files instead of
overriding entire service files.  In particular, upstream uses flag `-P`
so we don't need to use RuntimeDirectory= anymore. | 
| | |  | 
| | |  | 
| | 
| 
| 
| 
| 
| 
| 
| 
| | * Use nftables sets with a timeout
 * Start daemon with a hardened unit file and restricted Capability
   Bounding Set.  (This requires to change the log path to
   /var/log/fail2ban/*.)
 * Skip database as we don't care about persistence.
 * Refactor jail.local | 
| | |  | 
| | 
| 
| 
| | Inspired from /lib/systemd/system/bacula-fd.service. | 
| | 
| 
| 
| | And remove ‘ReadOnlyDirectories=/’ as it's implied by ‘ProtectSystem=strict’. | 
|  |  |