configpolicy/roles/docker/files/protect-system.systemd.conf

5 lines
109 B
Plaintext

[Service]
ReadOnlyDirectories=/
ReadWriteDirectories=/var /run /proc /sys/fs/cgroup /dev/pts
PrivateTmp=true