diff --git a/package/alertmanager/alertmanager.service b/package/alertmanager/alertmanager.service index df779ac..e6e2218 100644 --- a/package/alertmanager/alertmanager.service +++ b/package/alertmanager/alertmanager.service @@ -15,11 +15,13 @@ ExecStart=/usr/sbin/alertmanager \ --web.listen-address=${WEB_LISTEN_ADDRESS} ExecReload=/bin/kill -HUP $MAINPID Restart=on-failure +User=alertmanager +StateDirectory=alertmanager +WorkingDirectory=/var/lib/alertmanager CapabilityBoundingSet= DeviceAllow= DevicePolicy=closed -DynamicUser=yes LockPersonality=yes MemoryDenyWriteExecute=yes NoNewPrivileges=yes