diff --git a/deploy/systemd/aitrader-dashboard.service b/deploy/systemd/aitrader-dashboard.service index eb1adc8..2657a8b 100644 --- a/deploy/systemd/aitrader-dashboard.service +++ b/deploy/systemd/aitrader-dashboard.service @@ -23,7 +23,7 @@ StandardError=journal NoNewPrivileges=true ProtectSystem=strict -ProtectHome=true +ProtectHome=false ReadWritePaths=/opt/aitrader/data PrivateTmp=true diff --git a/deploy/systemd/aitrader.service b/deploy/systemd/aitrader.service index 442db33..c22d46c 100644 --- a/deploy/systemd/aitrader.service +++ b/deploy/systemd/aitrader.service @@ -18,7 +18,8 @@ StandardError=journal # Hardening NoNewPrivileges=true ProtectSystem=strict -ProtectHome=true +# ProtectHome=false weil uv den Python-Interpreter in /home/aitrader/.local/share/uv ablegt +ProtectHome=false ReadWritePaths=/opt/aitrader/data PrivateTmp=true ProtectKernelTunables=true