- Add Capability=all for full capabilities - Add SystemCallFilter=@keyring bpf for required syscalls - Set PrivateUsers=no to avoid user namespace issues - Set SuppressSync=false for Docker compatibility - Fixes audit errors in nested systemd-nspawn containers
3.1 KiB
Executable File
3.1 KiB
Executable File