set ManagedOOMPreference=avoid to default systemd unit

Signed-off-by: June Strawberry <june@vern.cc>
This commit is contained in:
June Strawberry
2026-02-02 18:17:21 -05:00
parent 5110b9e47b
commit 3b4300d033
3 changed files with 6 additions and 0 deletions

View File

@@ -25,6 +25,8 @@ TTYRows=40
AmbientCapabilities=
CapabilityBoundingSet=
ManagedOOMPreference=avoid
DevicePolicy=closed
LockPersonality=yes
MemoryDenyWriteExecute=yes

View File

@@ -18,6 +18,8 @@ ReadWritePaths=/var/lib/tuwunel /etc/tuwunel
AmbientCapabilities=
CapabilityBoundingSet=
ManagedOOMPreference=avoid
DevicePolicy=closed
LockPersonality=yes
MemoryDenyWriteExecute=yes

View File

@@ -18,6 +18,8 @@ ReadWritePaths=/var/lib/tuwunel /etc/tuwunel
AmbientCapabilities=
CapabilityBoundingSet=
ManagedOOMPreference=avoid
DevicePolicy=closed
LockPersonality=yes
MemoryDenyWriteExecute=yes