gtnh-service-hardening #36

Closed
Lithium wants to merge 0 commits from gtnh-service-hardening into main
Owner

Hardening the service to prevent escape hatches

  • ProtectSystem, ProtectHome, PrivateTmp, are used to prevent reading/writing to
    outside locations
  • NoNewPrivileges, ProtectKernelTunables, ProtectControlGroups, are used
    to prevent abusing privilege escalation exploits or techniques
  • ReadWritePaths is used to define where the service can Read/Write

This is probably as good as it gets for security.
This makes most exploits unusable.

It's probably a good idea to look into whether you can add or remove sudo from specific users.
It'd be really useful to be able to completely neuter a user from privilege escalation without rarely available RCEs.

In the end, the better way is to run the server inside a virtual machine.
The extra image size is barely anything if we keep to a minimal image.
We could also remove the tmux requirements by using a different linux distribution.

Hardening the service to prevent escape hatches - ProtectSystem, ProtectHome, PrivateTmp, are used to prevent reading/writing to outside locations - NoNewPrivileges, ProtectKernelTunables, ProtectControlGroups, are used to prevent abusing privilege escalation exploits or techniques - ReadWritePaths is used to define where the service can Read/Write This is probably as good as it gets for security. This makes most exploits unusable. It's probably a good idea to look into whether you can add or remove sudo from specific users. It'd be really useful to be able to completely neuter a user from privilege escalation without rarely available RCEs. In the end, the better way is to run the server inside a virtual machine. The extra image size is barely anything if we keep to a minimal image. We could also remove the tmux requirements by using a different linux distribution.
Hardening the service to prevent escape hatches
- ProtectSystem, ProtectHome, PrivateTmp, are used to prevent reading/writing to
  outside locations
- NoNewPrivileges, ProtectKernelTunables, ProtectControlGroups, are used
  to prevent abusing privilege escalation exploits or techniques
- ReadWritePaths is used to define where the service can Read/Write
Collaborator

LGTM

LGTM
MinoFloof changed title from gtnh-service-hardening to WIP: gtnh-service-hardening 2026-10-08 18:37:28 +02:00
MinoFloof changed title from WIP: gtnh-service-hardening to gtnh-service-hardening 2026-10-08 18:37:34 +02:00
MinoFloof approved these changes 2026-10-08 18:37:52 +02:00
MinoFloof closed this pull request 2026-10-10 13:43:51 +02:00

Pull request closed

Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Lithium/nixosConfig!36
No description provided.