diff --git a/modules/qbittorrent/default.nix b/modules/qbittorrent/default.nix index ad41ba2..b0a2a45 100644 --- a/modules/qbittorrent/default.nix +++ b/modules/qbittorrent/default.nix @@ -94,6 +94,16 @@ in # Increase number of open file descriptors (default: 1024) LimitNOFILE = 65536; + # Avoid using nscd (leaks dns) + InaccessiblePaths = [ + "/run/nscd" + ]; + # Make correct resolv.conf available for unit + BindReadOnlyPaths = [ + "/etc/netns/qbittorrent/resolv.conf:/etc/resolv.conf" + ]; + + # systemd-analyze --no-pager security qbittorrent.service CapabilityBoundingSet = null; PrivateDevices = true;