logoalt Hacker News

storystarlingyesterday at 10:00 PM1 replyview on HN

I solved the port 80 issue by adding AmbientCapabilities=CAP_NET_BIND_SERVICE to the Service section of the unit file. That lets you bind privileged ports while still defining a User= line to run non-root. The lifecycle management seems solid in my experience, no force kills required.


Replies

plagiaristyesterday at 10:16 PM

Well, thank you, I will give it a try