Martin Weinelt 7d09d7f571
nixos/home-assistant: harden systemd service
This is what is still exposed, and it should still allow things to work
as usual.

✗ PrivateNetwork=                    Service has access to the host's …      0.5
✗ RestrictAddressFamilies=~AF_(INET… Service may allocate Internet soc…      0.3
✗ DeviceAllow=                       Service has a device ACL with som…      0.1
✗ IPAddressDeny=                     Service does not define an IP add…      0.2
✗ PrivateDevices=                    Service potentially has access to…      0.2
✗ PrivateUsers=                      Service has access to other users       0.2
✗ SystemCallFilter=~@resources       System call allow list defined fo…      0.2
✗ RootDirectory=/RootImage=          Service runs within the host's ro…      0.1
✗ SupplementaryGroups=               Service runs with supplementary g…      0.1
✗ RestrictAddressFamilies=~AF_UNIX   Service may allocate local sockets      0.1

→ Overall exposure level for home-assistant.service: 1.6 OK :-)

This can grow to as much as ~1.9 if you use one of the bluetooth or nmap
trackers or the emulated_hue component, all of which required elevated
permisssions.
2021-05-03 00:21:24 +02:00
..
2020-03-10 22:45:33 +01:00
2021-01-24 13:17:07 +01:00
2021-01-26 12:24:48 +01:00
2021-04-27 10:41:07 -07:00
2021-02-17 10:43:08 +01:00
2019-12-25 10:33:50 -05:00
2021-01-27 11:44:59 -08:00
2020-11-24 12:42:06 -05:00
2020-11-28 06:50:52 +01:00
2020-10-11 15:55:50 -07:00
2021-03-03 11:15:35 -08:00
2021-04-04 01:43:46 +02:00
2020-10-08 16:04:11 +02:00
2020-12-05 11:02:40 +01:00
2020-12-21 19:41:24 +01:00
2021-04-29 10:52:02 +03:00
2020-08-09 01:52:22 +02:00
2021-02-23 15:35:16 +01:00
2021-04-15 20:57:21 +00:00
2021-02-03 15:59:17 +08:00
2020-11-23 08:42:51 +10:00
2020-08-24 10:10:47 -04:00
2021-01-31 12:17:41 +01:00
2021-01-31 12:59:04 +01:00