@lanodanlanodan wrote: Hi, maybe for the Linux side of things it could use capabilities(7) and/or something like AppArmor+SELinux? capabilities would allow to drop all SuperUser privileges and only keep the ones needed. AppArmor/SELinux would allow to also restrict capabilities and their actions further.
https://misskey-taube.s3.eu-central-1.wasabisys.com/files/defc51ce-fab8-43f3-893a-615e7f8155c2.webp