Hacker News new | ask | show | jobs
by wavesquid 1391 days ago
> Requiring that I have to be root to set CAP_NET_BIND_SERVICE every time I replace my web server executable sucks.

There should be no need for that if you use ambient capabilities. Which you can set in e.g. a systemd unit.