Y
Hacker News
new
|
ask
|
show
|
jobs
by
tingletech
38 days ago
is that no longer true?
2 comments
bhaney
38 days ago
No, now you have the option of using CAP_NET_BIND_SERVICE
link
63stack
38 days ago
There is also net.ipv4.ip_unprivileged_port_start
link
jcgl
37 days ago
If the application supports it, there’s also systemd socket activation (or traditional inetd sorta stuff too if that fits)
link
jcgl
35 days ago
Forgot to mention: you can use systemd-socket-proxyd to bridge to an application that doesn't support socket activation too:
https://www.man7.org/linux/man-pages/man8/systemd-socket-pro...
link