A hardened service repeatedly regresses to insecure or …
A tmpfiles.d rule recreates a directory at boot with permissive ownership, undoing the tighter mode that the service requires after every restart
Permissions look correct after manual fixes, yet the next reboot reopens the security hole because tmpfiles policy rebuilds the directory differently from the service's expectation.
시나리오
단서
구독하면 이어서 볼 수 있어요
이 문제의 전체 시나리오와 점검 체크리스트, 복구 순서, 모범 풀이는 Pro 구독에서 열립니다.
먼저 볼 것
점검 체크리스트
복구와 재발 방지
같이 보면 좋은 질문
현장에서 본 비슷한 케이스