nixos: additional hardening for dnscrypt-proxy
- Run as unprivileged user/group via systemd, obviating the need to specify capabilities, etc.- Run with private tmp and minimal device name space
Joachim Fasting 10 years ago a88a6bc6 823bb5dd