Just have sane firewall rules and you are good. E.g. if I install openssh-server and it auto starts, it doesn't make it out of my machine because my nftables does not allow inbound on port 22. It's just knowing the default behaviour and adjusting your practices for it.
johnisgood|6 months ago
rbanffy|6 months ago
bayindirh|6 months ago
account42|6 months ago
teo_zero|6 months ago
mjochim|6 months ago
But you can't (easily) configure package X itself before you install it; and after you install it, it runs immediately so you only get to configure it after the first run.