[Unit] Description=tangled knot 2 server After=network-online.target Wants=network-online.target StartLimitIntervalSec=60 StartLimitBurst=5 [Service] ExecStart=/usr/local/bin/knot-server /var/lib/knot/config.toml User=git Group=git StateDirectory=knot WorkingDirectory=/var/lib/knot Environment=HOME=/var/lib/knot EnvironmentFile=/etc/knot/knot.env UMask=0077 Restart=on-failure RestartSec=5 TimeoutStopSec=120 LimitNOFILE=65536 StandardOutput=journal StandardError=journal AmbientCapabilities=CAP_NET_BIND_SERVICE CapabilityBoundingSet=CAP_NET_BIND_SERVICE NoNewPrivileges=true ProtectProc=invisible ProtectSystem=strict ProtectHome=true ReadWritePaths=/var/lib/knot PrivateTmp=true PrivateDevices=true ProtectHostname=true ProtectClock=true ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectControlGroups=true RestrictAddressFamilies=AF_INET AF_INET6 AF_NETLINK AF_UNIX RestrictNamespaces=true LockPersonality=true MemoryDenyWriteExecute=true RestrictRealtime=true RestrictSUIDSGID=true RemoveIPC=true PrivateMounts=true SystemCallFilter=@system-service SystemCallFilter=~@privileged @resources SystemCallArchitectures=native [Install] WantedBy=multi-user.target