[Unit] Description=Filebrowser Service After=network.target Wants=network.target [Service] User=filebrowser Group=filebrowser Type=simple WorkingDirectory=/var/lib/filebrowser ConfigurationDirectory=filebrowser RuntimeDirectory=filebrowser LogsDirectory=filebrowser StateDirectory=filebrowser Environment=USER=filebrowser HOME=/var/lib/filebrowser ExecStart=/usr/bin/filebrowser --config /etc/filebrowser/filebrowser.json Restart=on-failure RestartSec=2s ReadWritePaths=/var/lib/filebrowser LockPersonality=true NoNewPrivileges=true PrivateDevices=true PrivateTmp=true PrivateUsers=true ProtectClock=true ProtectControlGroups=true ProtectHome=true ProtectKernelModules=true ProtectKernelTunables=true ProtectProc=invisible ProtectSystem=strict RestrictAddressFamilies=AF_INET AF_INET6 AF_NETLINK AF_UNIX RestrictNamespaces=true RestrictRealtime=true RestrictSUIDSGID=true SystemCallArchitectures=native SystemCallFilter=@system-service SystemCallErrorNumber=EPERM [Install] WantedBy=multi-user.target