[Unit] Description=Gitea (Git with a cup of tea) After=syslog.target After=network.target After=mysqld.service After=postgresql.service After=memcached.service After=redis.service [Service] User=gitea Group=gitea Type=simple WorkingDirectory=~ RuntimeDirectory=gitea LogsDirectory=gitea Environment=USER=gitea HOME=/var/lib/gitea GITEA_WORK_DIR=/var/lib/gitea ExecStart=/usr/bin/gitea web -c /etc/gitea/app.ini Restart=always RestartSec=2s CapabilityBoundingSet= NoNewPrivileges=True PrivateUsers=true PrivateDevices=true PrivateTmp=true ProtectHome=true ProtectSystem=strict ProtectControlGroups=yes ProtectKernelTunables=true ProtectKernelModules=yes ReadWritePaths=/etc/gitea/app.ini /var/lib/gitea LockPersonality=true MemoryDenyWriteExecute=true RestrictRealtime=true SystemCallArchitectures=native SystemCallFilter=@system-service [Install] WantedBy=multi-user.target