[Unit] Description=keks-meet Server Daemon After=network.target Wants=network-online.target [Service] AmbientCapabilities=CAP_NET_BIND_SERVICE CapabilityBoundingSet=CAP_NET_BIND_SERVICE ExecStart=/usr/bin/keks-meet-server /etc/keks-meet-server.toml User=keks-meet-server LockPersonality=yes MemoryDenyWriteExecute=yes NoNewPrivileges=yes PrivateDevices=true PrivateTmp=true ProtectClock=yes ProtectControlGroups=yes ProtectHome=true ProtectHostname=yes ProtectKernelLogs=yes ProtectKernelModules=yes ProtectKernelTunables=yes ProtectSystem=full RestrictAddressFamilies=~AF_PACKET AF_NETLINK RestrictNamespaces=yes RestrictSUIDSGID=yes RestrictRealtime=yes Restart=always SystemCallArchitectures=native SystemCallFilter=@system-service Type=simple [Install] WantedBy=multi-user.target