[Unit] Description=penpot backend After=penpot.service After=redis.service [Service] Type=exec User=penpot WorkingDirectory=/var/lib/penpot EnvironmentFile=-/etc/conf.d/penpot-exporter ExecStart=/usr/bin/penpot-exporter Restart=on-failure RestartSec=30s # Optional hardening to improve security ReadWritePaths=/var/lib/penpot NoNewPrivileges=yes MemoryDenyWriteExecute=false PrivateDevices=yes PrivateTmp=yes ProtectHome=yes ProtectSystem=strict ProtectControlGroups=true RestrictSUIDSGID=true RestrictRealtime=true LockPersonality=true ProtectKernelLogs=true ProtectKernelTunables=true ProtectHostname=true ProtectKernelModules=true PrivateUsers=true ProtectClock=true SystemCallArchitectures=native SystemCallErrorNumber=EPERM SystemCallFilter=@system-service [Install] WantedBy=multi-user.target