[Unit] Description=Derper service Requires=network-online.target After=network-online.target [Service] Restart=on-failure EnvironmentFile=-/etc/default/derper ExecStart=/usr/bin/derper $DERPER_ARGS ExecReload=/bin/kill -HUP $MAINPID LimitNOFILE=65535 NoNewPrivileges=true ProtectHome=true ProtectSystem=full ProtectHostname=true ProtectControlGroups=true ProtectKernelModules=true ProtectKernelTunables=true LockPersonality=true RestrictRealtime=yes RestrictNamespaces=yes MemoryDenyWriteExecute=yes PrivateDevices=yes CapabilityBoundingSet= [Install] WantedBy=multi-user.target