[Unit] Description=Standalone DWH API-key verifier After=local-fs.target Wants=local-fs.target [Service] Type=simple User=dwh-auth Group=www-data SupplementaryGroups=dwh-auth ExecStart=/usr/local/sbin/dwh-auth serve --registry-root /var/lib/dwh-auth --socket /run/dwh-auth/verify.sock Restart=on-failure RestartSec=2s RuntimeDirectory=dwh-auth RuntimeDirectoryMode=0750 UMask=0007 NoNewPrivileges=true PrivateTmp=true PrivateDevices=true ProtectSystem=strict ProtectHome=true ProtectClock=true ProtectControlGroups=true ProtectHostname=true ProtectKernelLogs=true ProtectKernelModules=true ProtectKernelTunables=true ProtectProc=invisible ReadOnlyPaths=/var/lib/dwh-auth ReadWritePaths=/run/dwh-auth RestrictAddressFamilies=AF_UNIX RestrictNamespaces=true RestrictRealtime=true RestrictSUIDSGID=true LockPersonality=true MemoryDenyWriteExecute=true SystemCallArchitectures=native CapabilityBoundingSet= AmbientCapabilities= [Install] WantedBy=multi-user.target