[Unit] Description=Torwarden Monitoring Server After=network-online.target Wants=network-online.target [Service] Type=simple ExecStart=/usr/local/bin/torwarden-server --config /etc/torwarden/server.conf Restart=on-failure RestartSec=10s StandardOutput=journal StandardError=journal SyslogIdentifier=torwarden-server # The server writes to its data directory and reads its config — nothing else. # Adjust ReadWritePaths if you change DataDir in server.conf. ProtectSystem=strict ProtectHome=true PrivateTmp=true NoNewPrivileges=true ReadWritePaths=/var/lib/torwarden # :443 is a privileged port. Ambient capabilities are how a service that runs as # an unprivileged user binds one, and they work alongside NoNewPrivileges # because systemd sets the ambient set itself before exec. Without these two # lines the HTTPS listener fails with "permission denied" while plain HTTP keeps # working, which is confusing in exactly the wrong way. AmbientCapabilities=CAP_NET_BIND_SERVICE CapabilityBoundingSet=CAP_NET_BIND_SERVICE [Install] WantedBy=multi-user.target