[Unit] Description=Torwarden Monitoring Agent After=network-online.target Wants=network-online.target [Service] Type=simple ExecStart=/usr/local/bin/torwarden-agent --config /etc/torwarden/agent.conf Restart=on-failure RestartSec=10s StandardOutput=journal StandardError=journal SyslogIdentifier=torwarden-agent # Minimal privileges — read /proc, and write nothing outside the spool. # # StateDirectory is what makes /var/lib/torwarden-agent writable while the rest # of the filesystem stays read-only. It holds snapshots the collector would not # take, so a server that is restarting does not become a gap in the history the # availability report is built from. Remove it and the agent still runs; it # just loses whatever it could not deliver, which is how it behaved before 0.4.14. StateDirectory=torwarden-agent StateDirectoryMode=0700 ProtectSystem=strict ProtectHome=true PrivateTmp=true NoNewPrivileges=true [Install] WantedBy=multi-user.target