[Unit] Description=mc-proxy TLS proxy and router After=network-online.target Wants=network-online.target [Service] Type=simple User=mc-proxy Group=mc-proxy ExecStart=/usr/local/bin/mc-proxy server --config /srv/mc-proxy/mc-proxy.toml Restart=on-failure RestartSec=5 AmbientCapabilities=CAP_NET_BIND_SERVICE NoNewPrivileges=true ProtectSystem=strict ProtectHome=true PrivateTmp=true PrivateDevices=true ProtectKernelTunables=true ProtectKernelModules=true ProtectControlGroups=true RestrictSUIDSGID=true RestrictNamespaces=true LockPersonality=true MemoryDenyWriteExecute=true RestrictRealtime=true ReadWritePaths=/srv/mc-proxy [Install] WantedBy=multi-user.target