[Unit] Description=MCP Agent database backup After=mcp-agent.service [Service] Type=oneshot ExecStart=/usr/local/bin/mcp-agent snapshot --config /srv/mcp/mcp-agent.toml User=mcp Group=mcp NoNewPrivileges=true ProtectSystem=strict ProtectHome=true PrivateTmp=true PrivateDevices=true ProtectKernelTunables=true ProtectKernelModules=true ProtectControlGroups=true RestrictSUIDSGID=true RestrictNamespaces=true LockPersonality=true MemoryDenyWriteExecute=true RestrictRealtime=true ReadWritePaths=/srv