1 2 3 4 5
[Service] ProtectHome=true ReadOnlyPaths=/ ReadWritePaths=/var/lib/alloy NoNewPrivileges=true