This commit adds a warning for settings that possibly provide better
sandboxing and explains their tradeoffs.
Restart=always
Type=notify
+# The following lines leverage SystemD's sandboxing options to provide
+# defense in depth protection at the expense of restricting some flexibility
+# in your setup (e.g. placement of your configuration files) or possibly
+# reduced performance. See systemd.service(5) and systemd.exec(5) for further
+# information.
+
[Install]
WantedBy=multi-user.target