ProtectHostname=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
+ProtectKernelLogs=yes
ProtectSystem=strict
RestrictAddressFamilies=AF_UNIX
RestrictNamespaces=yes
ProtectHome=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
+ProtectKernelLogs=yes
ProtectSystem=strict
ReadWritePaths=/etc
RestrictAddressFamilies=AF_UNIX
ProtectHostname=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
+ProtectKernelLogs=yes
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
RestrictNamespaces=yes
RestrictRealtime=yes
ProtectHostname=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
+ProtectKernelLogs=yes
ProtectSystem=strict
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
RestrictNamespaces=yes
ProtectHostname=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
+ProtectKernelLogs=yes
RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6
RestrictNamespaces=yes
RestrictRealtime=yes
ProtectHostname=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
+ProtectKernelLogs=yes
ProtectSystem=strict
ReadWritePaths=/etc
RestrictAddressFamilies=AF_UNIX
ProtectHome=yes
ProtectHostname=yes
ProtectKernelModules=yes
+ProtectKernelLogs=yes
ProtectSystem=strict
ReadWritePaths=/etc /run
Restart=always
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
ProtectHostname=yes
+ProtectKernelLogs=yes
RestrictAddressFamilies=AF_UNIX AF_NETLINK AF_INET AF_INET6
RestrictRealtime=yes
SystemCallArchitectures=native
ProtectControlGroups=yes
ProtectHome=yes
ProtectKernelModules=yes
+ProtectKernelLogs=yes
ProtectSystem=strict
Restart=on-failure
RestartSec=0
CapabilityBoundingSet=CAP_KILL CAP_SYS_PTRACE CAP_SYS_ADMIN CAP_SETGID CAP_SYS_CHROOT CAP_DAC_READ_SEARCH CAP_DAC_OVERRIDE CAP_CHOWN CAP_FOWNER CAP_FSETID CAP_MKNOD
MemoryDenyWriteExecute=yes
ProtectHostname=yes
+ProtectKernelLogs=yes
RestrictRealtime=yes
RestrictAddressFamilies=AF_UNIX AF_NETLINK AF_INET AF_INET6
SystemCallFilter=@system-service @mount
ProtectHome=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
+ProtectKernelLogs=yes
ProtectSystem=strict
Restart=always
RestartSec=0
ProtectHostname=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
+ProtectKernelLogs=yes
ProtectSystem=strict
ReadWritePaths=/etc
RestrictAddressFamilies=AF_UNIX
ProtectHostname=yes
ProtectKernelModules=yes
ProtectKernelTunables=yes
+ProtectKernelLogs=yes
ProtectSystem=strict
Restart=always
RestartSec=0