# Copyright 2021 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); you may not # use this file except in compliance with the License. You may obtain a copy of # the License at # # https://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, WITHOUT # WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the # License for the specific language governing permissions and limitations under # the License. [Unit] Description=local subnet set maintenance daemon Requires=nftables.service After=nftables.service [Service] ExecStart=localsubnetsetd Restart=always NoNewPrivileges=true ProtectSystem=strict ProtectHome=true PrivateDevices=true ProtectKernelTunables=true ProtectKernelModules=true ProtectControlGroups=true RestrictAddressFamilies=AF_NETLINK RestrictNamespaces=true LockPersonality=true MemoryDenyWriteExecute=true RestrictRealtime=true SystemCallFilter=@system-service SystemCallArchitectures=native [Install] WantedBy=sysinit.target