security and hardening options for systemd service units A common and reliable pattern in service unit files is thus: NoNewPrivileges=yes PrivateTmp=yes PrivateDevices=yes DevicePolicy=closed ProtectSystem=strict