systemd Unit Hardening: Security Directives for Production Lockdown (2026)
Most Linux services ship with the same trust level as root. systemd has had per-unit security directives for years; almost nobody uses them. Here is the unit-file pattern that survives a security review....