[Unit] Description=HTTP Process Prober Daemon After=network.target [Service] Type=simple DynamicUser=yes Restart=on-failure ExecStart=/usr/bin/httpprocprobed -c /etc/httpprocprobed.json ExecReload=kill -HUP $MAINPID ReadOnlyPaths=/ AmbientCapabilities= CapabilityBoundingSet= LockPersonality=true MemoryDenyWriteExecute=true NoNewPrivileges=true PrivateDevices=true ProtectClock=true ProtectControlGroups=true ProtectHome=true ProtectKernelLogs=true ProtectKernelModules=true ProtectKernelTunables=true ProtectSystem=strict RestrictAddressFamilies=AF_INET AF_INET6 AF_UNIX RestrictNamespaces=true RestrictRealtime=true RestrictSUIDSGID=true SystemCallArchitectures=native [Install] WantedBy=multi-user.target