[Unit] Description=NX9 WireGuard Appliance Management Engine Documentation=https://github.com/nx9/nx9-wg After=network.target network-online.target Wants=network-online.target [Service] Type=simple User=root Group=root # Environment configuration file EnvironmentFile=-/etc/nx9-wg/nx9-wg.env # Executable location and invocation ExecStart=/usr/local/bin/nx9-wg --config /etc/nx9-wg/config.toml --data-dir /var/lib/nx9-wg serve # Process management and restart policy Restart=always RestartSec=5s KillMode=process TimeoutStopSec=15s # Security Hardening & Linux Capability Bounds CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE NoNewPrivileges=true # Filesystem Isolation ProtectSystem=strict ProtectHome=true PrivateTmp=true ProtectKernelTunables=false ProtectControlGroups=true ReadWritePaths=/var/lib/nx9-wg /etc/nx9-wg /var/log # Resource Limits LimitNOFILE=65536 LimitNPROC=4096 [Install] WantedBy=multi-user.target