[Unit] Description=Authelia authentication and authorization server Documentation=https://www.authelia.com After=network.target [Service] User=authelia Group=authelia UMask=027 Environment=AUTHELIA_SERVER_ADDRESS=tcp://127.0.0.1:9091/ Environment=AUTHELIA_SERVER_DISABLE_HEALTHCHECK=true ExecStart=/usr/libexec/authelia --config /etc/authelia/configuration.yml Restart=always RestartSec=3 SyslogIdentifier=authelia CapabilityBoundingSet= NoNewPrivileges=yes RestrictNamespaces=yes ProtectHome=true ProtectSystem=strict ReadWritePaths=/var/lib/authelia PrivateDevices=yes ProtectControlGroups=yes ProtectKernelModules=yes ProtectKernelTunables=yes SystemCallArchitectures=native SystemCallFilter=@system-service SystemCallErrorNumber=EPERM [Install] WantedBy=multi-user.target