[Unit] Description=Web-based chat platform After=network.target Wants=network-online.target Wants=systemd-networkd-wait-online.service [Service] ExecStart=/usr/bin/node /usr/share/rocketchat/bundle/main.js Restart=on-failure RestartSec=10 ExecReload=/bin/kill -USR1 $MAINPID SyslogIdentifier=rocketchat Environment=NODE_ENV=production EnvironmentFile=/etc/rocketchat.conf DynamicUser=true PrivateUsers=true CapabilityBoundingSet= NoNewPrivileges=true RemoveIPC=true LockPersonality=true ProtectControlGroups=true ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectClock=true ProtectHostname=true ProtectProc=noaccess RestrictRealtime=true RestrictSUIDSGID=true RestrictNamespaces=true ProtectSystem=strict ProtectHome=true PrivateTmp=true PrivateDevices=true SystemCallArchitectures=native SystemCallFilter=@system-service [Install] WantedBy=multi-user.target