[Unit] Description=Bacula Storage Daemon service After=network.target [Service] Type=simple StandardOutput=syslog User=bacula Group=tape ExecStart=/usr/sbin/bacula-sd -f -c /etc/bacula/bacula-sd.conf # Hardening NoNewPrivileges=yes PrivateDevices=yes ProtectHome=yes ProtectSystem=strict ReadWriteDirectories=-/var/lib/bacula ReadWriteDirectories=/mnt/backup/bacula RuntimeDirectory=bacula PrivateDevices=yes ProtectControlGroups=yes ProtectKernelModules=yes ProtectKernelTunables=yes RestrictAddressFamilies=AF_INET AF_INET6 [Install] WantedBy=multi-user.target