[Unit] Description=ntfy server After=network.target [Service] User=ntfy Group=ntfy ExecStart=/usr/bin/ntfy serve --no-log-dates ExecReload=/bin/kill --signal HUP $MAINPID Restart=on-failure AmbientCapabilities=CAP_NET_BIND_SERVICE LimitNOFILE=10000 PrivateDevices=true ProtectClock=true ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true RestrictRealtime=true ProtectHostname=true # These will be added in a future update. # ProtectSystem=full # PrivateTmp=true [Install] WantedBy=multi-user.target