[Unit] Description=ZyloVPN node agent Documentation=https://github.com/zylovpn/docs After=network-online.target Wants=network-online.target [Service] Type=simple ExecStart=/usr/local/bin/zylo-agent Restart=always RestartSec=10 # Root is required: the agent configures a WireGuard interface via `wg` and # `ip`, both of which need CAP_NET_ADMIN. The hardening below narrows what # that root can reach. User=root # --- Hardening ------------------------------------------------------------- # The agent's job is to run two binaries and talk HTTPS to one host. Almost # everything else a compromised agent might want is closed off here. NoNewPrivileges=yes ProtectSystem=strict ProtectHome=yes PrivateTmp=yes ProtectKernelTunables=no ProtectKernelModules=no ProtectControlGroups=yes RestrictSUIDSGID=yes RestrictRealtime=yes LockPersonality=yes MemoryDenyWriteExecute=yes # ProtectSystem=strict makes /etc read-only; the agent needs to write only the # node's own WireGuard private key on first run. ReadWritePaths=/etc/wireguard # CAP_NET_ADMIN configures the interface. CAP_NET_RAW is not needed and is # deliberately absent. CapabilityBoundingSet=CAP_NET_ADMIN CAP_NET_BIND_SERVICE AmbientCapabilities=CAP_NET_ADMIN RestrictAddressFamilies=AF_INET AF_INET6 AF_NETLINK AF_UNIX # --- Logging --------------------------------------------------------------- StandardOutput=journal StandardError=journal SyslogIdentifier=zylo-agent [Install] WantedBy=multi-user.target