[Unit] Description=Daemon to start Shadowsocks-libev-client Wants=network-online.target After=network.target [Service] # added automatically, for details please see # https://en.opensuse.org/openSUSE:Security_Features#Systemd_hardening_effort ProtectSystem=full ProtectHome=true PrivateDevices=true ProtectHostname=true ProtectClock=true ProtectKernelTunables=true ProtectKernelModules=true ProtectKernelLogs=true ProtectControlGroups=true RestrictRealtime=true # end of automatic additions Type=forking PIDFile=/var/run/shadowsocks-libev-client.pid ExecStart=/usr/bin/ss-local -c /etc/shadowsocks/shadowsocks-libev-config.json -f /var/run/shadowsocks-libev-client.pid -u --fast-open Restart=on-failure User=shadowsocks Group=shadowsocks [Install] WantedBy=multi-user.target