Good advice, to be sure. Especially anything getting network input[1].
In a reddit thread once, I pointed out that there is no need for any server/service program to have any access to the file holding the startup configuration. There really isn't.
If the user needs to write that configuration, use a different program with elevated privileges that do nothing but write that file.
When the server starts up and needs to read config, it should start up as a user with elevated privileges, read the entire file in the first 3 lines of `main()`, then drop privileges and continue execution as normal. It will never be able to access that file during the rest of its execution.
I don't think I've ever had a comment downvoted on reddit so hard!
[1] No need to say "untrusted network input" - all input is untrusted unless you are literally in control of both parties.