> In order to provide isolation, I run each service as its own unix user account.
systemd's DynamicUser feature could save some time here. It can allocate a uid, then create directories for logs/state with the correct permissions.
systemd's DynamicUser feature could save some time here. It can allocate a uid, then create directories for logs/state with the correct permissions.
You just drop a small text file (often a single line) into /etc/sysusers.d/ with the information about the user, like username, home directory and whatever, and then invoke the sysusers command or service!
Kerberos much? =)