Remix.run Logo
storystarling an hour ago

I solved the port 80 issue by adding AmbientCapabilities=CAP_NET_BIND_SERVICE to the Service section of the unit file. That lets you bind privileged ports while still defining a User= line to run non-root. The lifecycle management seems solid in my experience, no force kills required.

plagiarist an hour ago | parent [-]

Well, thank you, I will give it a try