Apply systemd sandboxing by default to some services

2 Likes