Apply systemd sandboxing by default to some services