what do you think about the approach described in the last paragraph of this? https://madaidans-insecurities.github.io/guides/linux-hardening.html#systemd-service-sandboxing
i don't necessarily think it's needed to reimplement that on your own but that's how i see things on my own so i dunno tbh
