systemd Service Generator
Generate a systemd unit file with the right service type, restart policy, dependency ordering, resource limits and sandboxing directives, with each choice explained.
Last reviewed by the Radiatus Cloud team
Want this automated for your stack?
We build CI/CD, Kubernetes & IaC pipelines that scale.
Two directives decide whether the service works
Type and Restart account for most systemd unit problems. Type=simple tells systemd the process is ready the moment it forks, which is wrong for anything that daemonises and wrong for anything with a slow start that other units depend on. Type=notify is correct when the program calls sd_notify, Type=forking when it double forks and writes a PID file, and Type=exec is a stricter simple that at least waits for the binary to be executed successfully.
Restart policies interact with the start limit
Restart=always sounds like what you want and produces a unit that gives up permanently after five failures in ten seconds, because StartLimitBurst defaults to five. A service crashing on a configuration error hits that within a second and then sits in a failed state that no amount of restarting fixes. Setting RestartSec to a few seconds, and raising the start limit interval, turns a crash loop into a service that keeps trying while you fix the cause.
Sandboxing is nearly free
systemd can confine a service without any change to the program: a private /tmp, a read only filesystem, no new privileges, no access to the kernel tunables or to devices, and a restricted set of system calls. Each directive is one line and most services need none of what they block. Applying them turns a compromised service from a foothold on the host into a process that cannot write outside its own directory, and the failure mode when you over restrict is loud and immediate rather than subtle.
Related tools
- CI/CD Security Gap Analyzer — Checklist based analyzer for CI/CD pipeline security gaps.
- Docker Security Scanner — A new tool extracted from the codebase.
- Terraform Scanner — A new tool extracted from the codebase.
- SQL Formatter — Format and indent SQL queries for readability. Handles joins, subqueries and CTEs, supports common dialects, and runs entirely in your browser.
Frequently Asked Questions
Which service Type should I use?
simple for a program that stays in the foreground, exec for the same with stricter start semantics, notify when the program calls sd_notify, forking when it daemonises and writes a PID file, and oneshot for a task that runs and exits. Choosing simple for a forking daemon makes systemd think it failed.
Why does my service stop restarting?
StartLimitBurst defaults to five failures in ten seconds, after which systemd stops trying and marks the unit failed. A service crashing immediately hits that within a second. Raise RestartSec so failures are spaced out, or widen StartLimitIntervalSec.
What is the difference between After and Requires?
After controls ordering only; Requires controls dependency. A unit with After=network.target but no Requires starts after the network is up if it is being started, and starts anyway if it is not. Ordering without a dependency is usually what you want.
Are the hardening directives safe to apply?
Mostly, and they fail loudly rather than subtly when too strict. Start with NoNewPrivileges, PrivateTmp, ProtectSystem=strict and ProtectHome, then test. systemd-analyze security gives the unit a score and lists what else could be applied.
Should I use a systemd timer instead of cron?
For anything on a systemd host, generally yes: timers give you logging in the journal, dependency ordering, resource control and the ability to run a missed job after a reboot, none of which cron provides.
Privacy & Security
Everything runs in your browser; nothing is uploaded.
How to Use
Fill in the command and user, choose a service type and restart policy, and copy the unit file.
Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.