[Unit] Description=tomswall firewall (apply local config at boot) Documentation=https://git.unkin.net/unkin/tomswall DefaultDependencies=no Wants=network-pre.target Before=network-pre.target shutdown.target After=local-fs.target systemd-sysctl.service Conflicts=shutdown.target tomswall-agent.service StartLimitIntervalSec=60 StartLimitBurst=5 [Service] Type=oneshot RemainAfterExit=yes Environment=TOMSWALL_CONFIG=/etc/tomswall/tomswall.yaml EnvironmentFile=-/etc/tomswall/tomswall.env ExecStart=/usr/sbin/tomswall apply -c ${TOMSWALL_CONFIG} ExecReload=/usr/sbin/tomswall apply -c ${TOMSWALL_CONFIG} # Fails open: after StartLimitBurst failures within StartLimitIntervalSec, boot continues without the ruleset. Restart=on-failure RestartSec=5 # No ExecStop: stopping the unit leaves the ruleset in place (flush would open the firewall). [Install] WantedBy=sysinit.target