systemd Unit Builder

Generate a production-ready systemd service unit with sane restart, ordering, and security hardening.

Related tools

What it does

Builds a complete systemd .service unit file from a form: description, ExecStart/ExecStop, working directory, user and group, restart policy with a configurable RestartSec, ordering against the network target, environment variables, and a security hardening block (NoNewPrivileges, ProtectSystem=strict, ProtectHome, PrivateTmp, and more) turned on by default. It can also generate a matching .timer unit as a systemd-native alternative to cron.

How to use it

Enter the command to run and adjust the restart, ordering, and hardening options to match your service. Copy the rendered unit into /etc/systemd/system/yourservice.service, then run systemctl daemon-reload, systemctl enable --now yourservice. Turn on the timer option to also get a .timer skeleton for scheduled jobs instead of a long-running daemon.

Why this one

Most systemd unit examples online are stale gists copy-pasted from a decade-old blog post, with no hardening and no thought given to the restart policy. This generator produces a current, opinionated unit with security hardening on by default, built entirely in your browser: your files and inputs never leave your device.

FAQ
What does Restart=on-failure do?
It restarts the service automatically when it exits with a nonzero code, is killed by a signal, or times out, but not when it exits cleanly (code 0) or is stopped intentionally with systemctl stop. That makes it the safest default for long-running daemons: crashes recover on their own, deliberate stops stay stopped.
Is the hardening safe to leave on?
The defaults here are a sane, conservative baseline that works for most services out of the box. The one directive to watch is ProtectSystem=strict, which makes almost the entire filesystem read-only to the service: if your app writes files outside /var, you will need to add ReadWritePaths=/your/path to the unit.
Can it make a timer instead of a long-running service?
Yes. Turn on "Also generate a .timer" and pick a schedule (daily, hourly, weekly, or a fixed time). The output appends a matching .timer unit with Persistent=true, so a missed run fires as soon as the system is back up, similar to anacron.

Keyboard shortcuts: press ? anywhere on this page to see them.