Endpoint configuration · GraphQL type

SystemServiceLinux type

Linux-specific attributes for a System Service (systemd).

Fields

Field Name Description
systemType - SystemServiceType! The type of systemd service (simple, forking, oneshot, dbus, notify, etc.).
pidFile - String! Path to PID file of the service.
notifyAccess - NotifyAccess! Controls access to the service status notification socket.
restart - Duration! Configures the time to wait before restarting the service.
timeout - Duration! Configures the timeout for starting and stopping the service.
watchdog - Duration! Configures the watchdog timeout for the service.
watchdogTimestamp - Time Timestamp of the last watchdog notification.
startLimitInterval - Duration! Configures unit start rate limiting interval.
startLimitBurst - Uint32! Configures how many starts per interval are allowed.
startLimitAction - String! Action to take when start rate limit is hit.
slice - String! The slice unit the service belongs to.
controlGroup - String! Control group path for the service.
execStartPre - [ExecCommand!] Commands to execute before ExecStart.
execStart - [ExecCommand!] Main commands to execute when starting the service.
execStartPost - [ExecCommand!] Commands to execute after ExecStart.
execReload - [ExecCommand!] Commands to execute to reload the service configuration.
execStop - [ExecCommand!] Commands to execute to stop the service.
execStopPost - [ExecCommand!] Commands to execute after the service stops.
environment - [EnvironmentVariable!] Environment variables to set for executed processes.
environmentFiles - [EnvFile!] Files from which additional environment variables are read.
umask - Int Controls which file mode creation mask to apply.
limitCpu - Uint64! CPU time soft resource limit.
limitFsize - Uint64! Maximum file size soft resource limit.
limitData - Uint64! Maximum data segment size soft resource limit.
limitStack - Uint64! Maximum stack size soft resource limit.
limitCore - Uint64! Maximum core file size soft resource limit.
limitRss - Uint64! Maximum resident set size soft resource limit.
limitNofile - Uint64! Maximum number of open files soft resource limit.
limitAs - Uint64! Maximum address space size soft resource limit.
limitNproc - Uint64! Maximum number of processes soft resource limit.
limitMemlock - Uint64! Maximum locked memory soft resource limit.
limitLocks - Uint64! Maximum file locks soft resource limit.
limitSigpending - Uint64! Maximum number of pending signals soft resource limit.
limitMsgqueue - Uint64! Maximum bytes in POSIX message queues soft resource limit.
limitNice - Uint64! Maximum nice priority soft resource limit.
limitRtprio - Uint64! Maximum realtime priority soft resource limit.
limitRttime - Uint64! Maximum realtime timeout soft resource limit.
workingDirectory - String Working directory for executed processes.
rootDirectory - String Root directory for executed processes.
oomScoreAdjust - Int! OOM score adjustment value.
nice - Int Nice level for executed processes.
ioScheduling - Int! I/O scheduling class and priority.
cpuSchedulingPolicy - Int! CPU scheduling policy.
cpuSchedulingPriority - Int! CPU scheduling priority.
timerSlack - Duration! Timer slack value.
cpuSchedulingResetOnFork - Boolean! Whether to reset CPU scheduling on fork.
nonBlocking - Boolean! Whether to set O_NONBLOCK flag on all file descriptors.
standardInput - String! Standard input source for executed processes.
standardOutput - String! Standard output destination for executed processes.
standardError - String! Standard error destination for executed processes.
ttyPath - String! TTY path to use for standard input/output/error.
ttyReset - Boolean! Whether to reset TTY before and after execution.
ttyVHangup - Boolean! Whether to hang up TTY after execution.
ttyVtDisallocate - Boolean! Whether to deallocate TTY after execution.
syslogPriority - Int! Syslog priority for executed processes.
syslogIdentifier - String! Syslog identifier for executed processes.
syslogLevelPrefix - Boolean! Whether to prefix syslog messages with severity level.
capabilities - String! Capabilities to set for executed processes.
secureBits - Int! Secure bits to set for executed processes.
capabilityBoundingSet - Uint64! Capability bounding set for executed processes.
user - String! User to run the service as.
group - String! Group to run the service as.
supplementaryGroups - [String!] Supplementary groups for the service process.
tcpWrapName - String! TCP wrapper name for the service.
pamName - String! PAM service name for the service.
readWriteDirectories - [String!] Directories that should be made accessible read-write.
readOnlyDirectories - [String!] Directories that should be made accessible read-only.
inaccessibleDirectories - [String!] Directories that should be made inaccessible.
mountFlags - Uint64! Mount flags for the service.
privateTmp - Boolean! Whether to set up a private /tmp directory.
privateNetwork - Boolean! Whether to set up a private network namespace.
sameProcessGroup - Boolean! Whether to run all processes in the same process group.
utmpIdentifier - String! UTMP identifier for the service.
ignoreSigpipe - Boolean! Whether to ignore SIGPIPE.
noNewPrivileges - Boolean! Whether to set the no new privileges flag.
systemCallFilter - SystemCallFilter! System call filter for the service.
killMode - String! Kill mode for the service (control-group, process, mixed, none).
killSignal - Int! Signal to use to kill the service.
sendSigkill - Boolean! Whether to send SIGKILL to the service when stopping.
sendSighup - Boolean! Whether to send SIGHUP to the service when stopping.
cpuAccounting - Boolean! Whether to enable CPU accounting.
cpuShares - Uint64! CPU shares for the service.
blockIoAccounting - Boolean! Whether to enable block I/O accounting.
blockIoWeight - Uint64! Block I/O weight for the service.
blockIoDeviceWeight - [DeviceWeight!] Per-device block I/O weights.
blockIoReadBandwidth - [DeviceWeight!] Per-device block I/O read bandwidth limits.
blockIoWriteBandwidth - [DeviceWeight!] Per-device block I/O write bandwidth limits.
memoryAccounting - Boolean! Whether to enable memory accounting.
memoryLimit - Uint64! Memory limit for the service.
devicePolicy - String! Device access policy (auto, closed, strict).
deviceAllow - [DeviceAllow!] Device access control list.
permissionsStartOnly - Boolean! Whether permissions are only applied to ExecStart.
rootDirectoryStartOnly - Boolean! Whether root directory is only applied to ExecStart.
remainAfterExit - Boolean! Whether the service should be considered active after it exits.
execMainStartTimestamp - Time Timestamp when the main process started.
execMainExitTimestamp - Time Timestamp when the main process exited.
execMainPid - Uint32! PID of the main process.
execMainCode - Int! Exit code type of the main process.
execMainStatus - Int! Exit status of the main process.
mainPid - Uint32! Current main PID of the service.
controlPid - Uint32! Current control PID of the service.
busName - String! D-Bus bus name of the service.
statusText - String! Status text reported by the service.
result - ServiceResult! Result of the last run (success, failure, etc.).
unitId - String! Unique systemd unit identifier for the service.
unitNames - [String!] All systemd unit names the service is known by, including aliases.
following - String! Unit this service follows for state changes.
requires - [String!] Units this service requires to be started.
requiresOverridable - [String!] Units this service overridably requires to be started.
requisite - [String!] Units this service requisites to be started.
requisiteOverridable - [String!] Units this service overridably requisites to be started.
wants - [String!] Units this service wants to be started.
bindsTo - [String!] Units this service binds to.
partOf - [String!] Units this service is part of.
requiredBy - [String!] Units that require this service.
requiredByOverridable - [String!] Units that overridably require this service.
wantedBy - [String!] Units that want this service.
boundBy - [String!] Units bound by this service.
consistsOf - [String!] Units that consist of this service.
conflicts - [String!] Units that conflict with this service.
conflictedBy - [String!] Units conflicted by this service.
before - [String!] Units that must start before this service.
after - [String!] Units that must start after this service.
onFailure - [String!] Units to activate on failure of this service.
triggers - [String!] Units triggered by this service.
triggeredBy - [String!] Units that trigger this service.
propagatesReloadTo - [String!] Units to propagate reload to.
reloadPropagatedFrom - [String!] Units that propagate reload from.
requiresMountsFor - [String!] Mount points required for this service.
sourcePath - String! Source path of the unit file.
dropInPaths - [String!] Drop-in paths that extend this unit.
documentation - [String!] Documentation URLs for this service.
loadState - String! Load state of the unit (loaded, not-found, bad-setting, error, masked).
subState - String! Sub-state of the unit.
fragmentPath - String! Path to the unit file fragment.
inactiveExitTimestamp - Time Timestamp when the unit became inactive.
activeEnterTimestamp - Time Timestamp when the unit became active.
activeExitTimestamp - Time Timestamp when the unit stopped being active.
inactiveEnterTimestamp - Time Timestamp when the unit became inactive.
canStart - Boolean! Whether the unit can be started.
canStop - Boolean! Whether the unit can be stopped.
canReload - Boolean! Whether the unit can be reloaded.
canIsolate - Boolean! Whether the unit can be isolated.
jobId - Uint64! Current job ID for the unit.
jobPath - String! Current job path for the unit.
stopWhenUnneeded - Boolean! Whether to stop the unit when it's no longer needed.
refuseManualStart - Boolean! Whether manual start is refused.
refuseManualStop - Boolean! Whether manual stop is refused.
allowIsolate - Boolean! Whether isolation is allowed.
defaultDependencies - Boolean! Whether default dependencies are enabled.
onFailureIsolate - Boolean! Whether to isolate on failure.
ignoreOnIsolate - Boolean! Whether to ignore on isolate.
ignoreOnSnapshot - Boolean! Whether to ignore on snapshot.
needDaemonReload - Boolean! Whether daemon reload is needed.
jobTimeout - Duration! Job timeout.
conditionTimestamp - Time Timestamp when conditions were last checked.
conditionResult - Boolean! Result of the last condition check.
conditions - [Condition!] Start conditions for the unit.
loadError - LoadErrorPair! Load error information.
transient - Boolean! Whether the unit is transient.
exitType - ServiceExitType! Service exit type (main, cgroup).
restartMode - ServiceRestartMode! Service restart mode (normal, direct, debug).
restartMaxDelay - Duration! Maximum delay for restart.
restartSteps - Uint32! Number of restart steps.
restartPreventExitCode - String! Exit codes that prevent restart.
restartForceExitCode - String! Exit codes that force restart.
successExitStatus - SuccessExitStatus! Success exit status configuration.
timeoutStartFailureMode - ServiceTimeoutFailureMode! Timeout start failure mode.
timeoutStopFailureMode - ServiceTimeoutFailureMode! Timeout stop failure mode.
runtimeMax - Duration! Maximum runtime.
runtimeRandomizedExtra - Duration! Randomized extra runtime.
oomPolicy - OomPolicy! OOM policy (continue, stop, kill).
reloadResult - String! Result of the last reload operation.
cleanResult - String! Result of the last clean operation.
liveMountResult - String! Result of the last live mount operation.
statusErrno - Int! Status errno value.
statusBusError - String! Status bus error message.
statusVarlinkError - String! Status varlink error message.
fileDescriptorStoreMax - Uint32! Maximum file descriptors to store.
nFileDescriptorStore - Uint32! Number of file descriptors stored.
fileDescriptorStorePreserve - String! File descriptor store preservation mode.
passEnvironment - [String!] Environment variables to pass through.
unsetEnvironment - [String!] Environment variables to unset.
cpuAffinityFromNuma - Boolean! Whether CPU affinity is derived from NUMA.
numaPolicy - Int! NUMA memory allocation policy.
cpuWeight - Uint64! CPU weight for the service.
startupCpuWeight - Uint64! Startup CPU weight for the service.
cpuQuota - Duration! CPU quota per second.
cpuQuotaPeriod - Duration! CPU quota period.
ioAccounting - Boolean! Whether to enable I/O accounting.
ioWeight - Uint64! I/O weight for the service.
startupIoWeight - Uint64! Startup I/O weight for the service.
ioDeviceWeight - [DeviceWeight!] Per-device I/O weights.
ioReadBandwidthMax - [DeviceWeight!] Per-device I/O read bandwidth limits.
ioWriteBandwidthMax - [DeviceWeight!] Per-device I/O write bandwidth limits.
memoryCurrent - Uint64! Current memory usage.
memoryPeak - Uint64! Peak memory usage.
memoryAvailable - Uint64! Available memory.
memoryMin - Uint64! Minimum memory threshold.
memoryLow - Uint64! Low memory threshold.
memoryHigh - Uint64! High memory threshold.
memoryMax - Uint64! Maximum memory limit.
memorySwapMax - Uint64! Maximum swap memory limit.
memoryZswapMax - Uint64! Maximum zswap memory limit.
memoryDenyWriteExecute - Boolean! Whether to deny write-execute memory mappings.
memoryKsm - Boolean! Whether to enable kernel samepage merging.
managedOomKills - Uint64! Number of OOM kills managed.
managedOomSwap - String! Managed OOM swap policy.
managedOomMemoryPressure - String! Managed OOM memory pressure policy.
managedOomMemoryPressureLimit - Uint32! Managed OOM memory pressure limit percentage.
managedOomPreference - String! Managed OOM preference.
protectKernelTunables - Boolean! Whether to protect kernel tunables.
protectKernelModules - Boolean! Whether to protect kernel modules.
protectKernelLogs - Boolean! Whether to protect kernel logs.
protectClock - Boolean! Whether to protect the system clock.
protectControlGroups - Boolean! Whether to protect control groups.
protectSystem - String! System protection level (strict, full, yes, no).
protectHome - String! Home directory protection level (read-only, tmpfs, yes, no).
privateDevices - Boolean! Whether to use private /dev.
privateUsers - Boolean! Whether to use private user namespace.
privateIpc - Boolean! Whether to use private IPC namespace.
protectHostname - Boolean! Whether to protect hostname.
lockPersonality - Boolean! Whether to lock personality.
restrictRealtime - Boolean! Whether to restrict realtime scheduling.
restrictSuidSgid - Boolean! Whether to restrict SUID/SGID.
restrictNamespaces - Uint64! Restricted namespaces mask.
restrictFileSystems - RestrictList! Restricted filesystems.
restrictAddressFamilies - RestrictList! Restricted address families.
keyringMode - String! Keyring mode.
userNamespacePath - String! User namespace path.
networkNamespacePath - String! Network namespace path.
ipcNamespacePath - String! IPC namespace path.
runtimeDirectory - [String!] Runtime directories to create.
stateDirectory - [String!] State directories to create.
cacheDirectory - [String!] Cache directories to create.
logsDirectory - [String!] Log directories to create.
configurationDirectory - [String!] Configuration directories to create.
runtimeDirectoryMode - Uint32! Mode for runtime directory.
stateDirectoryMode - Uint32! Mode for state directory.
cacheDirectoryMode - Uint32! Mode for cache directory.
logsDirectoryMode - Uint32! Mode for logs directory.
configurationDirectoryMode - Uint32! Mode for configuration directory.
bindPaths - [BindPath!] Bind mount paths.
bindReadOnlyPaths - [BindPath!] Read-only bind mount paths.
temporaryFileSystem - [RestrictList!] Temporary filesystems.
mountApiVfs - Boolean! Whether to mount API VFS.
delegate - Boolean! Whether to delegate cgroup management.
delegateControllers - [String!] Delegated controllers.
delegateNamespaces - Uint64! Delegated namespaces mask.
ipAccounting - Boolean! Whether to enable IP accounting.
ipAddressAllow - [IPAddressRule!] IP addresses to allow.
ipAddressDeny - [IPAddressRule!] IP addresses to deny.
ipIngressBytes - Uint64! Total ingress bytes.
ipEgressBytes - Uint64! Total egress bytes.
restrictNetworkInterfaces - RestrictList! Restricted network interfaces.
restartKillSignal - Int! Signal to use for restart kill.
finalKillSignal - Int! Final signal to use for kill.
watchdogSignal - Int! Signal to use for watchdog.
rootImage - String! Root image path.
rootImageOptions - [KeyValuePair!] Root image options.
rootHashPath - String! Root hash path for verification.
rootVerity - String! Root verity settings.
rootEphemeral - Boolean! Whether root is ephemeral.
rootImagePolicy - String! Root image policy.
mountImagePolicy - String! Mount image policy.
extensionImagePolicy - String! Extension image policy.
protectProc - String! /proc protection mode.
procSubset - String! /proc subset to expose.
dynamicUser - Boolean! Whether to use dynamic user.
setLoginEnvironment - Boolean! Whether to set login environment.
removeIpc - Boolean! Whether to remove IPC objects on exit.
loadCredential - [KeyValuePair!] Credentials to load.
loadCredentialEncrypted - [KeyValuePair!] Encrypted credentials to load.
importCredential - [String!] Credentials to import.
bpfProgram - [BPFProgram!] BPF programs to load.
upholds - [String!] Units this service upholds.
upheldBy - [String!] Units that uphold this service.
onSuccess - [String!] Units to activate on success.
onSuccessOf - [String!] Units that activate on this service's success.
onFailureOf - [String!] Units that activate on this service's failure.
propagatesStopTo - [String!] Units to propagate stop to.
stopPropagatedFrom - [String!] Units that propagate stop from.
joinsNamespaceOf - [String!] Units whose namespace to join.
sliceOf - [String!] Units in this slice.
wantsMountsFor - [String!] Mount points wanted for this service.
accessSelinuxContext - String! SELinux context for access.
freezerState - String! Freezer state.
stateChangeTimestamp - Time Timestamp of last state change.
canClean - [String!] What can be cleaned.
canFreeze - Boolean! Whether the unit can be frozen.
canLiveMount - Boolean! Whether the unit can be live mounted.
surviveFinalKillSignal - Boolean! Whether to survive final kill signal.
onSuccessJobMode - String! On-success job mode.
failureAction - String! Action to take on failure.
failureActionExitStatus - Int! Exit status for failure action.
successAction - String! Action to take on success.
successActionExitStatus - Int! Exit status for success action.
rebootArgument - String! Reboot argument.
perpetual - Boolean! Whether the unit is perpetual.
jobRunningTimeout - Duration! Job running timeout.
jobTimeoutAction - String! Action to take on job timeout.
jobTimeoutRebootArgument - String! Reboot argument for job timeout.
collectMode - ServiceCollectMode! Service collect mode.
refs - [String!] Reference list.
markers - [String!] Marker list.
activationDetails - [KeyValuePair!] Activation details.
debugInvocation - Boolean! Whether debug invocation is enabled.
openFiles - [SystemServiceOpenFile!] Open files.

Used by

Example

Example

{
  "systemType": "SIMPLE",
  "pidFile": "abc123",
  "notifyAccess": "NONE",
  "restart": "600000000",
  "timeout": "600000000",
  "watchdog": "600000000",
  "watchdogTimestamp": "2021-10-07T18:23:25.829Z",
  "startLimitInterval": "600000000",
  "startLimitBurst": "1073741824",
  "startLimitAction": "xyz789",
  "slice": "xyz789",
  "controlGroup": "abc123",
  "execStartPre": [ExecCommand],
  "execStart": [ExecCommand],
  "execStartPost": [ExecCommand],
  "execReload": [ExecCommand],
  "execStop": [ExecCommand],
  "execStopPost": [ExecCommand],
  "environment": [EnvironmentVariable],
  "environmentFiles": [EnvFile],
  "umask": 123,
  "limitCpu": "8589934592",
  "limitFsize": "8589934592",
  "limitData": "8589934592",
  "limitStack": "8589934592",
  "limitCore": "8589934592",
  "limitRss": "8589934592",
  "limitNofile": "8589934592",
  "limitAs": "8589934592",
  "limitNproc": "8589934592",
  "limitMemlock": "8589934592",
  "limitLocks": "8589934592",
  "limitSigpending": "8589934592",
  "limitMsgqueue": "8589934592",
  "limitNice": "8589934592",
  "limitRtprio": "8589934592",
  "limitRttime": "8589934592",
  "workingDirectory": "xyz789",
  "rootDirectory": "abc123",
  "oomScoreAdjust": 987,
  "nice": 123,
  "ioScheduling": 123,
  "cpuSchedulingPolicy": 987,
  "cpuSchedulingPriority": 123,
  "timerSlack": "600000000",
  "cpuSchedulingResetOnFork": true,
  "nonBlocking": true,
  "standardInput": "xyz789",
  "standardOutput": "xyz789",
  "standardError": "abc123",
  "ttyPath": "xyz789",
  "ttyReset": true,
  "ttyVHangup": false,
  "ttyVtDisallocate": true,
  "syslogPriority": 987,
  "syslogIdentifier": "xyz789",
  "syslogLevelPrefix": false,
  "capabilities": "abc123",
  "secureBits": 123,
  "capabilityBoundingSet": "8589934592",
  "user": "abc123",
  "group": "xyz789",
  "supplementaryGroups": ["abc123"],
  "tcpWrapName": "abc123",
  "pamName": "xyz789",
  "readWriteDirectories": ["abc123"],
  "readOnlyDirectories": ["abc123"],
  "inaccessibleDirectories": ["xyz789"],
  "mountFlags": "8589934592",
  "privateTmp": false,
  "privateNetwork": true,
  "sameProcessGroup": false,
  "utmpIdentifier": "abc123",
  "ignoreSigpipe": false,
  "noNewPrivileges": false,
  "systemCallFilter": SystemCallFilter,
  "killMode": "abc123",
  "killSignal": 987,
  "sendSigkill": false,
  "sendSighup": false,
  "cpuAccounting": false,
  "cpuShares": "8589934592",
  "blockIoAccounting": true,
  "blockIoWeight": "8589934592",
  "blockIoDeviceWeight": [DeviceWeight],
  "blockIoReadBandwidth": [DeviceWeight],
  "blockIoWriteBandwidth": [DeviceWeight],
  "memoryAccounting": false,
  "memoryLimit": "8589934592",
  "devicePolicy": "xyz789",
  "deviceAllow": [DeviceAllow],
  "permissionsStartOnly": false,
  "rootDirectoryStartOnly": false,
  "remainAfterExit": true,
  "execMainStartTimestamp": "2021-10-07T18:23:25.829Z",
  "execMainExitTimestamp": "2021-10-07T18:23:25.829Z",
  "execMainPid": "1073741824",
  "execMainCode": 987,
  "execMainStatus": 987,
  "mainPid": "1073741824",
  "controlPid": "1073741824",
  "busName": "abc123",
  "statusText": "xyz789",
  "result": "SUCCESS",
  "unitId": "abc123",
  "unitNames": ["xyz789"],
  "following": "xyz789",
  "requires": ["abc123"],
  "requiresOverridable": ["xyz789"],
  "requisite": ["abc123"],
  "requisiteOverridable": ["xyz789"],
  "wants": ["xyz789"],
  "bindsTo": ["xyz789"],
  "partOf": ["xyz789"],
  "requiredBy": ["xyz789"],
  "requiredByOverridable": ["xyz789"],
  "wantedBy": ["abc123"],
  "boundBy": ["xyz789"],
  "consistsOf": ["xyz789"],
  "conflicts": ["abc123"],
  "conflictedBy": ["xyz789"],
  "before": ["abc123"],
  "after": ["xyz789"],
  "onFailure": ["xyz789"],
  "triggers": ["xyz789"],
  "triggeredBy": ["abc123"],
  "propagatesReloadTo": ["abc123"],
  "reloadPropagatedFrom": ["abc123"],
  "requiresMountsFor": ["abc123"],
  "sourcePath": "xyz789",
  "dropInPaths": ["abc123"],
  "documentation": ["abc123"],
  "loadState": "xyz789",
  "subState": "xyz789",
  "fragmentPath": "abc123",
  "inactiveExitTimestamp": "2021-10-07T18:23:25.829Z",
  "activeEnterTimestamp": "2021-10-07T18:23:25.829Z",
  "activeExitTimestamp": "2021-10-07T18:23:25.829Z",
  "inactiveEnterTimestamp": "2021-10-07T18:23:25.829Z",
  "canStart": true,
  "canStop": true,
  "canReload": true,
  "canIsolate": true,
  "jobId": "8589934592",
  "jobPath": "abc123",
  "stopWhenUnneeded": false,
  "refuseManualStart": false,
  "refuseManualStop": false,
  "allowIsolate": false,
  "defaultDependencies": false,
  "onFailureIsolate": true,
  "ignoreOnIsolate": false,
  "ignoreOnSnapshot": true,
  "needDaemonReload": true,
  "jobTimeout": "600000000",
  "conditionTimestamp": "2021-10-07T18:23:25.829Z",
  "conditionResult": true,
  "conditions": [Condition],
  "loadError": LoadErrorPair,
  "transient": true,
  "exitType": "MAIN",
  "restartMode": "NORMAL",
  "restartMaxDelay": "600000000",
  "restartSteps": "1073741824",
  "restartPreventExitCode": "xyz789",
  "restartForceExitCode": "xyz789",
  "successExitStatus": SuccessExitStatus,
  "timeoutStartFailureMode": "TERMINATE",
  "timeoutStopFailureMode": "TERMINATE",
  "runtimeMax": "600000000",
  "runtimeRandomizedExtra": "600000000",
  "oomPolicy": "CONTINUE",
  "reloadResult": "abc123",
  "cleanResult": "abc123",
  "liveMountResult": "abc123",
  "statusErrno": 987,
  "statusBusError": "abc123",
  "statusVarlinkError": "xyz789",
  "fileDescriptorStoreMax": "1073741824",
  "nFileDescriptorStore": "1073741824",
  "fileDescriptorStorePreserve": "xyz789",
  "passEnvironment": ["abc123"],
  "unsetEnvironment": ["xyz789"],
  "cpuAffinityFromNuma": false,
  "numaPolicy": 987,
  "cpuWeight": "8589934592",
  "startupCpuWeight": "8589934592",
  "cpuQuota": "600000000",
  "cpuQuotaPeriod": "600000000",
  "ioAccounting": true,
  "ioWeight": "8589934592",
  "startupIoWeight": "8589934592",
  "ioDeviceWeight": [DeviceWeight],
  "ioReadBandwidthMax": [DeviceWeight],
  "ioWriteBandwidthMax": [DeviceWeight],
  "memoryCurrent": "8589934592",
  "memoryPeak": "8589934592",
  "memoryAvailable": "8589934592",
  "memoryMin": "8589934592",
  "memoryLow": "8589934592",
  "memoryHigh": "8589934592",
  "memoryMax": "8589934592",
  "memorySwapMax": "8589934592",
  "memoryZswapMax": "8589934592",
  "memoryDenyWriteExecute": false,
  "memoryKsm": false,
  "managedOomKills": "8589934592",
  "managedOomSwap": "abc123",
  "managedOomMemoryPressure": "xyz789",
  "managedOomMemoryPressureLimit": "1073741824",
  "managedOomPreference": "abc123",
  "protectKernelTunables": false,
  "protectKernelModules": true,
  "protectKernelLogs": true,
  "protectClock": true,
  "protectControlGroups": false,
  "protectSystem": "xyz789",
  "protectHome": "xyz789",
  "privateDevices": true,
  "privateUsers": false,
  "privateIpc": false,
  "protectHostname": true,
  "lockPersonality": true,
  "restrictRealtime": false,
  "restrictSuidSgid": true,
  "restrictNamespaces": "8589934592",
  "restrictFileSystems": RestrictList,
  "restrictAddressFamilies": RestrictList,
  "keyringMode": "xyz789",
  "userNamespacePath": "xyz789",
  "networkNamespacePath": "xyz789",
  "ipcNamespacePath": "xyz789",
  "runtimeDirectory": ["abc123"],
  "stateDirectory": ["xyz789"],
  "cacheDirectory": ["xyz789"],
  "logsDirectory": ["abc123"],
  "configurationDirectory": ["abc123"],
  "runtimeDirectoryMode": "1073741824",
  "stateDirectoryMode": "1073741824",
  "cacheDirectoryMode": "1073741824",
  "logsDirectoryMode": "1073741824",
  "configurationDirectoryMode": "1073741824",
  "bindPaths": [BindPath],
  "bindReadOnlyPaths": [BindPath],
  "temporaryFileSystem": [RestrictList],
  "mountApiVfs": true,
  "delegate": true,
  "delegateControllers": ["xyz789"],
  "delegateNamespaces": "8589934592",
  "ipAccounting": true,
  "ipAddressAllow": [IPAddressRule],
  "ipAddressDeny": [IPAddressRule],
  "ipIngressBytes": "8589934592",
  "ipEgressBytes": "8589934592",
  "restrictNetworkInterfaces": RestrictList,
  "restartKillSignal": 987,
  "finalKillSignal": 123,
  "watchdogSignal": 987,
  "rootImage": "abc123",
  "rootImageOptions": [KeyValuePair],
  "rootHashPath": "abc123",
  "rootVerity": "xyz789",
  "rootEphemeral": true,
  "rootImagePolicy": "abc123",
  "mountImagePolicy": "abc123",
  "extensionImagePolicy": "abc123",
  "protectProc": "xyz789",
  "procSubset": "abc123",
  "dynamicUser": false,
  "setLoginEnvironment": true,
  "removeIpc": false,
  "loadCredential": [KeyValuePair],
  "loadCredentialEncrypted": [KeyValuePair],
  "importCredential": ["xyz789"],
  "bpfProgram": [BPFProgram],
  "upholds": ["abc123"],
  "upheldBy": ["xyz789"],
  "onSuccess": ["xyz789"],
  "onSuccessOf": ["abc123"],
  "onFailureOf": ["abc123"],
  "propagatesStopTo": ["xyz789"],
  "stopPropagatedFrom": ["xyz789"],
  "joinsNamespaceOf": ["xyz789"],
  "sliceOf": ["abc123"],
  "wantsMountsFor": ["xyz789"],
  "accessSelinuxContext": "abc123",
  "freezerState": "xyz789",
  "stateChangeTimestamp": "2021-10-07T18:23:25.829Z",
  "canClean": ["abc123"],
  "canFreeze": false,
  "canLiveMount": true,
  "surviveFinalKillSignal": true,
  "onSuccessJobMode": "abc123",
  "failureAction": "xyz789",
  "failureActionExitStatus": 123,
  "successAction": "abc123",
  "successActionExitStatus": 987,
  "rebootArgument": "xyz789",
  "perpetual": false,
  "jobRunningTimeout": "600000000",
  "jobTimeoutAction": "abc123",
  "jobTimeoutRebootArgument": "xyz789",
  "collectMode": "INACTIVE",
  "refs": ["xyz789"],
  "markers": ["abc123"],
  "activationDetails": [KeyValuePair],
  "debugInvocation": false,
  "openFiles": [SystemServiceOpenFile]
}