Use when hardening Linux services with systemd unit directives — sandboxing a daemon so a compromise of it can't reach the rest of the system.