Unfortunately, with OJF requiring all kinds of network address families1, systemd-analyze security onlyjunk-fans.service is no longer SAFE, only OK. But at a rating of 1.6, it's still good, only Postgres tops it with 1.3.
Mostly pointless metric, but it was fun to restrict it as much as possible.
AF_UNIXto notify systemd,AF_NETLINKto talk to the kernel about WireGuard, andAF_INET+AF_INET6to perform its reverse proxy duties. ↩︎