#  SPDX-License-Identifier: LGPL-2.1-or-later
#
#  This file is part of systemd.
#
#  systemd is free software; you can redistribute it and/or modify it
#  under the terms of the GNU Lesser General Public License as published by
#  the Free Software Foundation; either version 2.1 of the License, or
#  (at your option) any later version.

[Unit]
Description=Cloud Instance Metadata Access (IMDS)
Documentation=man:systemd-imdsd@.service(8)
DefaultDependencies=no
Conflicts=shutdown.target initrd-switch-root.target
Before=shutdown.target initrd-switch-root.target
After=sys-devices-virtual-dmi-id.device

[Service]
ExecStart=-/usr/lib/systemd/systemd-imdsd
User=systemd-imds
RuntimeDirectory=systemd/imds
RuntimeDirectoryPreserve=yes
# CAP_NET_ADMIN is required to set SO_FWMARK and bypass the routing restrictions, and CAP_NET_BIND_SERVICE to bind to a low port
AmbientCapabilities=CAP_NET_ADMIN CAP_NET_BIND_SERVICE
LockPersonality=yes
MemoryDenyWriteExecute=yes
NoNewPrivileges=yes
ImportCredential=imds.*
