[Unit] Description=FilyX isolated TikTok LIVE MultiChat relay After=network-online.target Wants=network-online.target [Service] Type=simple User=www-data WorkingDirectory=/srv/filyx/apps/tiktok-live-relay Environment=NODE_ENV=production Environment=FILYX_PROJECT_ROOT=/srv/filyx # Loaded by systemd before privileges are dropped; no credential is written to # this unit or to the relay logs. EnvironmentFile=/srv/filyx/.env # The public domain can change; this local-only FPM endpoint is the same # application and keeps the relay off Cloudflare and the public network. Environment=FILYX_PANEL_URL=http://127.0.0.1:8181 ExecStart=/usr/local/bin/node /srv/filyx/apps/tiktok-live-relay/src/index.mjs Restart=always RestartSec=15 NoNewPrivileges=true PrivateTmp=true ProtectSystem=full ReadWritePaths=/srv/filyx [Install] WantedBy=multi-user.target