[Unit] Description=SearXNG-only SOCKS5 egress via ESH After=network-online.target tailscaled.service Wants=network-online.target [Service] Type=simple User=nobody Group=nogroup # -w bypasses authentication ONLY for nh3-docker. Everyone else must provide # an unknown, freshly randomized password (never stored or distributed). ExecStart=/bin/sh -ec 'exec /usr/bin/microsocks -i 10.0.50.65 -p 1080 -b 10.0.50.65 -w 10.100.50.40 -u denied -P "$$(cat /proc/sys/kernel/random/uuid)"' Restart=on-failure RestartSec=5 NoNewPrivileges=true ProtectSystem=strict ProtectHome=true PrivateTmp=true RestrictAddressFamilies=AF_INET AF_UNIX [Install] WantedBy=multi-user.target