# The "trusted" profile for services, i.e. no restrictions are applied [Service] MountAPIVFS=yes BindPaths=/run BindReadOnlyPaths=/etc/machine-id BindReadOnlyPaths=/etc/resolv.conf