[Service] # ## extra permissions # # allow adding tun device and IP routes and iptables rules; required when ZROK_BACKEND_MODE=vpn # AmbientCapabilities=CAP_NET_ADMIN # you must run 'systemctl daemon-reload' after modifying this file