d687423c22
- cloudflared: create dedicated service account, run as non-root with ProtectSystem=strict and full hardening directives - cloudflared: skip credentials overwrite when existing tunnel has valid credentials on disk; delete and recreate if credentials are missing - wireguard: add systemd drop-in with ProtectHome, ProtectClock, ProtectHostname, ProtectKernelLogs, PrivateTmp Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>