systemd-analyze verify warns "Special user nobody configured, this is not
safe!": nobody is a shared account, so any other service running as it can
read and write /run/gost. DynamicUser= gives the unit its own transient
identity, named gost, without adding a static user to the package.
Verified under a real systemd: the unit starts, binds :80 through the
ambient capabilities, runs as the dynamic user, and is skipped rather than
failed when /etc/gost/gost.yml is absent.
CapabilityBoundingSet= was dropped when CAP_NET_ADMIN was added for TUN,
which leaves the bounding set unrestricted. Pin it to the capabilities the
unit actually needs. Restore ~@privileged as well: TUN uses ioctl(TUNSETIFF)
and netlink, neither of which is in that group.
* Add systemd service file
* Add DEB and RPM packages for amd64, amd64v3 and arm64 architectures
* Remove GOMEMLIMIT from systemd service
* Fix packaged systemd service defaults