systemctl status/restart/enable --now <svc>
journalctl -u <svc> -n 50 -f
Drop-in 覆盖(不改主 unit):
mkdir -p /etc/systemd/system/<svc>.service.d
# override.conf 里 ExecStart= 清空再重设
systemctl daemon-reload && systemctl restart <svc>
非 root 绑 <1024 端口需
AmbientCapabilities=CAP_NET_BIND_SERVICE。