[Unit] Description=Voice Limit Guard (hard per-room voice channel participant limits, fronts lk-jwt-service) After=network.target livekit-server.service lk-jwt-service.service Wants=lk-jwt-service.service [Service] Type=simple ExecStart=/usr/bin/env python3 /opt/voice-limit-guard/voice-limit-guard.py Restart=on-failure RestartSec=5 # Secrets come from the deploy env file, never from this unit — it is in git. # Provides MATRIX_TOKEN (server-admin), LIVEKIT_KEY and LIVEKIT_SECRET. # NOTE: LIVEKIT_KEY/SECRET must match /etc/livekit/config.yaml and # lk-jwt-service (which reads the same env file). Rotating means changing # all three together, or every call fails to get a token. EnvironmentFile=/etc/matrix-deploy.env Environment=GUARD_BIND_HOST=0.0.0.0 Environment=GUARD_BIND_PORT=8070 Environment=GUARD_UPSTREAM=http://127.0.0.1:8071 Environment=LIVEKIT_API=http://127.0.0.1:7880 Environment=SYNAPSE_API=http://127.0.0.1:8008 [Install] WantedBy=multi-user.target