pub fn render_unit(
exe: &Path,
env_path: &Path,
credential: Option<&str>,
) -> StringExpand description
The unit file. No sandboxing directives: the service drives incusd and
reads the user’s projects, and most of them need a system manager anyway.
credential (from credential_path) loads the encrypted secrets key.