Include some trivial sandboxing options in the provided service files
as an example and lead users to `systemd-analyze security`.
While being a trivial change and far from a secure service it is an
improvement and may push downstream packagers and/or users to add even
a bit of sandboxing.
Signed-off-by: srestegosaurio <lcdt@disroot.org>