Restricting the privileges of Linux services and reducing the actor vector has always been challenging. You need to adapt your software or start looking for a sandbox program or a manager that handles this for you. And at this moment you should look at systemd. systemd is a suite of basic building blocks for a Linux system. It provides a system and service manager that runs as PID 1 and starts the rest of the system.