This might help what you want is the core app running as a service under its own account. That’s possible, it’s basically a *nix box, but you’d need to do a little tweaking to persuade the headless core to run as something more secure than root.
3 Likes