Code should be owned by root, so an attacker cannot modify it. The same should apply to systemd unit files. closes #11752 closes #10831
To ease setup some changes required in the nginx config for load balancer setup are prepared here. They do not harm non-loadbalancer setups. The changes in the system startup scripts are mandatory