https://github.com/desbma/shh
# ProtectSystem=
TemporaryFileSystem=/:ro BindReadOnly=/usr/bin/binary /lib /lib64 /usr/lib usr/lib64 <paths you want to read>
EDIT: More info here: https://github.com/systemd/systemd/issues/33688
https://github.com/desbma/shh