Without a keepalive the kernel watchdog timer expires and reboots the host mid-audit. Configuring RuntimeWatchdogSec lets systemd PID 1 reset /dev/watchdog every 30 s — well within the typical 60 s timeout. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>