useful for docker/systemd stuff also makes logfiles flush to disk per line by default; can be disabled for a small performance gain with --no-logflush
suggest letting copyparty bind 80/443 itself because nft hard