[Unit] Description=Telegraf - 节点监控服务 Documentation=https://github.com/influxdata/telegraf After=network.target [Service] Type=notify User=telegraf Group=telegraf ExecStart=/usr/bin/telegraf --config {{ telegraf_config_url }} ExecReload=/bin/kill -HUP $MAINPID KillMode=control-group Restart=on-failure RestartSec=5 TimeoutStopSec=20 EnvironmentFile=/etc/default/telegraf # 安全配置 NoNewPrivileges=true PrivateTmp=true ProtectSystem=strict ProtectHome=true ReadWritePaths=/var/lib/telegraf ProtectKernelTunables=true ProtectKernelModules=true ProtectControlGroups=true [Install] WantedBy=multi-user.target