[Service] ExecStart= ExecStart=/usr/sbin/grafana-server --config=/etc/grafana/grafana.ini --pidfile=/run/grafana-server.pid --packaging=deb cfg:default.paths.logs=/var/log/grafana # TODO: Store or provision a set of plugins, prefferably the latter ProtectSystem=strict PrivateUsers=true NoNewPrivileges=yes TemporaryFileSystem=/:ro BindReadOnlyPaths=/etc/grafana /usr /lib /lib64 ProtectControlGroups=yes ProtectKernelModules=yes ProtectKernelTunables=yes RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK RestrictNamespaces=yes RestrictRealtime=yes RestrictSUIDSGID=yes MemoryDenyWriteExecute=yes LockPersonality=yes PrivateTmp=yes PrivateDevices=yes