[Unit] StartLimitIntervalSec=0 [Service] Restart=on-failure RestartSec=10 # TODO: Add mounts TemporaryFileSystem=/:ro BindReadOnlyPaths=/etc/influxdb /usr /lib /lib64 BindPaths={{ influxdb.data.path }} ProtectSystem=strict PrivateUsers=true NoNewPrivileges=yes ProtectControlGroups=yes ProtectKernelModules=yes ProtectKernelTunables=yes RestrictAddressFamilies=AF_UNIX AF_INET AF_INET6 AF_NETLINK RestrictNamespaces=yes RestrictRealtime=yes RestrictSUIDSGID=yes MemoryDenyWriteExecute=yes LockPersonality=yes PrivateTmp=yes PrivateDevices=yes