Hello,
The example doas.conf(5) rules in the README permit _telegraf to run
unbound-control(8) as _unbound and nsd-control(8) as _nsd. The
plugins only replaced sudo with doas and invoked
doas /usr/sbin/unbound-control stats_noreset
doas /usr/sbin/nsd-control stats_noreset
doas(1) defaults to root unless -u is given, so those rules never match
and the plugins fail with exit status 1.
Pass -u _unbound / -u _nsd so the commands match the README.
ok?
Index: Makefile
===================================================================
RCS file: /cvs/ports/sysutils/telegraf/Makefile,v
diff -u -p -r1.47 Makefile
--- Makefile 20 Jul 2026 22:44:35 -0000 1.47
+++ Makefile 28 Aug 2026 14:31:39 -0000
@@ -14,6 +14,8 @@ MAINTAINER = Lucas Raab <tuftedocelot@fa
CATEGORIES = sysutils
+REVISION = 0
+
# MIT
PERMIT_PACKAGE = Yes
Index: patches/patch-plugins_inputs_nsd_nsd_go
===================================================================
RCS file: /cvs/ports/sysutils/telegraf/patches/patch-plugins_inputs_nsd_nsd_go,v
diff -u -p -r1.3 patch-plugins_inputs_nsd_nsd_go
--- patches/patch-plugins_inputs_nsd_nsd_go 6 Mar 2025 01:58:54 -0000
1.3
+++ patches/patch-plugins_inputs_nsd_nsd_go 28 Aug 2026 14:31:40 -0000
@@ -1,11 +1,13 @@
Index: plugins/inputs/nsd/nsd.go
--- plugins/inputs/nsd/nsd.go.orig
+++ plugins/inputs/nsd/nsd.go
-@@ -120,7 +120,7 @@ func nsdRunner(cmdName string, timeout config.Duration
+@@ -119,8 +119,8 @@ func nsdRunner(cmdName string, timeout config.Duration
+ cmd := exec.Command(cmdName, cmdArgs...)
if useSudo {
- cmdArgs = append([]string{cmdName}, cmdArgs...)
+- cmdArgs = append([]string{cmdName}, cmdArgs...)
- cmd = exec.Command("sudo", cmdArgs...)
++ cmdArgs = append([]string{"-u", "_nsd", cmdName}, cmdArgs...)
+ cmd = exec.Command("doas", cmdArgs...)
}
Index: patches/patch-plugins_inputs_unbound_unbound_go
===================================================================
RCS file:
/cvs/ports/sysutils/telegraf/patches/patch-plugins_inputs_unbound_unbound_go,v
diff -u -p -r1.5 patch-plugins_inputs_unbound_unbound_go
--- patches/patch-plugins_inputs_unbound_unbound_go 10 Jul 2025 03:38:13
-0000 1.5
+++ patches/patch-plugins_inputs_unbound_unbound_go 28 Aug 2026 14:31:40
-0000
@@ -1,11 +1,13 @@
Index: plugins/inputs/unbound/unbound.go
--- plugins/inputs/unbound/unbound.go.orig
+++ plugins/inputs/unbound/unbound.go
-@@ -159,7 +159,7 @@ func unboundRunner(unbound Unbound) (*bytes.Buffer, er
+@@ -158,8 +158,8 @@ func unboundRunner(unbound Unbound) (*bytes.Buffer, er
+ cmd := exec.Command(unbound.Binary, cmdArgs...)
if unbound.UseSudo {
- cmdArgs = append([]string{unbound.Binary}, cmdArgs...)
+- cmdArgs = append([]string{unbound.Binary}, cmdArgs...)
- cmd = exec.Command("sudo", cmdArgs...)
++ cmdArgs = append([]string{"-u", "_unbound", unbound.Binary},
cmdArgs...)
+ cmd = exec.Command("doas", cmdArgs...)
}
Index: pkg/README
===================================================================
RCS file: /cvs/ports/sysutils/telegraf/pkg/README,v
diff -u -p -r1.2 README
--- pkg/README 20 Jul 2026 22:44:35 -0000 1.2
+++ pkg/README 28 Aug 2026 14:31:40 -0000
@@ -13,9 +13,12 @@ install and configure sudo:
* OpenSMTPD
* Unbound
-Below are some example doas.conf(5) lines which could be used. If you
-have a nonstandard configuration of those daemons, adjustments to the
-location of binaries and arguments may be needed.
+Below are some example doas.conf(5) lines which could be used.
+Set use_sudo = true in the plugin configuration so telegraf invokes
+doas(1). If you have a nonstandard configuration of those daemons,
+adjustments to the location of binaries and arguments may be needed.
+The Unbound and NSD plugins run the control commands as _unbound
+and _nsd.
permit nopass _telegraf as _unbound cmd /usr/sbin/unbound-control \
args stats_noreset