osp-grafana

Warning

Beta version This feature is currently in beta. It may change in a future version without prior notice. See the Beta Features page for the full list of beta features and their planned release. If you’re using this feature, we encourage you to share your feedback to help with the evaluation process.

List of configuration files

Filename

Short description

Format

Documentation

module.service

Each service is defined in a separate file and then combined into a unified compose stack file

yml

See the Swarm administration or Official documentation

Swissdotnet implementation

The default Grafana installation is the non-enterprise edition. To include the enterprise edition, refer to the Requirements section to create a personalized docker image.

Requirements

  • The module must be called exactly osp-grafana, otherwise the connection from Keycloak and the frontend will fail on the default hardcoded nginx configuration in the osp-web module. For unmanaged mode, the service name must be osp-grafana.

  • The environment variables below must be set exactly as shown.

Persistent storage

The osp-grafana plugin stores the entire Grafana configuration (dashboards, datasources, alerts, etc.) in the path /var/lib/grafana. See persistent storage section for more details on how to implement persistent storage in your configuration.

By default the /var/lib/grafana path is stored into the default volume grafana_data

Healthcheck

The healthcheck is done based on the return of the API.

curl -k -s http://localhost:3000/api/health | grep -q '"database": "ok"'

With the default parameters :

HEALTHCHECK --start-period=300s --timeout=5s --interval=15s CMD /osp/bin/healthcheck.sh || exit 1

Environment Variables

All modules env variables

Variable Name

Default Value

Usage

PROMETHEUS_PORT

9100

The internal port used for Openmetrics exposition.

DISPATCHER_HOST

modules_configuration-dispatcher_main

The hostname on which the modules can fetch the configuration.

DISPATCHER_PORT

10000

The port used by the module to listen for configuration request.

USE_LEGACY_RESTART

Not set

When this flag is enabled, the container will terminate itself whenever a restart is needed (for example, after a configuration change). This is the legacy restart (before version 2.1.0). Otherwise, the system will simply restart the process running inside the container.

CUSTOM_JVM_OPTIONS

Not set

Allow to inject JVM options. See Configuration changes for more information.

ALLOW_VERSION_MISMATCH

Not set

Allow to disable the version check when a new configuration is published to a module. By default, a module will not be restarted if its configuration does not match its version.

Dedicated variables

Environment Variable

Value

GF_SECURITY_ALLOW_EMBEDDING

true

GF_SERVER_PROTOCOL

http

GF_SERVER_SERVE_FROM_SUB_PATH

true

GF_AUTH_GENERIC_OAUTH_ENABLED

true

GF_AUTH_GENERIC_OAUTH_NAME

Keycloak

GF_AUTH_GENERIC_OAUTH_CLIENT_ID

grafana

GF_AUTH_GENERIC_OAUTH_TLS_SKIP_VERIFY

true

GF_AUTH_GENERIC_OAUTH_ALLOW_SIGN_UP

true

GF_AUTH_GENERIC_OAUTH_AUTO_LOGIN

true

GF_AUTH_DISABLE_LOGIN_FORM

true

GF_AUTH_OAUTH_AUTO_LOGIN

true

GF_AUTH_GENERIC_OAUTH_SCOPES

“openid email profile”

GF_AUTH_GENERIC_OAUTH_ALLOW_ASSIGN_GRAFANA_ADMIN

true

GF_AUTH_GENERIC_OAUTH_TLS_SKIP_VERIFY_INSECURE

true

GF_AUTH_GENERIC_OAUTH_API_URL

/auth/realms/onsphere/protocol/openid-connect/userinfo

GF_AUTH_GENERIC_OAUTH_AUTH_URL

/auth/realms/onsphere/protocol/openid-connect/auth

GF_SERVER_HTTP_PORT

3000

GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET

Can be found in Bitwarden under the entry Grafana & Keycloak secret oauth

GF_SERVER_ROOT_URL

/osp/grafana

GF_AUTH_GENERIC_OAUTH_TOKEN_URL

http://osp-keycloak:8080/auth/realms/onsphere/protocol/openid-connect/token

GF_RENDERING_SERVER_URL

http://osp-grafana-renderer:8081/render

GF_RENDERING_CALLBACK_URL

http://osp-grafana:3000/osp/grafana

The secret defined by the environment variable GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET is used to establish the connection with Keycloak. To change it, you must update it both in Grafana and in the Keycloak realm.json file.

Note

For more information on the environment variables, refer to the official Grafana documentation: grafana configuration