Grafana Grafana

[SSO] Monitoring dashboard

Grafana open source software enables you to query, visualize, alert on, and explore your metrics, logs, and traces wherever they are stored. Grafana OSS provides you with tools to turn your time-series database (TSDB) data into insightful graphs and visualizations. The Grafana OSS plugin framework also enables you to connect other data sources like NoSQL/SQL databases, ticketing tools like Jira or ServiceNow, and CI/CD tooling like GitLab. (source)

Default admin user credentials: admin / admin

Links:

Recommended dashboards to import:

Authentik OIDC

Grafana uses native OIDC for Authentik’s monitoring group. Keep a local Grafana administrator enabled for recovery. API tokens and service accounts are independent of browser SSO.

Setup

Create the ignored client-secret file:

config/docker/<host>/grafana/authentik-client-secret

Set its mode to 0600, then set GRAFANA_AUTHENTIK_CLIENT_ID and GRAFANA_AUTHENTIK_CLIENT_SECRET_PATH in the ignored config/docker/<host>/.env.grafana file. Create the Authentik resources and recreate Grafana:

scripts/authentik-apps.py --application grafana --apply
scripts/labctl.py service recreate monitoring/grafana

The Compose configuration supplies the issuer endpoints, PKCE, refresh-token scope, and sign-out endpoint. Keep the registered callback URI exact: https://grafana.<domain>/login/generic_oauth.

Verify

Confirm a monitoring member can sign in, a non-member is denied, and the retained local administrator can still sign in. Access changes are re-evaluated when Grafana refreshes its Authentik token.

name: grafana
services:
  grafana:
    image: grafana/grafana-oss:13.0.2
    container_name: grafana
    restart: unless-stopped
    user: "0:0"
    environment:
      GF_SERVER_ROOT_URL: https://grafana.${MYDOMAIN}/
      GF_AUTH_DISABLE_LOGIN_FORM: "false"
      GF_AUTH_GENERIC_OAUTH_ENABLED: "true"
      GF_AUTH_GENERIC_OAUTH_NAME: Authentik
      GF_AUTH_GENERIC_OAUTH_ALLOW_SIGN_UP: "true"
      GF_AUTH_GENERIC_OAUTH_AUTO_LOGIN: "false"
      GF_AUTH_GENERIC_OAUTH_ALLOW_ASSIGN_GRAFANA_ADMIN: "false"
      GF_AUTH_GENERIC_OAUTH_CLIENT_ID: ${GRAFANA_AUTHENTIK_CLIENT_ID:?Configure Grafana Authentik client ID}
      GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET__FILE: /run/secrets/grafana-authentik-client-secret
      # Revalidate Authentik application access when the five-minute access token expires.
      GF_AUTH_GENERIC_OAUTH_SCOPES: openid profile email offline_access
      GF_AUTH_GENERIC_OAUTH_USE_REFRESH_TOKEN: "true"
      GF_AUTH_GENERIC_OAUTH_AUTH_URL: https://sso.${MYDOMAIN}/application/o/authorize/
      GF_AUTH_GENERIC_OAUTH_TOKEN_URL: https://sso.${MYDOMAIN}/application/o/token/
      GF_AUTH_GENERIC_OAUTH_API_URL: https://sso.${MYDOMAIN}/application/o/userinfo/
      GF_AUTH_GENERIC_OAUTH_USE_PKCE: "true"
      GF_AUTH_SIGNOUT_REDIRECT_URL: https://sso.${MYDOMAIN}/application/o/grafana/end-session/
    volumes:
      - ${DOCKER_VOLUMES}/grafana:/var/lib/grafana
    secrets:
      - grafana-authentik-client-secret
    networks:
      - proxy
    labels:
      traefik.enable: true
      traefik.http.routers.grafana.middlewares: localaccess@file
      traefik.http.services.grafana.loadbalancer.server.port: 3000
      homepage.group: Monitoring
      homepage.name: Grafana
      homepage.icon: grafana.png
      homepage.href: https://grafana.${MYDOMAIN}/
      homepage.description: "[SSO] Monitoring dashboard"

networks:
  proxy:
    external: true

secrets:
  grafana-authentik-client-secret:
    file: ${GRAFANA_AUTHENTIK_CLIENT_SECRET_PATH:?Configure Grafana Authentik client secret path}

# volumes:
#   grafana-data:
#     driver: local