diff --git a/grafana.yml b/grafana.yml
new file mode 100644
index 0000000..32e462b
--- /dev/null
+++ b/grafana.yml
@@ -0,0 +1,3 @@
+- hosts: grafana
+ roles:
+ - grafana
diff --git a/group_vars/grafana/main.yml b/group_vars/grafana/main.yml
new file mode 100644
index 0000000..956b3ea
--- /dev/null
+++ b/group_vars/grafana/main.yml
@@ -0,0 +1,17 @@
+grafana_ldap_enabled: true
+grafana_http_addr: '[::1]'
+grafana_ldap_host: dc0.pyrocufflink.blue
+grafana_ldap_ssl: true
+grafana_ldap_start_tls: true
+grafana_ldap_bind_dn: CN=svc.grafana,CN=Users,DC=pyrocufflink,DC=blue
+grafana_ldap_search_filter: (sAMAccountName=%s)
+grafana_ldap_search_base_dns:
+- DC=pyrocufflink,DC=blue
+grafana_ldap_attr_username: sAMAccountName
+grafana_ldap_attr_email: mail
+grafana_ldap_group_mappings:
+- group_dn: CN=Grafana Admins,CN=Users,DC=pyrocufflink,DC=blue
+ org_role: Admin
+ grafana_admin: true
+- group_dn: '*'
+ org_role: Viewer
diff --git a/group_vars/grafana/secrets b/group_vars/grafana/secrets
new file mode 100644
index 0000000..dd9f6a2
--- /dev/null
+++ b/group_vars/grafana/secrets
@@ -0,0 +1,9 @@
+$ANSIBLE_VAULT;1.1;AES256
+35333639333036633432663463313536316163366130626436623962363466616234306462333239
+3338353961306664326137343262373565643234666238340a316163616236373636323836366363
+38653732643539666465323537613634376238343833313063623964363862633939376164313961
+3837366130386631370a323131333561353638353738393835346533393563393132323763316663
+37353735346438346435336465333565353866323434346131316434366362343964613933316530
+31633933346263323262323631623138326337343132383035613634383233313963663530333636
+33376232383937336463353837346264316537396431376636336264613439613538613038633637
+63316336313661386135
diff --git a/hosts b/hosts
index 2ff663e..b94e8fc 100644
--- a/hosts
+++ b/hosts
@@ -44,6 +44,8 @@ file0.pyrocufflink.blue
[gitea]
git0.pyrocufflink.blue
+[grafana]
+
[graylog]
logs0.pyrocufflink.blue
diff --git a/roles/grafana/defaults/main.yml b/roles/grafana/defaults/main.yml
new file mode 100644
index 0000000..0fa1a39
--- /dev/null
+++ b/roles/grafana/defaults/main.yml
@@ -0,0 +1,23 @@
+grafana_ldap_enabled: false
+grafana_http_addr:
+grafana_ldap_host: 127.0.0.1
+grafana_ldap_port: 389
+grafana_ldap_ssl: false
+grafana_ldap_start_tls: false
+grafana_ldap_bind_dn: cn=admin,dc=grafana,dc=org
+grafana_ldap_bind_password: grafana
+grafana_ldap_search_filter: (cn=%s)
+grafana_ldap_search_base_dns:
+- dc=grafana,dc=org
+grafana_ldap_attr_name: givenName
+grafana_ldap_attr_surname: sn
+grafana_ldap_attr_username: cn
+grafana_ldap_attr_member_of: memberOf
+grafana_ldap_attr_email: email
+grafana_ldap_group_mappings:
+- group_dn: cn=admins,ou=groups,dc=grafana,dc=org
+ org_role: Admin
+- group_dn: cn=users,ou=groups,dc=grafana,dc=org
+ org_role: Editor
+- group_dn: '*'
+ org_role: Viewer
diff --git a/roles/grafana/files/grafana.nginx.conf b/roles/grafana/files/grafana.nginx.conf
new file mode 100644
index 0000000..ed1f205
--- /dev/null
+++ b/roles/grafana/files/grafana.nginx.conf
@@ -0,0 +1,3 @@
+location / {
+ proxy_pass http://[::1]:3000/;
+}
diff --git a/roles/grafana/handlers/main.yml b/roles/grafana/handlers/main.yml
new file mode 100644
index 0000000..73865e6
--- /dev/null
+++ b/roles/grafana/handlers/main.yml
@@ -0,0 +1,8 @@
+- name: restart grafana
+ service:
+ name: grafana-server
+ state: restarted
+- name: reload nginx
+ service:
+ name: nginx
+ state: reloaded
diff --git a/roles/grafana/meta/main.yml b/roles/grafana/meta/main.yml
new file mode 100644
index 0000000..3ebd2a7
--- /dev/null
+++ b/roles/grafana/meta/main.yml
@@ -0,0 +1,4 @@
+dependencies:
+- role: nginx
+ tags:
+ - nginx
diff --git a/roles/grafana/tasks/main.yml b/roles/grafana/tasks/main.yml
new file mode 100644
index 0000000..1c80700
--- /dev/null
+++ b/roles/grafana/tasks/main.yml
@@ -0,0 +1,43 @@
+- name: ensure grafana is installed
+ package:
+ name: grafana
+ state: present
+ tags:
+ - install
+
+- name: ensure grafana is configured
+ template:
+ src: grafana.ini.j2
+ dest: /etc/grafana/grafana.ini
+ owner: root
+ group: grafana
+ mode: '0640'
+ notify: restart grafana
+ tags:
+ - config
+- name: ensure grafana ldap servers are configured
+ template:
+ src: ldap.toml.j2
+ dest: /etc/grafana/ldap.toml
+ owner: root
+ group: grafana
+ mode: '0640'
+ notify: restart grafana
+ tags:
+ - config
+
+- name: ensure nginx is configured to proxy for grafana
+ copy:
+ src: grafana.nginx.conf
+ dest: /etc/nginx/default.d/grafan.conf
+ mode: '0644'
+ notify: reload nginx
+ tags:
+ - nginx-config
+
+- meta: flush_handlers
+
+- name: ensure grafana is running
+ service:
+ name: grafana-server
+ state: started
diff --git a/roles/grafana/templates/grafana.ini.j2 b/roles/grafana/templates/grafana.ini.j2
new file mode 100644
index 0000000..22d8898
--- /dev/null
+++ b/roles/grafana/templates/grafana.ini.j2
@@ -0,0 +1,860 @@
+##################### Grafana Configuration Defaults #####################
+#
+# Do not modify this file in grafana installs
+#
+
+# possible values : production, development
+app_mode = production
+
+# instance name, defaults to HOSTNAME environment variable value or hostname if HOSTNAME var is empty
+instance_name = ${HOSTNAME}
+
+#################################### Paths ###############################
+[paths]
+# Path to where grafana can store temp files, sessions, and the sqlite3 db (if that is used)
+data = /var/lib/grafana
+
+# Temporary files in `data` directory older than given duration will be removed
+temp_data_lifetime = 24h
+
+# Directory where grafana can store logs
+logs = /var/log/grafana
+
+# Directory where grafana will automatically scan and look for plugins
+plugins = /var/lib/grafana/plugins
+
+# folder that contains provisioning config files that grafana will apply on startup and while running.
+provisioning = /etc/grafana/provisioning
+
+#################################### Server ##############################
+[server]
+# Protocol (http, https, h2, socket)
+protocol = http
+
+# The ip address to bind to, empty will bind to all interfaces
+http_addr = {{ grafana_http_addr }}
+
+# The http port to use
+http_port = 3000
+
+# The public facing domain name used to access grafana from a browser
+domain = localhost
+
+# Redirect to correct domain if host header does not match domain
+# Prevents DNS rebinding attacks
+enforce_domain = false
+
+# The full public facing url
+root_url = %(protocol)s://%(domain)s:%(http_port)s/
+
+# Serve Grafana from subpath specified in `root_url` setting. By default it is set to `false` for compatibility reasons.
+serve_from_sub_path = false
+
+# Log web requests
+router_logging = false
+
+# the path relative working path
+static_root_path = public
+
+# enable gzip
+enable_gzip = false
+
+# https certs & key file
+cert_file =
+cert_key =
+
+# Unix socket path
+socket = /tmp/grafana.sock
+
+#################################### Database ############################
+[database]
+# You can configure the database connection by specifying type, host, name, user and password
+# as separate properties or as on string using the url property.
+
+# Either "mysql", "postgres" or "sqlite3", it's your choice
+type = sqlite3
+host = 127.0.0.1:3306
+name = grafana
+user = root
+# If the password contains # or ; you have to wrap it with triple quotes. Ex """#password;"""
+password =
+# Use either URL or the previous fields to configure the database
+# Example: mysql://user:secret@host:port/database
+url =
+
+# Max idle conn setting default is 2
+max_idle_conn = 2
+
+# Max conn setting default is 0 (mean not set)
+max_open_conn =
+
+# Connection Max Lifetime default is 14400 (means 14400 seconds or 4 hours)
+conn_max_lifetime = 14400
+
+# Set to true to log the sql calls and execution times.
+log_queries =
+
+# For "postgres", use either "disable", "require" or "verify-full"
+# For "mysql", use either "true", "false", or "skip-verify".
+ssl_mode = disable
+
+ca_cert_path =
+client_key_path =
+client_cert_path =
+server_cert_name =
+
+# For "sqlite3" only, path relative to data_path setting
+path = grafana.db
+
+# For "sqlite3" only. cache mode setting used for connecting to the database
+cache_mode = private
+
+#################################### Cache server #############################
+[remote_cache]
+# Either "redis", "memcached" or "database" default is "database"
+type = database
+
+# cache connectionstring options
+# database: will use Grafana primary database.
+# redis: config like redis server e.g. `addr=127.0.0.1:6379,pool_size=100,db=0,ssl=false`. Only addr is required. ssl may be 'true', 'false', or 'insecure'.
+# memcache: 127.0.0.1:11211
+connstr =
+
+#################################### Data proxy ###########################
+[dataproxy]
+
+# This enables data proxy logging, default is false
+logging = false
+
+# How long the data proxy waits before timing out, default is 30 seconds.
+# This setting also applies to core backend HTTP data sources where query requests use an HTTP client with timeout set.
+timeout = 30
+
+# How many seconds the data proxy waits before sending a keepalive request.
+keep_alive_seconds = 30
+
+# How many seconds the data proxy waits for a successful TLS Handshake before timing out.
+tls_handshake_timeout_seconds = 10
+
+# How many seconds the data proxy will wait for a server's first response headers after
+# fully writing the request headers if the request has an "Expect: 100-continue"
+# header. A value of 0 will result in the body being sent immediately, without
+# waiting for the server to approve.
+expect_continue_timeout_seconds = 1
+
+# The maximum number of idle connections that Grafana will keep alive.
+max_idle_connections = 100
+
+# How many seconds the data proxy keeps an idle connection open before timing out.
+idle_conn_timeout_seconds = 90
+
+# If enabled and user is not anonymous, data proxy will add X-Grafana-User header with username into the request.
+send_user_header = false
+
+#################################### Analytics ###########################
+[analytics]
+# Server reporting, sends usage counters to stats.grafana.org every 24 hours.
+# No ip addresses are being tracked, only simple counters to track
+# running instances, dashboard and error counts. It is very helpful to us.
+# Change this option to false to disable reporting.
+reporting_enabled = false
+
+# Set to false to disable all checks to https://grafana.com
+# for new versions (grafana itself and plugins), check is used
+# in some UI views to notify that grafana or plugin update exists
+# This option does not cause any auto updates, nor send any information
+# only a GET request to https://grafana.com to get latest versions
+check_for_updates = false
+
+# Google Analytics universal tracking code, only enabled if you specify an id here
+google_analytics_ua_id =
+
+# Google Tag Manager ID, only enabled if you specify an id here
+google_tag_manager_id =
+
+#################################### Security ############################
+[security]
+# disable creation of admin user on first start of grafana
+disable_initial_admin_creation = false
+
+# default admin user, created on startup
+admin_user = admin
+
+# default admin password, can be changed before first start of grafana, or in profile settings
+admin_password = admin
+
+# used for signing
+secret_key = SW2YcwTIb9zpOOhoPsMm
+
+# disable gravatar profile images
+disable_gravatar = false
+
+# data source proxy whitelist (ip_or_domain:port separated by spaces)
+data_source_proxy_whitelist =
+
+# disable protection against brute force login attempts
+disable_brute_force_login_protection = false
+
+# set to true if you host Grafana behind HTTPS. default is false.
+cookie_secure = false
+
+# set cookie SameSite attribute. defaults to `lax`. can be set to "lax", "strict", "none" and "disabled"
+cookie_samesite = lax
+
+# set to true if you want to allow browsers to render Grafana in a ,