diff --git a/grafana.yml b/grafana.yml new file mode 100644 index 0000000..32e462b --- /dev/null +++ b/grafana.yml @@ -0,0 +1,3 @@ +- hosts: grafana + roles: + - grafana diff --git a/group_vars/grafana/main.yml b/group_vars/grafana/main.yml new file mode 100644 index 0000000..956b3ea --- /dev/null +++ b/group_vars/grafana/main.yml @@ -0,0 +1,17 @@ +grafana_ldap_enabled: true +grafana_http_addr: '[::1]' +grafana_ldap_host: dc0.pyrocufflink.blue +grafana_ldap_ssl: true +grafana_ldap_start_tls: true +grafana_ldap_bind_dn: CN=svc.grafana,CN=Users,DC=pyrocufflink,DC=blue +grafana_ldap_search_filter: (sAMAccountName=%s) +grafana_ldap_search_base_dns: +- DC=pyrocufflink,DC=blue +grafana_ldap_attr_username: sAMAccountName +grafana_ldap_attr_email: mail +grafana_ldap_group_mappings: +- group_dn: CN=Grafana Admins,CN=Users,DC=pyrocufflink,DC=blue + org_role: Admin + grafana_admin: true +- group_dn: '*' + org_role: Viewer diff --git a/group_vars/grafana/secrets b/group_vars/grafana/secrets new file mode 100644 index 0000000..dd9f6a2 --- /dev/null +++ b/group_vars/grafana/secrets @@ -0,0 +1,9 @@ +$ANSIBLE_VAULT;1.1;AES256 +35333639333036633432663463313536316163366130626436623962363466616234306462333239 +3338353961306664326137343262373565643234666238340a316163616236373636323836366363 +38653732643539666465323537613634376238343833313063623964363862633939376164313961 +3837366130386631370a323131333561353638353738393835346533393563393132323763316663 +37353735346438346435336465333565353866323434346131316434366362343964613933316530 +31633933346263323262323631623138326337343132383035613634383233313963663530333636 +33376232383937336463353837346264316537396431376636336264613439613538613038633637 +63316336313661386135 diff --git a/hosts b/hosts index 2ff663e..b94e8fc 100644 --- a/hosts +++ b/hosts @@ -44,6 +44,8 @@ file0.pyrocufflink.blue [gitea] git0.pyrocufflink.blue +[grafana] + [graylog] logs0.pyrocufflink.blue diff --git a/roles/grafana/defaults/main.yml b/roles/grafana/defaults/main.yml new file mode 100644 index 0000000..0fa1a39 --- /dev/null +++ b/roles/grafana/defaults/main.yml @@ -0,0 +1,23 @@ +grafana_ldap_enabled: false +grafana_http_addr: +grafana_ldap_host: 127.0.0.1 +grafana_ldap_port: 389 +grafana_ldap_ssl: false +grafana_ldap_start_tls: false +grafana_ldap_bind_dn: cn=admin,dc=grafana,dc=org +grafana_ldap_bind_password: grafana +grafana_ldap_search_filter: (cn=%s) +grafana_ldap_search_base_dns: +- dc=grafana,dc=org +grafana_ldap_attr_name: givenName +grafana_ldap_attr_surname: sn +grafana_ldap_attr_username: cn +grafana_ldap_attr_member_of: memberOf +grafana_ldap_attr_email: email +grafana_ldap_group_mappings: +- group_dn: cn=admins,ou=groups,dc=grafana,dc=org + org_role: Admin +- group_dn: cn=users,ou=groups,dc=grafana,dc=org + org_role: Editor +- group_dn: '*' + org_role: Viewer diff --git a/roles/grafana/files/grafana.nginx.conf b/roles/grafana/files/grafana.nginx.conf new file mode 100644 index 0000000..ed1f205 --- /dev/null +++ b/roles/grafana/files/grafana.nginx.conf @@ -0,0 +1,3 @@ +location / { + proxy_pass http://[::1]:3000/; +} diff --git a/roles/grafana/handlers/main.yml b/roles/grafana/handlers/main.yml new file mode 100644 index 0000000..73865e6 --- /dev/null +++ b/roles/grafana/handlers/main.yml @@ -0,0 +1,8 @@ +- name: restart grafana + service: + name: grafana-server + state: restarted +- name: reload nginx + service: + name: nginx + state: reloaded diff --git a/roles/grafana/meta/main.yml b/roles/grafana/meta/main.yml new file mode 100644 index 0000000..3ebd2a7 --- /dev/null +++ b/roles/grafana/meta/main.yml @@ -0,0 +1,4 @@ +dependencies: +- role: nginx + tags: + - nginx diff --git a/roles/grafana/tasks/main.yml b/roles/grafana/tasks/main.yml new file mode 100644 index 0000000..1c80700 --- /dev/null +++ b/roles/grafana/tasks/main.yml @@ -0,0 +1,43 @@ +- name: ensure grafana is installed + package: + name: grafana + state: present + tags: + - install + +- name: ensure grafana is configured + template: + src: grafana.ini.j2 + dest: /etc/grafana/grafana.ini + owner: root + group: grafana + mode: '0640' + notify: restart grafana + tags: + - config +- name: ensure grafana ldap servers are configured + template: + src: ldap.toml.j2 + dest: /etc/grafana/ldap.toml + owner: root + group: grafana + mode: '0640' + notify: restart grafana + tags: + - config + +- name: ensure nginx is configured to proxy for grafana + copy: + src: grafana.nginx.conf + dest: /etc/nginx/default.d/grafan.conf + mode: '0644' + notify: reload nginx + tags: + - nginx-config + +- meta: flush_handlers + +- name: ensure grafana is running + service: + name: grafana-server + state: started diff --git a/roles/grafana/templates/grafana.ini.j2 b/roles/grafana/templates/grafana.ini.j2 new file mode 100644 index 0000000..22d8898 --- /dev/null +++ b/roles/grafana/templates/grafana.ini.j2 @@ -0,0 +1,860 @@ +##################### Grafana Configuration Defaults ##################### +# +# Do not modify this file in grafana installs +# + +# possible values : production, development +app_mode = production + +# instance name, defaults to HOSTNAME environment variable value or hostname if HOSTNAME var is empty +instance_name = ${HOSTNAME} + +#################################### Paths ############################### +[paths] +# Path to where grafana can store temp files, sessions, and the sqlite3 db (if that is used) +data = /var/lib/grafana + +# Temporary files in `data` directory older than given duration will be removed +temp_data_lifetime = 24h + +# Directory where grafana can store logs +logs = /var/log/grafana + +# Directory where grafana will automatically scan and look for plugins +plugins = /var/lib/grafana/plugins + +# folder that contains provisioning config files that grafana will apply on startup and while running. +provisioning = /etc/grafana/provisioning + +#################################### Server ############################## +[server] +# Protocol (http, https, h2, socket) +protocol = http + +# The ip address to bind to, empty will bind to all interfaces +http_addr = {{ grafana_http_addr }} + +# The http port to use +http_port = 3000 + +# The public facing domain name used to access grafana from a browser +domain = localhost + +# Redirect to correct domain if host header does not match domain +# Prevents DNS rebinding attacks +enforce_domain = false + +# The full public facing url +root_url = %(protocol)s://%(domain)s:%(http_port)s/ + +# Serve Grafana from subpath specified in `root_url` setting. By default it is set to `false` for compatibility reasons. +serve_from_sub_path = false + +# Log web requests +router_logging = false + +# the path relative working path +static_root_path = public + +# enable gzip +enable_gzip = false + +# https certs & key file +cert_file = +cert_key = + +# Unix socket path +socket = /tmp/grafana.sock + +#################################### Database ############################ +[database] +# You can configure the database connection by specifying type, host, name, user and password +# as separate properties or as on string using the url property. + +# Either "mysql", "postgres" or "sqlite3", it's your choice +type = sqlite3 +host = 127.0.0.1:3306 +name = grafana +user = root +# If the password contains # or ; you have to wrap it with triple quotes. Ex """#password;""" +password = +# Use either URL or the previous fields to configure the database +# Example: mysql://user:secret@host:port/database +url = + +# Max idle conn setting default is 2 +max_idle_conn = 2 + +# Max conn setting default is 0 (mean not set) +max_open_conn = + +# Connection Max Lifetime default is 14400 (means 14400 seconds or 4 hours) +conn_max_lifetime = 14400 + +# Set to true to log the sql calls and execution times. +log_queries = + +# For "postgres", use either "disable", "require" or "verify-full" +# For "mysql", use either "true", "false", or "skip-verify". +ssl_mode = disable + +ca_cert_path = +client_key_path = +client_cert_path = +server_cert_name = + +# For "sqlite3" only, path relative to data_path setting +path = grafana.db + +# For "sqlite3" only. cache mode setting used for connecting to the database +cache_mode = private + +#################################### Cache server ############################# +[remote_cache] +# Either "redis", "memcached" or "database" default is "database" +type = database + +# cache connectionstring options +# database: will use Grafana primary database. +# redis: config like redis server e.g. `addr=127.0.0.1:6379,pool_size=100,db=0,ssl=false`. Only addr is required. ssl may be 'true', 'false', or 'insecure'. +# memcache: 127.0.0.1:11211 +connstr = + +#################################### Data proxy ########################### +[dataproxy] + +# This enables data proxy logging, default is false +logging = false + +# How long the data proxy waits before timing out, default is 30 seconds. +# This setting also applies to core backend HTTP data sources where query requests use an HTTP client with timeout set. +timeout = 30 + +# How many seconds the data proxy waits before sending a keepalive request. +keep_alive_seconds = 30 + +# How many seconds the data proxy waits for a successful TLS Handshake before timing out. +tls_handshake_timeout_seconds = 10 + +# How many seconds the data proxy will wait for a server's first response headers after +# fully writing the request headers if the request has an "Expect: 100-continue" +# header. A value of 0 will result in the body being sent immediately, without +# waiting for the server to approve. +expect_continue_timeout_seconds = 1 + +# The maximum number of idle connections that Grafana will keep alive. +max_idle_connections = 100 + +# How many seconds the data proxy keeps an idle connection open before timing out. +idle_conn_timeout_seconds = 90 + +# If enabled and user is not anonymous, data proxy will add X-Grafana-User header with username into the request. +send_user_header = false + +#################################### Analytics ########################### +[analytics] +# Server reporting, sends usage counters to stats.grafana.org every 24 hours. +# No ip addresses are being tracked, only simple counters to track +# running instances, dashboard and error counts. It is very helpful to us. +# Change this option to false to disable reporting. +reporting_enabled = false + +# Set to false to disable all checks to https://grafana.com +# for new versions (grafana itself and plugins), check is used +# in some UI views to notify that grafana or plugin update exists +# This option does not cause any auto updates, nor send any information +# only a GET request to https://grafana.com to get latest versions +check_for_updates = false + +# Google Analytics universal tracking code, only enabled if you specify an id here +google_analytics_ua_id = + +# Google Tag Manager ID, only enabled if you specify an id here +google_tag_manager_id = + +#################################### Security ############################ +[security] +# disable creation of admin user on first start of grafana +disable_initial_admin_creation = false + +# default admin user, created on startup +admin_user = admin + +# default admin password, can be changed before first start of grafana, or in profile settings +admin_password = admin + +# used for signing +secret_key = SW2YcwTIb9zpOOhoPsMm + +# disable gravatar profile images +disable_gravatar = false + +# data source proxy whitelist (ip_or_domain:port separated by spaces) +data_source_proxy_whitelist = + +# disable protection against brute force login attempts +disable_brute_force_login_protection = false + +# set to true if you host Grafana behind HTTPS. default is false. +cookie_secure = false + +# set cookie SameSite attribute. defaults to `lax`. can be set to "lax", "strict", "none" and "disabled" +cookie_samesite = lax + +# set to true if you want to allow browsers to render Grafana in a ,