From dbb533424f6df25bfff92d04ad78024cceb21496 Mon Sep 17 00:00:00 2001 From: nd Date: Tue, 5 Nov 2019 00:45:01 +0100 Subject: [PATCH] add support for config options and nginx --- defaults/main.yml | 4 + meta/main.yml | 1 + tasks/main.yml | 24 +- templates/grafana.ini.j2 | 615 +++++++++++++++++++++++++++++++++++++++ vars/main.yml | 15 + 5 files changed, 656 insertions(+), 3 deletions(-) create mode 100644 templates/grafana.ini.j2 diff --git a/defaults/main.yml b/defaults/main.yml index 3b77667..4df5b2d 100644 --- a/defaults/main.yml +++ b/defaults/main.yml @@ -1,5 +1,9 @@ grafana: adminpw: "{{ lookup('password', '/dev/null') }}" + config: + secret_key: "{{ lookup('password', '/dev/null') }}" + instance_name: "${HOSTNAME}" + root_url: "https://localhost" plugins: "grafana-piechart-panel": {} datasources: [] diff --git a/meta/main.yml b/meta/main.yml index cfcf207..17405f0 100644 --- a/meta/main.yml +++ b/meta/main.yml @@ -1,3 +1,4 @@ --- dependencies: - packages +- nginx diff --git a/tasks/main.yml b/tasks/main.yml index 84f1ceb..1b33c10 100644 --- a/tasks/main.yml +++ b/tasks/main.yml @@ -2,6 +2,12 @@ apt: pkg: grafana +- name: add www-data to grafana group + user: + name: www-data + groups: grafana + append: yes + - name: set admin password command: argv: @@ -21,15 +27,27 @@ command: grafana-cli plugins update-all notify: restart grafana +- name: copy grafana config + notify: restart grafana + template: + src: grafana.ini.j2 + dest: /etc/grafana/grafana.ini + owner: root + group: grafana + mode: 0640 + - name: "ensure grafana is started" service: name: grafana-server enabled: true state: started +- name: flush handlers so grafana is ready + meta: flush_handlers + - name: "Check if grafana is accessible." uri: - url: http://127.0.0.1:3000 + url: http://127.0.0.1 method: GET status_code: 200 @@ -37,7 +55,7 @@ loop: "{{ grafana.datasources }}" grafana_datasource: name: "{{ item.name }}" - grafana_url: "http://127.0.0.1:3000" + grafana_url: "http://127.0.0.1" grafana_user: "admin" grafana_password: "{{ grafana.adminpw }}" ds_type: "{{ item.ds_type }}" @@ -48,7 +66,7 @@ - name: import dashboards loop: "{{ grafana.dashboards }}" grafana_dashboard: - grafana_url: "http://127.0.0.1:3000" + grafana_url: "http://127.0.0.1" grafana_user: "admin" grafana_password: "{{ grafana.adminpw }}" path: "{{ item.path }}" diff --git a/templates/grafana.ini.j2 b/templates/grafana.ini.j2 new file mode 100644 index 0000000..46866a3 --- /dev/null +++ b/templates/grafana.ini.j2 @@ -0,0 +1,615 @@ +##################### Grafana Configuration Example ##################### +# +# Everything has defaults so you only need to uncomment things you want to +# change + +# possible values : production, development +;app_mode = production + +# instance name, defaults to HOSTNAME environment variable value or hostname if HOSTNAME var is empty +instance_name = {{ grafana.config.instance_name }} + +#################################### Paths #################################### +[paths] +# Path to where grafana can store temp files, sessions, and the sqlite3 db (if that is used) +;data = /var/lib/grafana + +# Temporary files in `data` directory older than given duration will be removed +;temp_data_lifetime = 24h + +# Directory where grafana can store logs +;logs = /var/log/grafana + +# Directory where grafana will automatically scan and look for plugins +;plugins = /var/lib/grafana/plugins + +# folder that contains provisioning config files that grafana will apply on startup and while running. +;provisioning = conf/provisioning + +#################################### Server #################################### +[server] +# Protocol (http, https, h2, socket) +protocol = socket + +# The ip address to bind to, empty will bind to all interfaces +;http_addr = + +# The http port to use +;http_port = 3000 + +# The public facing domain name used to access grafana from a browser +;domain = localhost + +# Redirect to correct domain if host header does not match domain +# Prevents DNS rebinding attacks +;enforce_domain = false + +# The full public facing url you use in browser, used for redirects and emails +# If you use reverse proxy and sub path specify full url (with sub path) +root_url = {{ grafana.config.root_url }} + +# Serve Grafana from subpath specified in `root_url` setting. By default it is set to `false` for compatibility reasons. +;serve_from_sub_path = false + +# Log web requests +;router_logging = false + +# the path relative working path +;static_root_path = public + +# enable gzip +;enable_gzip = false + +# https certs & key file +;cert_file = +;cert_key = + +# Unix socket path +socket = /var/run/grafana/webui.sock + +#################################### Database #################################### +[database] +# You can configure the database connection by specifying type, host, name, user and password +# as separate properties or as on string using the url properties. + +# Either "mysql", "postgres" or "sqlite3", it's your choice +;type = sqlite3 +;host = 127.0.0.1:3306 +;name = grafana +;user = root +# If the password contains # or ; you have to wrap it with triple quotes. Ex """#password;""" +;password = + +# Use either URL or the previous fields to configure the database +# Example: mysql://user:secret@host:port/database +;url = + +# For "postgres" only, either "disable", "require" or "verify-full" +;ssl_mode = disable + +# For "sqlite3" only, path relative to data_path setting +;path = grafana.db + +# Max idle conn setting default is 2 +;max_idle_conn = 2 + +# Max conn setting default is 0 (mean not set) +;max_open_conn = + +# Connection Max Lifetime default is 14400 (means 14400 seconds or 4 hours) +;conn_max_lifetime = 14400 + +# Set to true to log the sql calls and execution times. +;log_queries = + +# For "sqlite3" only. cache mode setting used for connecting to the database. (private, shared) +;cache_mode = private + +#################################### Cache server ############################# +[remote_cache] +# Either "redis", "memcached" or "database" default is "database" +;type = database + +# cache connectionstring options +# database: will use Grafana primary database. +# redis: config like redis server e.g. `addr=127.0.0.1:6379,pool_size=100,db=0,ssl=false`. Only addr is required. ssl may be 'true', 'false', or 'insecure'. +# memcache: 127.0.0.1:11211 +;connstr = + +#################################### Data proxy ########################### +[dataproxy] + +# This enables data proxy logging, default is false +;logging = false + +# How long the data proxy should wait before timing out default is 30 (seconds) +;timeout = 30 + +# If enabled and user is not anonymous, data proxy will add X-Grafana-User header with username into the request, default is false. +;send_user_header = false + +#################################### Analytics #################################### +[analytics] +# Server reporting, sends usage counters to stats.grafana.org every 24 hours. +# No ip addresses are being tracked, only simple counters to track +# running instances, dashboard and error counts. It is very helpful to us. +# Change this option to false to disable reporting. +;reporting_enabled = true + +# Set to false to disable all checks to https://grafana.net +# for new vesions (grafana itself and plugins), check is used +# in some UI views to notify that grafana or plugin update exists +# This option does not cause any auto updates, nor send any information +# only a GET request to http://grafana.com to get latest versions +;check_for_updates = true + +# Google Analytics universal tracking code, only enabled if you specify an id here +;google_analytics_ua_id = + +# Google Tag Manager ID, only enabled if you specify an id here +;google_tag_manager_id = + +#################################### Security #################################### +[security] +# default admin user, created on startup +;admin_user = admin + +# default admin password, can be changed before first start of grafana, or in profile settings +admin_password = {{ grafana.adminpw }} + +# used for signing +secret_key = {{ grafana.config.secret_key }} + +# disable gravatar profile images +disable_gravatar = true + +# data source proxy whitelist (ip_or_domain:port separated by spaces) +;data_source_proxy_whitelist = + +# disable protection against brute force login attempts +;disable_brute_force_login_protection = false + +# set to true if you host Grafana behind HTTPS. default is false. +;cookie_secure = false + +# set cookie SameSite attribute. defaults to `lax`. can be set to "lax", "strict" and "none" +;cookie_samesite = lax + +# set to true if you want to allow browsers to render Grafana in a ,