Skip to content

Ansible Role linuxfabrik.lfops.icingaweb2_module_grafana

This role installs and configures the IcingaWeb2 Grafana Module, and deploys the graph configuration for the Linuxfabrik Monitoring Plugins when called with the icingaweb2_module_grafana:monitoring_plugins_graphs tag.

This role is tested with the following IcingaWeb2 Grafana Module versions:

  • 3.1.3

Available since LFOps 2.0.0.

Requirements

Manual steps:

Tags

icingaweb2_module_grafana

  • Installs and configures the IcingaWeb2 Grafana Module.
  • Triggers: none.

icingaweb2_module_grafana:configure

  • Configures the IcingaWeb2 Grafana Module.
  • Triggers: none.

icingaweb2_module_grafana:monitoring_plugins_graphs

Mandatory Role Variables

icingaweb2_module_grafana__monitoring_plugins_version

  • Which version of the monitoring plugins should be deployed? Possible options:

    • A specific release, for example 1.2.0.11. See the Releases.
    • dev: The development version (main branch). Use with care. Only works with monitoring_plugins__install_method: 'source'.
  • Type: String.

  • Default: '{{ lfops__monitoring_plugins_version | default() }}'

icingaweb2_module_grafana__version

  • The module version to install. Possible options: https://github.com/NETWAYS/icingaweb2-module-grafana/releases.
  • Type: String.

Example:

# mandatory
icingaweb2_module_grafana__monitoring_plugins_version: '1.2.0.11'
icingaweb2_module_grafana__version: 'v3.1.3'

Optional Role Variables

icingaweb2_module_grafana__auth_jwt

  • Enable JWT-based authentication for Grafana requests.
  • Type: Bool.
  • Default: '{{ grafana__auth_jwt }}'

icingaweb2_module_grafana__auth_jwt__expires

  • How long, in seconds, the JWT embedded in a Grafana graph stays valid. Grafana keeps no session for it, so the graph shows the Grafana login once the token has expired, until the page in IcingaWeb2 is reloaded. Anyone who obtains the URL of a graph can use Grafana as grafana-admin for this long.
  • Type: Number.
  • Default: 259200 (3 days)

icingaweb2_module_grafana__auth_jwt__priv_key_file

  • Path to the private key file used for JWT-based Grafana authentication.
  • Type: String.
  • Default: '{{ grafana__auth_jwt__priv_key_file }}'

icingaweb2_module_grafana__custom_graphs_config

  • Multiline string. Custom configuration for the Grafana Graphs, will be deployed to /etc/icingweb2/modules/grafana/graphs.ini along with the configuration for the Linuxfabrik Monitoring Plugins.
  • Type: String.
  • Default: ''

icingaweb2_module_grafana__default_dashboard

  • Name of the default Grafana dashboard.
  • Type: String.
  • Default: 'Default'

icingaweb2_module_grafana__theme

  • The theme for the Grafana graphs. Possible options:

    • dark
    • light
  • Type: String.

  • Default: 'light'

icingaweb2_module_grafana__url

  • The Grafana URL. This should be reachable from both the IcingaWeb2 server and the client device.
  • Type: String.
  • Default: '{{ grafana__root_url }}'

Example:

# optional
icingaweb2_module_grafana__auth_jwt: false
icingaweb2_module_grafana__auth_jwt__expires: 259200
icingaweb2_module_grafana__auth_jwt__priv_key_file: '/etc/grafana/jwt.key.priv'
icingaweb2_module_grafana__custom_graphs_config: |-
  [icingacli-x509]
  dashboard = "Default"
  panelId = "1"
  orgId = ""
  repeatable = "no"
  dashboarduid = "default"
  timerange = "7d"
icingaweb2_module_grafana__default_dashboard: 'Default'
icingaweb2_module_grafana__theme: 'light'
icingaweb2_module_grafana__url: 'https://monitoring.example.com/grafana'

License

The Unlicense

Author Information

Linuxfabrik GmbH, Zurich