Ansible Role linuxfabrik.lfops.icingaweb2_module_grafana¶
This role installs and configures the IcingaWeb2 Grafana Module, and deploys the graph configuration for the Linuxfabrik Monitoring Plugins when called with the icingaweb2_module_grafana:monitoring_plugins_graphs tag.
This role is tested with the following IcingaWeb2 Grafana Module versions:
- 3.1.3
Available since LFOps 2.0.0.
Requirements¶
Manual steps:
- Deploy a configured IcingaWeb2 by running the icingaweb2 playbook (role: linuxfabrik.lfops.icingaweb2).
- Deploy a configured Grafana by running the grafana playbook (role: linuxfabrik.lfops.grafana).
Tags¶
icingaweb2_module_grafana
- Installs and configures the IcingaWeb2 Grafana Module.
- Triggers: none.
icingaweb2_module_grafana:configure
- Configures the IcingaWeb2 Grafana Module.
- Triggers: none.
icingaweb2_module_grafana:monitoring_plugins_graphs
- Only runs if explicitly called. Deploys the graph configuration for the Linuxfabrik Monitoring Plugins.
- Triggers: none.
Mandatory Role Variables¶
icingaweb2_module_grafana__monitoring_plugins_version
-
Which version of the monitoring plugins should be deployed? Possible options:
- A specific release, for example
1.2.0.11. See the Releases. dev: The development version (main branch). Use with care. Only works withmonitoring_plugins__install_method: 'source'.
- A specific release, for example
-
Type: String.
- Default:
'{{ lfops__monitoring_plugins_version | default() }}'
icingaweb2_module_grafana__version
- The module version to install. Possible options: https://github.com/NETWAYS/icingaweb2-module-grafana/releases.
- Type: String.
Example:
# mandatory
icingaweb2_module_grafana__monitoring_plugins_version: '1.2.0.11'
icingaweb2_module_grafana__version: 'v3.1.3'
Optional Role Variables¶
icingaweb2_module_grafana__auth_jwt
- Enable JWT-based authentication for Grafana requests.
- Type: Bool.
- Default:
'{{ grafana__auth_jwt }}'
icingaweb2_module_grafana__auth_jwt__expires
- How long, in seconds, the JWT embedded in a Grafana graph stays valid. Grafana keeps no session for it, so the graph shows the Grafana login once the token has expired, until the page in IcingaWeb2 is reloaded. Anyone who obtains the URL of a graph can use Grafana as
grafana-adminfor this long. - Type: Number.
- Default:
259200(3 days)
icingaweb2_module_grafana__auth_jwt__priv_key_file
- Path to the private key file used for JWT-based Grafana authentication.
- Type: String.
- Default:
'{{ grafana__auth_jwt__priv_key_file }}'
icingaweb2_module_grafana__custom_graphs_config
- Multiline string. Custom configuration for the Grafana Graphs, will be deployed to
/etc/icingweb2/modules/grafana/graphs.inialong with the configuration for the Linuxfabrik Monitoring Plugins. - Type: String.
- Default:
''
icingaweb2_module_grafana__default_dashboard
- Name of the default Grafana dashboard.
- Type: String.
- Default:
'Default'
icingaweb2_module_grafana__theme
-
The theme for the Grafana graphs. Possible options:
darklight
-
Type: String.
- Default:
'light'
icingaweb2_module_grafana__url
- The Grafana URL. This should be reachable from both the IcingaWeb2 server and the client device.
- Type: String.
- Default:
'{{ grafana__root_url }}'
Example:
# optional
icingaweb2_module_grafana__auth_jwt: false
icingaweb2_module_grafana__auth_jwt__expires: 259200
icingaweb2_module_grafana__auth_jwt__priv_key_file: '/etc/grafana/jwt.key.priv'
icingaweb2_module_grafana__custom_graphs_config: |-
[icingacli-x509]
dashboard = "Default"
panelId = "1"
orgId = ""
repeatable = "no"
dashboarduid = "default"
timerange = "7d"
icingaweb2_module_grafana__default_dashboard: 'Default'
icingaweb2_module_grafana__theme: 'light'
icingaweb2_module_grafana__url: 'https://monitoring.example.com/grafana'