From dd19e3a00b5811f9aac68257bf35d7997cb8ca61 Mon Sep 17 00:00:00 2001 From: greg Date: Mon, 21 Oct 2024 11:27:52 +0200 Subject: [PATCH] add loki + grafana dashboards provisionning and home.json --- README.md | 30 +- docker-compose.yml | 99 +- grafana/config/grafana.ini | 964 ++++++++++++++++++ .../provisioning/datasources/datasource.yml | 43 + 4 files changed, 1094 insertions(+), 42 deletions(-) create mode 100644 grafana/config/grafana.ini diff --git a/README.md b/README.md index 1107477..771addb 100644 --- a/README.md +++ b/README.md @@ -58,6 +58,12 @@ domain = grafana.votre-domaine.tld ... +# pour rediriger auto vers SSO provider +[auth] +oauth_auto_login = true + +... + [auth.generic_oauth] enabled = true scopes = openid email profile @@ -71,9 +77,31 @@ token_url = https://votre-keycloak/auth/realms/votre-royaume/protocol/openid-con api_url = https://votre-keycloak/auth/realms/votre-royaume/protocol/openid-connect/userinfo # Pour ne laisser que l'authentification keycloak -#disable_login_form = true +disable_login_form = true ``` +### GRAFANA DASHBOARDS + +- Configurer une home page avec des liens vers les dashboards: +```ini +default_home_dashboard_path = /etc/grafana/provisioning/dashboards/home.json +``` + +- Configuration du html dans le home.json: +```html + +
\n\n \"Le\n\n + +\n\n
" +``` + +> Pour chaque dashboard créées, récupérer le lien dans l'url pour l'ajouter à la liste. + ## UTILISATION :rocket: - Démarrer la stack: diff --git a/docker-compose.yml b/docker-compose.yml index abfd3b1..52a675b 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,9 +1,9 @@ -version: '2.1' - - networks: - monitor-net: + grafana-network: driver: bridge + ipam: + config: + - subnet: 192.168.100.0/24 volumes: prometheus_data: {} @@ -11,6 +11,26 @@ volumes: services: +# POUR AFFICHAGE DASHBOARD + grafana: + image: grafana/grafana:11.2.0 + container_name: grafana + volumes: + - grafana_data:/var/lib/grafana + - ./grafana/provisioning:/etc/grafana/provisioning + environment: + - GF_SECURITY_ADMIN_USER=${ADMIN_USER} + - GF_SECURITY_ADMIN_PASSWORD=${ADMIN_PASSWORD} + - GF_USERS_ALLOW_SIGN_UP=false + restart: unless-stopped + ports: + - 3000:3000 + networks: + grafana-network: + ipv4_address: 192.168.100.10 + labels: + org.label-schema.group: "monitoring" + # METRICS GATHERER prometheus: image: prom/prometheus:v2.54.1 @@ -29,31 +49,13 @@ services: expose: - 9090 networks: - - monitor-net - labels: - org.label-schema.group: "monitoring" - -# FOR ALERTS - alertmanager: - image: prom/alertmanager:v0.20.0 - container_name: alertmanager - volumes: - - ./alertmanager:/etc/alertmanager - command: - #- '--config.file=/etc/alertmanager/config.yml' - - '--config.file=/etc/alertmanager/alertmanager.yml' - - '--storage.path=/alertmanager' - restart: unless-stopped - expose: - - 9093 - networks: - - monitor-net + - grafana-network labels: org.label-schema.group: "monitoring" # FOR HOST METRICS nodeexporter: - image: prom/node-exporter:v0.18.1 + image: prom/node-exporter:v1.8.2 container_name: nodeexporter volumes: - /proc:/host/proc:ro @@ -68,7 +70,7 @@ services: expose: - 9100 networks: - - monitor-net + - grafana-network labels: org.label-schema.group: "monitoring" @@ -86,26 +88,41 @@ services: expose: - 8080 networks: - - monitor-net + - grafana-network labels: org.label-schema.group: "monitoring" -# POUR AFFICHAGE DASHBOARD - grafana: - image: grafana/grafana:11.2.0 - container_name: grafana - volumes: - - grafana_data:/var/lib/grafana - - ./grafana/provisioning:/etc/grafana/provisioning - environment: - - GF_SECURITY_ADMIN_USER=${ADMIN_USER} - - GF_SECURITY_ADMIN_PASSWORD=${ADMIN_PASSWORD} - - GF_USERS_ALLOW_SIGN_UP=false - restart: unless-stopped +# LOKI FOR LOGS + loki: + image: grafana/loki:latest + container_name: loki ports: - - 3000:3000 + - '3100:3100' + volumes: + - ./loki/config:/etc/loki + - ./loki/cert:/etc/loki/cert + - /etc/localtime:/etc/localtime:ro + - /etc/timezone:/etc/timezone:ro +# environment: + command: -config.file=/etc/loki/config.yml -config.expand-env=true networks: - - monitor-net + - grafana-network + +# FOR ALERTS + alertmanager: + image: prom/alertmanager:v0.20.0 + container_name: alertmanager + volumes: + - ./alertmanager:/etc/alertmanager + command: + #- '--config.file=/etc/alertmanager/config.yml' + - '--config.file=/etc/alertmanager/alertmanager.yml' + - '--storage.path=/alertmanager' + restart: unless-stopped + expose: + - 9093 + networks: + - grafana-network labels: org.label-schema.group: "monitoring" @@ -116,6 +133,6 @@ services: expose: - 9091 networks: - - monitor-net + - grafana-network labels: org.label-schema.group: "monitoring" diff --git a/grafana/config/grafana.ini b/grafana/config/grafana.ini new file mode 100644 index 0000000..cee3afb --- /dev/null +++ b/grafana/config/grafana.ini @@ -0,0 +1,964 @@ +##################### Grafana Configuration Example ##################### +# +# Everything has defaults so you only need to uncomment things you want to +# change + +# possible values : production, development +;app_mode = production + +# instance name, defaults to HOSTNAME environment variable value or hostname if HOSTNAME var is empty +;instance_name = ${HOSTNAME} + +#################################### Paths #################################### +[paths] +# Path to where grafana can store temp files, sessions, and the sqlite3 db (if that is used) +;data = /var/lib/grafana + +# Temporary files in `data` directory older than given duration will be removed +;temp_data_lifetime = 24h + +# Directory where grafana can store logs +;logs = /var/log/grafana + +# Directory where grafana will automatically scan and look for plugins +;plugins = /var/lib/grafana/plugins + +# folder that contains provisioning config files that grafana will apply on startup and while running. +;provisioning = conf/provisioning + +#################################### Server #################################### +[server] +# Protocol (http, https, h2, socket) +;protocol = https + +# The ip address to bind to, empty will bind to all interfaces +;http_addr = + +# The http port to use +http_port = 3000 + +# The public facing domain name used to access grafana from a browser +domain = votredomaine.com + +# Redirect to correct domain if host header does not match domain +# Prevents DNS rebinding attacks +;enforce_domain = false + +# The full public facing url you use in browser, used for redirects and emails +# If you use reverse proxy and sub path specify full url (with sub path) +root_url = https://votredomaine.com + +# Serve Grafana from subpath specified in `root_url` setting. By default it is set to `false` for compatibility reasons. +;serve_from_sub_path = false + +# Log web requests +;router_logging = false + +# the path relative working path +;static_root_path = public + +# enable gzip +;enable_gzip = false + +# https certs & key file +;cert_file = +;cert_key = + +# Unix socket path +;socket = + +# CDN Url +;cdn_url = + +# Sets the maximum time using a duration format (5s/5m/5ms) before timing out read of an incoming request and closing idle connections. +# `0` means there is no timeout for reading the request. +;read_timeout = 0 + +#################################### Database #################################### +[database] +# You can configure the database connection by specifying type, host, name, user and password +# as separate properties or as on string using the url properties. + +# Either "mysql", "postgres" or "sqlite3", it's your choice +;type = sqlite3 +;host = 127.0.0.1:3306 +;name = grafana +;user = root +# If the password contains # or ; you have to wrap it with triple quotes. Ex """#password;""" +;password = + +# Use either URL or the previous fields to configure the database +# Example: mysql://user:secret@host:port/database +;url = + +# For "postgres" only, either "disable", "require" or "verify-full" +;ssl_mode = disable + +# Database drivers may support different transaction isolation levels. +# Currently, only "mysql" driver supports isolation levels. +# If the value is empty - driver's default isolation level is applied. +# For "mysql" use "READ-UNCOMMITTED", "READ-COMMITTED", "REPEATABLE-READ" or "SERIALIZABLE". +;isolation_level = + +;ca_cert_path = +;client_key_path = +;client_cert_path = +;server_cert_name = + +# For "sqlite3" only, path relative to data_path setting +;path = grafana.db + +# Max idle conn setting default is 2 +;max_idle_conn = 2 + +# Max conn setting default is 0 (mean not set) +;max_open_conn = + +# Connection Max Lifetime default is 14400 (means 14400 seconds or 4 hours) +;conn_max_lifetime = 14400 + +# Set to true to log the sql calls and execution times. +;log_queries = + +# For "sqlite3" only. cache mode setting used for connecting to the database. (private, shared) +;cache_mode = private + +################################### Data sources ######################### +[datasources] +# Upper limit of data sources that Grafana will return. This limit is a temporary configuration and it will be deprecated when pagination will be introduced on the list data sources API. +;datasource_limit = 5000 + +#################################### Cache server ############################# +[remote_cache] +# Either "redis", "memcached" or "database" default is "database" +;type = database + +# cache connectionstring options +# database: will use Grafana primary database. +# redis: config like redis server e.g. `addr=127.0.0.1:6379,pool_size=100,db=0,ssl=false`. Only addr is required. ssl may be 'true', 'false', or 'insecure'. +# memcache: 127.0.0.1:11211 +;connstr = + +#################################### Data proxy ########################### +[dataproxy] + +# This enables data proxy logging, default is false +;logging = false + +# How long the data proxy waits to read the headers of the response before timing out, default is 30 seconds. +# This setting also applies to core backend HTTP data sources where query requests use an HTTP client with timeout set. +;timeout = 30 + +# How long the data proxy waits to establish a TCP connection before timing out, default is 10 seconds. +;dialTimeout = 10 + +# How many seconds the data proxy waits before sending a keepalive probe request. +;keep_alive_seconds = 30 + +# How many seconds the data proxy waits for a successful TLS Handshake before timing out. +;tls_handshake_timeout_seconds = 10 + +# How many seconds the data proxy will wait for a server's first response headers after +# fully writing the request headers if the request has an "Expect: 100-continue" +# header. A value of 0 will result in the body being sent immediately, without +# waiting for the server to approve. +;expect_continue_timeout_seconds = 1 + +# Optionally limits the total number of connections per host, including connections in the dialing, +# active, and idle states. On limit violation, dials will block. +# A value of zero (0) means no limit. +;max_conns_per_host = 0 + +# The maximum number of idle connections that Grafana will keep alive. +;max_idle_connections = 100 + +# The maximum number of idle connections per host that Grafana will keep alive. +;max_idle_connections_per_host = 2 + +# How many seconds the data proxy keeps an idle connection open before timing out. +;idle_conn_timeout_seconds = 90 + +# If enabled and user is not anonymous, data proxy will add X-Grafana-User header with username into the request, default is false. +;send_user_header = false + +#################################### Analytics #################################### +[analytics] +# Server reporting, sends usage counters to stats.grafana.org every 24 hours. +# No ip addresses are being tracked, only simple counters to track +# running instances, dashboard and error counts. It is very helpful to us. +# Change this option to false to disable reporting. +;reporting_enabled = true + +# The name of the distributor of the Grafana instance. Ex hosted-grafana, grafana-labs +;reporting_distributor = grafana-labs + +# Set to false to disable all checks to https://grafana.net +# for new versions (grafana itself and plugins), check is used +# in some UI views to notify that grafana or plugin update exists +# This option does not cause any auto updates, nor send any information +# only a GET request to http://grafana.com to get latest versions +;check_for_updates = true + +# Google Analytics universal tracking code, only enabled if you specify an id here +;google_analytics_ua_id = + +# Google Tag Manager ID, only enabled if you specify an id here +;google_tag_manager_id = + +#################################### Security #################################### +[security] +# disable creation of admin user on first start of grafana +;disable_initial_admin_creation = false + +# default admin user, created on startup +;admin_user = admin + +# default admin password, can be changed before first start of grafana, or in profile settings +;admin_password = admin + +# used for signing +;secret_key = SW2YcwTIb9zpOOhoPsMm + +# disable gravatar profile images +;disable_gravatar = false + +# data source proxy whitelist (ip_or_domain:port separated by spaces) +;data_source_proxy_whitelist = + +# disable protection against brute force login attempts +;disable_brute_force_login_protection = false + +# set to true if you host Grafana behind HTTPS. default is false. +;cookie_secure = false + +# set cookie SameSite attribute. defaults to `lax`. can be set to "lax", "strict", "none" and "disabled" +;cookie_samesite = lax + +# set to true if you want to allow browsers to render Grafana in a ,