Amazon Managed Grafana setup (#133)

* Managed Grafana Workspace with Identity Centre Users (#83)

* update kuberenetes and instance type

* initial setup of managed grafana workspace and identity centre identities

* cleanup

* run precommit

* output grafana workspace ID

* add identity store id variable

* remove API key

* update outputs naming convention as per terraform guidelines

* update docs and add versions

* update variables type

* update naming conventions

* add managed policy arn for querying promethues

* update readme

* update workshop references to this

* add role arn type

* cleanup and simplification

* remove workshop

---------

Co-authored-by: charlie keegan <chakeega@amazon.com>
Co-authored-by: Rodrigue Koffi <bonclay7@users.noreply.github.com>

* Rename example

* Update grafana example and base module references

* Update example's reference

* Cleanup and docs ref

* Add docs

* Update docs

* TODO: add link after merge

* Update managed-grafana.md

---------

Co-authored-by: Charlie Keegan <91210223+charliekeeegan@users.noreply.github.com>
Co-authored-by: charlie keegan <chakeega@amazon.com>
Co-authored-by: Mark Beacom <7315957+mbeacom@users.noreply.github.com>
This commit is contained in:
Rodrigue Koffi
2023-03-20 18:44:49 +01:00
committed by GitHub
parent 0abea3c8a8
commit 71b6f352bf
21 changed files with 209 additions and 52 deletions
+57
View File
@@ -0,0 +1,57 @@
# Creating a new Amazon Managed Grafana Workspace
This example creates an Amazon Managed Grafana Workspace with
Amazon CloudWatch, AWS X-Ray and Amazon Managed Service for Prometheus
datasources.
The authentication method chosen for this example is with IAM Identity
Center (former SSO). You can extend this example to add SAML.
## Prerequisites
!!! note
Make sure to complete the [prerequisites section](https://aws-observability.github.io/terraform-aws-observability-accelerator/concepts/#prerequisites) before proceeding.
## Setup
### 1. Download sources and initialize Terraform
```
git clone https://github.com/aws-observability/terraform-aws-observability-accelerator.git
cd examples/managed-grafana-workspace
terraform init
```
### 2. AWS Region
Specify the AWS Region where the resources will be deployed:
```bash
export TF_VAR_aws_region=xxx
```
## Deploy
Simply run this command to deploy the example
```bash
terraform apply
```
## Authentication
After apply, Terraform will output the Worksapce's URL, but you need to:
- [Setup user(s)](https://docs.aws.amazon.com/singlesignon/latest/userguide/getting-started.html) in the IAM Identity Center (former SSO)
- [Assign the user(s) to the workspace](https://docs.aws.amazon.com/grafana/latest/userguide/AMG-manage-users-and-groups-AMG.html) with proper permissions
<img width="1936" alt="Screenshot 2023-03-19 at 12 04 45" src="https://user-images.githubusercontent.com/10175027/226172947-f8588ed3-3751-47c1-a3ed-fb4c2d4d847e.png">
## Cleanup
To clean up your environment, destroy the Terraform example by running
```sh
terraform destroy
```