Amazon Managed Grafana setup (#133)

* Managed Grafana Workspace with Identity Centre Users (#83)

* update kuberenetes and instance type

* initial setup of managed grafana workspace and identity centre identities

* cleanup

* run precommit

* output grafana workspace ID

* add identity store id variable

* remove API key

* update outputs naming convention as per terraform guidelines

* update docs and add versions

* update variables type

* update naming conventions

* add managed policy arn for querying promethues

* update readme

* update workshop references to this

* add role arn type

* cleanup and simplification

* remove workshop

---------

Co-authored-by: charlie keegan <chakeega@amazon.com>
Co-authored-by: Rodrigue Koffi <bonclay7@users.noreply.github.com>

* Rename example

* Update grafana example and base module references

* Update example's reference

* Cleanup and docs ref

* Add docs

* Update docs

* TODO: add link after merge

* Update managed-grafana.md

---------

Co-authored-by: Charlie Keegan <91210223+charliekeeegan@users.noreply.github.com>
Co-authored-by: charlie keegan <chakeega@amazon.com>
Co-authored-by: Mark Beacom <7315957+mbeacom@users.noreply.github.com>
This commit is contained in:
Rodrigue Koffi
2023-03-20 18:44:49 +01:00
committed by GitHub
parent 0abea3c8a8
commit 71b6f352bf
21 changed files with 209 additions and 52 deletions
+5 -3
View File
@@ -50,9 +50,11 @@ Add your cluster name for `eks_cluster_id="..."` to the `terraform.tfvars` or us
4. Amazon Managed Grafana workspace
To run this example you need an Amazon Managed Grafana workspace. If you have an existing workspace, create an environment variable `export TF_VAR_managed_grafana_workspace_id=g-xxx`.
To create a new one, visit our Amazon Managed Grafana [documentation](https://docs.aws.amazon.com/grafana/latest/userguide/getting-started-with-AMG.html).
Make sure to provide the workspace with Amazon Managed Service for Prometheus read permissions.
To run this example you need an Amazon Managed Grafana workspace. If you have
an existing workspace, create an environment variable
`export TF_VAR_managed_grafana_workspace_id=g-xxx`.
To create a new one, visit [this example](../managed-grafana-workspace).
> In the URL `https://g-xyz.grafana-workspace.eu-central-1.amazonaws.com`, the workspace ID would be `g-xyz`
-1
View File
@@ -47,7 +47,6 @@ module "aws_observability_accelerator" {
managed_prometheus_workspace_id = var.managed_prometheus_workspace_id
# reusing existing Amazon Managed Grafana workspace
enable_managed_grafana = false
managed_grafana_workspace_id = var.managed_grafana_workspace_id
grafana_api_key = var.grafana_api_key
+5 -3
View File
@@ -49,9 +49,11 @@ Add your cluster name for `eks_cluster_id="..."` to the `terraform.tfvars` or us
4. Amazon Managed Grafana workspace
To run this example you need an Amazon Managed Grafana workspace. If you have an existing workspace, create an environment variable `export TF_VAR_managed_grafana_workspace_id=g-xxx`.
To create a new one, visit our Amazon Managed Grafana [documentation](https://docs.aws.amazon.com/grafana/latest/userguide/getting-started-with-AMG.html).
Make sure to provide the workspace with Amazon Managed Service for Prometheus read permissions.
To run this example you need an Amazon Managed Grafana workspace. If you have
an existing workspace, create an environment variable
`export TF_VAR_managed_grafana_workspace_id=g-xxx`.
To create a new one, visit [this example](../managed-grafana-workspace).
> In the URL `https://g-xyz.grafana-workspace.eu-central-1.amazonaws.com`, the workspace ID would be `g-xyz`
-1
View File
@@ -47,7 +47,6 @@ module "aws_observability_accelerator" {
managed_prometheus_workspace_id = var.managed_prometheus_workspace_id
# reusing existing Amazon Managed Grafana workspace
enable_managed_grafana = false
managed_grafana_workspace_id = var.managed_grafana_workspace_id
grafana_api_key = var.grafana_api_key
@@ -47,9 +47,11 @@ Add your cluster name for `eks_cluster_id="..."` to the `terraform.tfvars` or us
4. Amazon Managed Grafana workspace
To run this example you need an Amazon Managed Grafana workspace. If you have an existing workspace, create an environment variable `export TF_VAR_managed_grafana_workspace_id=g-xxx`.
To create a new one, visit our Amazon Managed Grafana [documentation](https://docs.aws.amazon.com/grafana/latest/userguide/getting-started-with-AMG.html).
Make sure to provide the workspace with Amazon Managed Service for Prometheus read permissions.
To run this example you need an Amazon Managed Grafana workspace. If you have
an existing workspace, create an environment variable
`export TF_VAR_managed_grafana_workspace_id=g-xxx`.
To create a new one, visit [this example](../managed-grafana-workspace).
> In the URL `https://g-xyz.grafana-workspace.eu-central-1.amazonaws.com`, the workspace ID would be `g-xyz`
@@ -50,7 +50,6 @@ module "aws_observability_accelerator" {
enable_alertmanager = true
# reusing existing Amazon Managed Grafana workspace
enable_managed_grafana = false
managed_grafana_workspace_id = var.managed_grafana_workspace_id
grafana_api_key = var.grafana_api_key
@@ -0,0 +1,47 @@
provider "aws" {
region = var.aws_region
}
locals {
name = "aws-observability-accelerator"
description = "Amazon Managed Grafana workspace for ${local.name}"
tags = {
GithubRepo = "terraform-aws-observability-accelerator"
GithubOrg = "aws-observability"
}
}
module "managed_grafana" {
source = "terraform-aws-modules/managed-service-grafana/aws"
version = "1.8.0"
name = local.name
associate_license = false
description = local.description
account_access_type = "CURRENT_ACCOUNT"
authentication_providers = ["AWS_SSO"]
permission_type = "SERVICE_MANAGED"
data_sources = ["CLOUDWATCH", "PROMETHEUS", "XRAY"]
notification_destinations = ["SNS"]
stack_set_name = local.name
configuration = jsonencode({
unifiedAlerting = {
enabled = true
}
})
# Workspace IAM role
create_iam_role = true
iam_role_name = local.name
use_iam_role_name_prefix = true
iam_role_description = local.description
iam_role_path = "/grafana/"
iam_role_force_detach_policies = true
iam_role_max_session_duration = 7200
iam_role_tags = local.tags
tags = local.tags
}
@@ -0,0 +1,14 @@
output "grafana_workspace_endpoint" {
description = "Amazon Managed Grafana Workspace endpoint"
value = "https://${module.managed_grafana.workspace_endpoint}"
}
output "grafana_workspace_id" {
description = "Amazon Managed Grafana Workspace ID"
value = module.managed_grafana.workspace_id
}
output "grafana_workspace_iam_role_arn" {
description = "Amazon Managed Grafana Workspace's IAM Role ARN"
value = module.managed_grafana.workspace_iam_role_arn
}
@@ -0,0 +1,48 @@
# Amazon Managed Grafana Workspace Setup
This example creates an Amazon Managed Grafana Workspace with
Amazon CloudWatch, AWS X-Ray and Amazon Managed Service for Prometheus
datasources
The authentication method chosen for this example is with IAM Identity
Center (former SSO). You can extend this example to add SAML.
Step-by-step instructions available on our [docs site](https://aws-observability.github.io/terraform-aws-observability-accelerator/)
under **Supporting Examples**
<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
## Requirements
| Name | Version |
|------|---------|
| <a name="requirement_terraform"></a> [terraform](#requirement\_terraform) | >= 1.1.0 |
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 4.0.0 |
## Providers
No providers.
## Modules
| Name | Source | Version |
|------|--------|---------|
| <a name="module_managed_grafana"></a> [managed\_grafana](#module\_managed\_grafana) | terraform-aws-modules/managed-service-grafana/aws | 1.8.0 |
## Resources
No resources.
## Inputs
| Name | Description | Type | Default | Required |
|------|-------------|------|---------|:--------:|
| <a name="input_aws_region"></a> [aws\_region](#input\_aws\_region) | AWS Region | `string` | n/a | yes |
## Outputs
| Name | Description |
|------|-------------|
| <a name="output_grafana_workspace_endpoint"></a> [grafana\_workspace\_endpoint](#output\_grafana\_workspace\_endpoint) | Amazon Managed Grafana Workspace endpoint |
| <a name="output_grafana_workspace_iam_role_arn"></a> [grafana\_workspace\_iam\_role\_arn](#output\_grafana\_workspace\_iam\_role\_arn) | Amazon Managed Grafana Workspace's IAM Role ARN |
| <a name="output_grafana_workspace_id"></a> [grafana\_workspace\_id](#output\_grafana\_workspace\_id) | Amazon Managed Grafana Workspace ID |
<!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
@@ -0,0 +1,4 @@
variable "aws_region" {
description = "AWS Region"
type = string
}
@@ -0,0 +1,10 @@
terraform {
required_version = ">= 1.1.0"
required_providers {
aws = {
source = "hashicorp/aws"
version = ">= 4.0.0"
}
}
}
@@ -8,13 +8,12 @@ provider "grafana" {
}
data "aws_grafana_workspace" "this" {
count = var.managed_grafana_workspace_id == "" ? 0 : 1
workspace_id = var.managed_grafana_workspace_id
}
locals {
region = var.aws_region
amg_ws_endpoint = "https://${data.aws_grafana_workspace.this[0].endpoint}"
amg_ws_endpoint = "https://${data.aws_grafana_workspace.this.endpoint}"
}
resource "grafana_folder" "this" {