mirror of
https://github.com/storytold/terraform-aws-observability-accelerator.git
synced 2026-10-09 00:09:43 +00:00
Amazon Managed Grafana setup (#133)
* Managed Grafana Workspace with Identity Centre Users (#83) * update kuberenetes and instance type * initial setup of managed grafana workspace and identity centre identities * cleanup * run precommit * output grafana workspace ID * add identity store id variable * remove API key * update outputs naming convention as per terraform guidelines * update docs and add versions * update variables type * update naming conventions * add managed policy arn for querying promethues * update readme * update workshop references to this * add role arn type * cleanup and simplification * remove workshop --------- Co-authored-by: charlie keegan <chakeega@amazon.com> Co-authored-by: Rodrigue Koffi <bonclay7@users.noreply.github.com> * Rename example * Update grafana example and base module references * Update example's reference * Cleanup and docs ref * Add docs * Update docs * TODO: add link after merge * Update managed-grafana.md --------- Co-authored-by: Charlie Keegan <91210223+charliekeeegan@users.noreply.github.com> Co-authored-by: charlie keegan <chakeega@amazon.com> Co-authored-by: Mark Beacom <7315957+mbeacom@users.noreply.github.com>
This commit is contained in:
@@ -50,9 +50,11 @@ Add your cluster name for `eks_cluster_id="..."` to the `terraform.tfvars` or us
|
||||
|
||||
4. Amazon Managed Grafana workspace
|
||||
|
||||
To run this example you need an Amazon Managed Grafana workspace. If you have an existing workspace, create an environment variable `export TF_VAR_managed_grafana_workspace_id=g-xxx`.
|
||||
To create a new one, visit our Amazon Managed Grafana [documentation](https://docs.aws.amazon.com/grafana/latest/userguide/getting-started-with-AMG.html).
|
||||
Make sure to provide the workspace with Amazon Managed Service for Prometheus read permissions.
|
||||
To run this example you need an Amazon Managed Grafana workspace. If you have
|
||||
an existing workspace, create an environment variable
|
||||
`export TF_VAR_managed_grafana_workspace_id=g-xxx`.
|
||||
|
||||
To create a new one, visit [this example](../managed-grafana-workspace).
|
||||
|
||||
> In the URL `https://g-xyz.grafana-workspace.eu-central-1.amazonaws.com`, the workspace ID would be `g-xyz`
|
||||
|
||||
|
||||
@@ -47,7 +47,6 @@ module "aws_observability_accelerator" {
|
||||
managed_prometheus_workspace_id = var.managed_prometheus_workspace_id
|
||||
|
||||
# reusing existing Amazon Managed Grafana workspace
|
||||
enable_managed_grafana = false
|
||||
managed_grafana_workspace_id = var.managed_grafana_workspace_id
|
||||
grafana_api_key = var.grafana_api_key
|
||||
|
||||
|
||||
@@ -49,9 +49,11 @@ Add your cluster name for `eks_cluster_id="..."` to the `terraform.tfvars` or us
|
||||
|
||||
4. Amazon Managed Grafana workspace
|
||||
|
||||
To run this example you need an Amazon Managed Grafana workspace. If you have an existing workspace, create an environment variable `export TF_VAR_managed_grafana_workspace_id=g-xxx`.
|
||||
To create a new one, visit our Amazon Managed Grafana [documentation](https://docs.aws.amazon.com/grafana/latest/userguide/getting-started-with-AMG.html).
|
||||
Make sure to provide the workspace with Amazon Managed Service for Prometheus read permissions.
|
||||
To run this example you need an Amazon Managed Grafana workspace. If you have
|
||||
an existing workspace, create an environment variable
|
||||
`export TF_VAR_managed_grafana_workspace_id=g-xxx`.
|
||||
|
||||
To create a new one, visit [this example](../managed-grafana-workspace).
|
||||
|
||||
> In the URL `https://g-xyz.grafana-workspace.eu-central-1.amazonaws.com`, the workspace ID would be `g-xyz`
|
||||
|
||||
|
||||
@@ -47,7 +47,6 @@ module "aws_observability_accelerator" {
|
||||
managed_prometheus_workspace_id = var.managed_prometheus_workspace_id
|
||||
|
||||
# reusing existing Amazon Managed Grafana workspace
|
||||
enable_managed_grafana = false
|
||||
managed_grafana_workspace_id = var.managed_grafana_workspace_id
|
||||
grafana_api_key = var.grafana_api_key
|
||||
|
||||
|
||||
@@ -47,9 +47,11 @@ Add your cluster name for `eks_cluster_id="..."` to the `terraform.tfvars` or us
|
||||
|
||||
4. Amazon Managed Grafana workspace
|
||||
|
||||
To run this example you need an Amazon Managed Grafana workspace. If you have an existing workspace, create an environment variable `export TF_VAR_managed_grafana_workspace_id=g-xxx`.
|
||||
To create a new one, visit our Amazon Managed Grafana [documentation](https://docs.aws.amazon.com/grafana/latest/userguide/getting-started-with-AMG.html).
|
||||
Make sure to provide the workspace with Amazon Managed Service for Prometheus read permissions.
|
||||
To run this example you need an Amazon Managed Grafana workspace. If you have
|
||||
an existing workspace, create an environment variable
|
||||
`export TF_VAR_managed_grafana_workspace_id=g-xxx`.
|
||||
|
||||
To create a new one, visit [this example](../managed-grafana-workspace).
|
||||
|
||||
> In the URL `https://g-xyz.grafana-workspace.eu-central-1.amazonaws.com`, the workspace ID would be `g-xyz`
|
||||
|
||||
|
||||
@@ -50,7 +50,6 @@ module "aws_observability_accelerator" {
|
||||
enable_alertmanager = true
|
||||
|
||||
# reusing existing Amazon Managed Grafana workspace
|
||||
enable_managed_grafana = false
|
||||
managed_grafana_workspace_id = var.managed_grafana_workspace_id
|
||||
grafana_api_key = var.grafana_api_key
|
||||
|
||||
|
||||
@@ -0,0 +1,47 @@
|
||||
provider "aws" {
|
||||
region = var.aws_region
|
||||
}
|
||||
|
||||
locals {
|
||||
name = "aws-observability-accelerator"
|
||||
description = "Amazon Managed Grafana workspace for ${local.name}"
|
||||
|
||||
tags = {
|
||||
GithubRepo = "terraform-aws-observability-accelerator"
|
||||
GithubOrg = "aws-observability"
|
||||
}
|
||||
}
|
||||
|
||||
module "managed_grafana" {
|
||||
source = "terraform-aws-modules/managed-service-grafana/aws"
|
||||
version = "1.8.0"
|
||||
|
||||
name = local.name
|
||||
associate_license = false
|
||||
description = local.description
|
||||
account_access_type = "CURRENT_ACCOUNT"
|
||||
authentication_providers = ["AWS_SSO"]
|
||||
permission_type = "SERVICE_MANAGED"
|
||||
data_sources = ["CLOUDWATCH", "PROMETHEUS", "XRAY"]
|
||||
notification_destinations = ["SNS"]
|
||||
stack_set_name = local.name
|
||||
|
||||
configuration = jsonencode({
|
||||
unifiedAlerting = {
|
||||
enabled = true
|
||||
}
|
||||
})
|
||||
|
||||
|
||||
# Workspace IAM role
|
||||
create_iam_role = true
|
||||
iam_role_name = local.name
|
||||
use_iam_role_name_prefix = true
|
||||
iam_role_description = local.description
|
||||
iam_role_path = "/grafana/"
|
||||
iam_role_force_detach_policies = true
|
||||
iam_role_max_session_duration = 7200
|
||||
iam_role_tags = local.tags
|
||||
|
||||
tags = local.tags
|
||||
}
|
||||
@@ -0,0 +1,14 @@
|
||||
output "grafana_workspace_endpoint" {
|
||||
description = "Amazon Managed Grafana Workspace endpoint"
|
||||
value = "https://${module.managed_grafana.workspace_endpoint}"
|
||||
}
|
||||
|
||||
output "grafana_workspace_id" {
|
||||
description = "Amazon Managed Grafana Workspace ID"
|
||||
value = module.managed_grafana.workspace_id
|
||||
}
|
||||
|
||||
output "grafana_workspace_iam_role_arn" {
|
||||
description = "Amazon Managed Grafana Workspace's IAM Role ARN"
|
||||
value = module.managed_grafana.workspace_iam_role_arn
|
||||
}
|
||||
@@ -0,0 +1,48 @@
|
||||
# Amazon Managed Grafana Workspace Setup
|
||||
|
||||
This example creates an Amazon Managed Grafana Workspace with
|
||||
Amazon CloudWatch, AWS X-Ray and Amazon Managed Service for Prometheus
|
||||
datasources
|
||||
|
||||
The authentication method chosen for this example is with IAM Identity
|
||||
Center (former SSO). You can extend this example to add SAML.
|
||||
|
||||
Step-by-step instructions available on our [docs site](https://aws-observability.github.io/terraform-aws-observability-accelerator/)
|
||||
under **Supporting Examples**
|
||||
|
||||
<!-- BEGINNING OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
|
||||
## Requirements
|
||||
|
||||
| Name | Version |
|
||||
|------|---------|
|
||||
| <a name="requirement_terraform"></a> [terraform](#requirement\_terraform) | >= 1.1.0 |
|
||||
| <a name="requirement_aws"></a> [aws](#requirement\_aws) | >= 4.0.0 |
|
||||
|
||||
## Providers
|
||||
|
||||
No providers.
|
||||
|
||||
## Modules
|
||||
|
||||
| Name | Source | Version |
|
||||
|------|--------|---------|
|
||||
| <a name="module_managed_grafana"></a> [managed\_grafana](#module\_managed\_grafana) | terraform-aws-modules/managed-service-grafana/aws | 1.8.0 |
|
||||
|
||||
## Resources
|
||||
|
||||
No resources.
|
||||
|
||||
## Inputs
|
||||
|
||||
| Name | Description | Type | Default | Required |
|
||||
|------|-------------|------|---------|:--------:|
|
||||
| <a name="input_aws_region"></a> [aws\_region](#input\_aws\_region) | AWS Region | `string` | n/a | yes |
|
||||
|
||||
## Outputs
|
||||
|
||||
| Name | Description |
|
||||
|------|-------------|
|
||||
| <a name="output_grafana_workspace_endpoint"></a> [grafana\_workspace\_endpoint](#output\_grafana\_workspace\_endpoint) | Amazon Managed Grafana Workspace endpoint |
|
||||
| <a name="output_grafana_workspace_iam_role_arn"></a> [grafana\_workspace\_iam\_role\_arn](#output\_grafana\_workspace\_iam\_role\_arn) | Amazon Managed Grafana Workspace's IAM Role ARN |
|
||||
| <a name="output_grafana_workspace_id"></a> [grafana\_workspace\_id](#output\_grafana\_workspace\_id) | Amazon Managed Grafana Workspace ID |
|
||||
<!-- END OF PRE-COMMIT-TERRAFORM DOCS HOOK -->
|
||||
@@ -0,0 +1,4 @@
|
||||
variable "aws_region" {
|
||||
description = "AWS Region"
|
||||
type = string
|
||||
}
|
||||
@@ -0,0 +1,10 @@
|
||||
terraform {
|
||||
required_version = ">= 1.1.0"
|
||||
|
||||
required_providers {
|
||||
aws = {
|
||||
source = "hashicorp/aws"
|
||||
version = ">= 4.0.0"
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -8,13 +8,12 @@ provider "grafana" {
|
||||
}
|
||||
|
||||
data "aws_grafana_workspace" "this" {
|
||||
count = var.managed_grafana_workspace_id == "" ? 0 : 1
|
||||
workspace_id = var.managed_grafana_workspace_id
|
||||
}
|
||||
|
||||
locals {
|
||||
region = var.aws_region
|
||||
amg_ws_endpoint = "https://${data.aws_grafana_workspace.this[0].endpoint}"
|
||||
amg_ws_endpoint = "https://${data.aws_grafana_workspace.this.endpoint}"
|
||||
}
|
||||
|
||||
resource "grafana_folder" "this" {
|
||||
|
||||
Reference in New Issue
Block a user