Files
terraform-aws-observability…/examples/managed-grafana-workspace/main.tf
T
Rodrigue Koffi 71b6f352bf Amazon Managed Grafana setup (#133)
* Managed Grafana Workspace with Identity Centre Users (#83)

* update kuberenetes and instance type

* initial setup of managed grafana workspace and identity centre identities

* cleanup

* run precommit

* output grafana workspace ID

* add identity store id variable

* remove API key

* update outputs naming convention as per terraform guidelines

* update docs and add versions

* update variables type

* update naming conventions

* add managed policy arn for querying promethues

* update readme

* update workshop references to this

* add role arn type

* cleanup and simplification

* remove workshop

---------

Co-authored-by: charlie keegan <chakeega@amazon.com>
Co-authored-by: Rodrigue Koffi <bonclay7@users.noreply.github.com>

* Rename example

* Update grafana example and base module references

* Update example's reference

* Cleanup and docs ref

* Add docs

* Update docs

* TODO: add link after merge

* Update managed-grafana.md

---------

Co-authored-by: Charlie Keegan <91210223+charliekeeegan@users.noreply.github.com>
Co-authored-by: charlie keegan <chakeega@amazon.com>
Co-authored-by: Mark Beacom <7315957+mbeacom@users.noreply.github.com>
2023-03-20 18:44:49 +01:00

48 lines
1.3 KiB
Terraform

provider "aws" {
region = var.aws_region
}
locals {
name = "aws-observability-accelerator"
description = "Amazon Managed Grafana workspace for ${local.name}"
tags = {
GithubRepo = "terraform-aws-observability-accelerator"
GithubOrg = "aws-observability"
}
}
module "managed_grafana" {
source = "terraform-aws-modules/managed-service-grafana/aws"
version = "1.8.0"
name = local.name
associate_license = false
description = local.description
account_access_type = "CURRENT_ACCOUNT"
authentication_providers = ["AWS_SSO"]
permission_type = "SERVICE_MANAGED"
data_sources = ["CLOUDWATCH", "PROMETHEUS", "XRAY"]
notification_destinations = ["SNS"]
stack_set_name = local.name
configuration = jsonencode({
unifiedAlerting = {
enabled = true
}
})
# Workspace IAM role
create_iam_role = true
iam_role_name = local.name
use_iam_role_name_prefix = true
iam_role_description = local.description
iam_role_path = "/grafana/"
iam_role_force_detach_policies = true
iam_role_max_session_duration = 7200
iam_role_tags = local.tags
tags = local.tags
}