Fix all the old usage of admonition syntax (#107017)
This commit is contained in:
@@ -14,13 +14,13 @@ weight: 300
|
||||
|
||||
Custom branding enables you to replace the Grafana Labs brand and logo with your corporate brand and logo.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Available in [Grafana Enterprise](../../../introduction/grafana-enterprise/) and [Grafana Cloud](/docs/grafana-cloud). For Cloud Advanced and Enterprise customers, please provide custom elements and logos to our Support team. We will help you host your images and update your custom branding.
|
||||
|
||||
This feature is not available for Grafana Free and Pro tiers.
|
||||
For more information on feature availability across plans, refer to our [feature comparison page](/docs/grafana-cloud/cost-management-and-billing/understand-grafana-cloud-features/)
|
||||
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
The `grafana.ini` file includes Grafana Enterprise custom branding. As with all configuration options, you can use environment variables to set custom branding.
|
||||
|
||||
@@ -103,9 +103,9 @@ GF_WHITE_LABELING_FOOTER_LINKS_EXTRACUSTOM_TEXT=Custom Text
|
||||
GF_WHITE_LABELING_FOOTER_LINKS_EXTRACUSTOM_URL=http://your.custom.site
|
||||
```
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
The following two links are always present in the footer:
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
- Grafana edition
|
||||
- Grafana version with build number
|
||||
|
||||
@@ -35,9 +35,9 @@ side to be valid for a different number of users or a new duration,
|
||||
your Grafana instance will be updated with the new terms
|
||||
automatically. Defaults to `true`.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
The license only automatically updates once per day. To immediately update the terms for a license, use the Grafana UI to renew your license token.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
### license_validation_type
|
||||
|
||||
@@ -408,9 +408,9 @@ Setting 'enabled' to `true` allows users to configure query caching for data sou
|
||||
|
||||
This value is `true` by default.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
This setting enables the caching feature, but it does not turn on query caching for any data source. To turn on query caching for a data source, update the setting on the data source configuration page. For more information, refer to the [query caching docs](../../../administration/data-source-management/#enable-and-configure-query-caching).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
### ttl
|
||||
|
||||
@@ -422,9 +422,9 @@ The max duration that a query result is stored in the caching system before it i
|
||||
|
||||
The default is `0s` (disabled).
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Disabling this constraint is not recommended in production environments.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
### max_value_mb
|
||||
|
||||
@@ -444,9 +444,9 @@ This setting defines the duration to wait for the caching backend to return a ca
|
||||
|
||||
The default is `0s` (disabled).
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Disabling this timeout is not recommended in production environments.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
### write_timeout
|
||||
|
||||
@@ -454,9 +454,9 @@ This setting defines the number of seconds to wait for the caching backend to st
|
||||
|
||||
The default is `0s` (disabled).
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Disabling this timeout is not recommended in production environments.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
## [caching.encryption]
|
||||
|
||||
@@ -488,9 +488,9 @@ To disable the maximum, set this value to `0`.
|
||||
|
||||
The default is `25`.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Disabling the maximum is not recommended in production environments.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
## [caching.redis]
|
||||
|
||||
@@ -505,13 +505,13 @@ The default is `"redis://localhost:6379"`.
|
||||
A comma-separated list of Redis cluster members, either in `host:port` format or using the full Redis URLs (`redis://username:password@localhost:6379`). For example, `localhost:7000, localhost: 7001, localhost:7002`.
|
||||
If you use the full Redis URLs, then you can specify the scheme, username, and password only once. For example, `redis://username:password@localhost:0000,localhost:1111,localhost:2222`. You cannot specify a different username and password for each URL.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
If you have specify `cluster`, the value for `url` is ignored.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
You can enable TLS for cluster mode using the `rediss` scheme in Grafana Enterprise v8.5 and later versions.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
### prefix
|
||||
|
||||
@@ -527,9 +527,9 @@ A space-separated list of memcached servers. Example: `memcached-server-1:11211
|
||||
|
||||
The default is `"localhost:11211"`.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
The following memcached configuration requires the `tlsMemcached` feature toggle.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
### tls_enabled
|
||||
|
||||
|
||||
@@ -16,9 +16,9 @@ weight: 500
|
||||
|
||||
# Settings updates at runtime
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
This functionality is deprecated and will be removed in a future release. For configuring SAML authentication, please use the new [SSO settings API](../../../developers/http_api/sso-settings/).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
By updating settings at runtime, you can update Grafana settings without needing to restart the Grafana server.
|
||||
|
||||
|
||||
@@ -19,15 +19,15 @@ weight: 800
|
||||
|
||||
Auditing allows you to track important changes to your Grafana instance. By default, audit logs are logged to file but the auditing feature also supports sending logs directly to Loki.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
To enable sending Grafana Cloud audit logs to your Grafana Cloud Logs instance, please [file a support ticket](/profile/org/tickets/new). Note that standard ingest and retention rates apply for ingesting these audit logs.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
Only API requests or UI actions that trigger an API request generate an audit log.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Available in [Grafana Enterprise](../../../introduction/grafana-enterprise/) and [Grafana Cloud](/docs/grafana-cloud).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
## Audit logs
|
||||
|
||||
@@ -354,9 +354,9 @@ Furthermore, you can also record `GET` requests. See below how to configure it.
|
||||
|
||||
## Configuration
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
The auditing feature is disabled by default.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
Audit logs can be saved into files, sent to a Loki instance or sent to the Grafana default logger. By default, only the file exporter is enabled.
|
||||
You can choose which exporter to use in the [configuration file](../../configure-grafana/).
|
||||
@@ -403,9 +403,9 @@ max_file_size_mb = 256
|
||||
|
||||
Audit logs are sent to a [Loki](/oss/loki/) service, through HTTP or gRPC.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
The HTTP option for the Loki exporter is available only in Grafana Enterprise version 7.4 and later.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
```ini
|
||||
[auditing.logs.loki]
|
||||
|
||||
+2
-2
@@ -240,9 +240,9 @@ use_refresh_token = true
|
||||
|
||||
## Configure team synchronization
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Available in [Grafana Enterprise](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/introduction/grafana-enterprise/) and [Grafana Cloud](/docs/grafana-cloud/).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
By using Team Sync, you can map GitLab groups to teams within Grafana. This will automatically assign users to the appropriate teams.
|
||||
Teams for each user are synchronized when the user logs in.
|
||||
|
||||
+2
-2
@@ -152,9 +152,9 @@ By default, Grafana includes the `access_type=offline` parameter in the authoriz
|
||||
|
||||
Refresh token fetching and access token expiration check is enabled by default for the Google provider since Grafana v10.1.0. If you would like to disable access token expiration check then set the `use_refresh_token` configuration value to `false`.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
The `accessTokenExpirationCheck` feature toggle has been removed in Grafana v10.3.0 and the `use_refresh_token` configuration value will be used instead for configuring refresh token fetching and access token expiration check.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
#### Configure automatic login
|
||||
|
||||
|
||||
@@ -23,9 +23,9 @@ This method of authentication is useful for integrating with other systems that
|
||||
use JWKS but can't directly integrate with Grafana or if you want to use pass-through
|
||||
authentication in an app embedding Grafana.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Grafana does not currently support refresh tokens.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
## Enable JWT
|
||||
|
||||
|
||||
+2
-2
@@ -82,9 +82,9 @@ To authenticate with Azure AD, the Keycloak application needs a client ID and cl
|
||||
1. Paste the client secret you created in the previous step in the **Client secret** field.
|
||||
1. Click Add.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Up to this point, you have created an App Registration in Azure AD, assigned users to the application, created credentials for the application, and configured the application in Keycloak. In the Keycloak Client's section, the client with ID `account` Home URL can be used to test the configuration. This will open a new tab where you can login into the correct Keycloak realm with the Azure AD tenant you just configured.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
Repeat this steps, for every Azure AD tenant you want to configure in Keycloak.
|
||||
|
||||
|
||||
+4
-4
@@ -93,9 +93,9 @@ profile
|
||||
roles
|
||||
```
|
||||
|
||||
{{% admonition type="warning" %}}
|
||||
{{< admonition type="warning" >}}
|
||||
These scopes do not add group claims to the `id_token`. Without group claims, teamsync will not work. Teamsync is covered further down in this document.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
3. For role mapping to work with the example configuration above,
|
||||
you need to create the following roles and assign them to users:
|
||||
@@ -153,9 +153,9 @@ signout_redirect_url = https://<PROVIDER_DOMAIN>/realms/<REALM_NAME>/protocol/op
|
||||
As an example, `<PROVIDER_DOMAIN>` can be `keycloak-demo.grafana.org`,
|
||||
`<REALM_NAME>` can be `grafana` and `<GRAFANA_DOMAIN>` can be `play.grafana.org`.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Grafana supports ID token hints for single logout. Grafana automatically adds the `id_token_hint` parameter to the logout request if it detects OAuth as the authentication method.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
## Allow assigning Grafana Admin
|
||||
|
||||
|
||||
+2
-2
@@ -245,9 +245,9 @@ org_mapping = ["Group 1:org_foo:Viewer", "Group 2:org_bar:Editor", "*:3:Editor"]
|
||||
|
||||
### Configure team synchronization (Enterprise only)
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Available in [Grafana Enterprise](https://grafana.com/docs/grafana/<GRAFANA_VERSION>/introduction/grafana-enterprise/) and [Grafana Cloud](../../../../introduction/grafana-cloud).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
By using Team Sync, you can link your Okta groups to teams within Grafana. This will automatically assign users to the appropriate teams.
|
||||
|
||||
|
||||
+8
-8
@@ -307,9 +307,9 @@ Grafana supports user authentication through Okta, which is useful when you want
|
||||
- In the **Single sign on URL** field, use the `/saml/acs` endpoint URL of your Grafana instance, for example, `https://grafana.example.com/saml/acs`.
|
||||
- In the **Audience URI (SP Entity ID)** field, use the `/saml/metadata` endpoint URL, by default it is the `/saml/metadata` endpoint of your Grafana instance (for example `https://example.grafana.com/saml/metadata`). This could be configured differently, but the value here must match the `entity_id` setting of the SAML settings of Grafana.
|
||||
- Leave the default values for **Name ID format** and **Application username**.
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
If you plan to enable SAML Single Logout, consider setting the **Name ID format** to `EmailAddress` or `Persistent`. This must match the `name_id_format` setting of the Grafana instance.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
- In the **ATTRIBUTE STATEMENTS (OPTIONAL)** section, enter the SAML attributes to be shared with Grafana. The attribute names in Okta need to match exactly what is defined within Grafana, for example:
|
||||
|
||||
| Attribute name (in Grafana) | Name and value (in Okta profile) | Grafana configuration (under `auth.saml`) |
|
||||
@@ -404,9 +404,9 @@ Additionally, Grafana did not support IdP sessions and could not include the `Se
|
||||
|
||||
Starting from Grafana version 11.5, Grafana uses the `NameID` from the SAML assertion to create the logout request. If the `NameID` is not present in the assertion, Grafana defaults to using the user's `Login` attribute. Additionally, Grafana supports including the `SessionIndex` in the logout request if it is provided in the SAML assertion by the IdP.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
These improvements are available in public preview behind the `improvedExternalSessionHandlingSAML` feature toggle, starting from Grafana v11.5. To enable it, refer to the [Configure feature toggles](/docs/grafana/<GRAFANA_VERSION>/setup-grafana/configure-grafana/feature-toggles/)
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
### Assertion mapping
|
||||
|
||||
@@ -480,7 +480,7 @@ auto_login = true
|
||||
|
||||
To use SAML Team sync, set [`assertion_attribute_groups`](../../../configure-grafana/enterprise-configuration#assertion_attribute_groups) to the attribute name where you store user groups. Then Grafana will use attribute values extracted from SAML assertion to add user into the groups with the same name configured on the External group sync tab.
|
||||
|
||||
{{% admonition type="warning" %}}
|
||||
{{< admonition type="warning" >}}
|
||||
Grafana requires the SAML groups attribute to be configured with distinct `AttributeValue` elements for each group. Do not include multiple groups within a single `AttributeValue` delimited by a comma or any other character. Failure to do so will prevent correct group parsing. Example:
|
||||
|
||||
```xml
|
||||
@@ -490,11 +490,11 @@ Grafana requires the SAML groups attribute to be configured with distinct `Attri
|
||||
</saml2:Attribute>
|
||||
```
|
||||
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Teamsync allows you sync users from SAML to Grafana teams. It does not automatically create teams in Grafana. You need to create teams in Grafana before you can use this feature.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
Given the following partial SAML assertion:
|
||||
|
||||
|
||||
+8
-8
@@ -18,21 +18,21 @@ Grafana’s database contains secrets, which are used to query data sources, sen
|
||||
|
||||
Grafana encrypts these secrets before they are written to the database, by using a symmetric-key encryption algorithm called Advanced Encryption Standard (AES). These secrets are signed using a [secret key](../../configure-grafana/#secret_key) that you can change when you configure a new Grafana instance.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Grafana v9.0 and newer use [envelope encryption](#envelope-encryption) by default, which adds a layer of indirection to the encryption process that introduces an [**implicit breaking change**](#implicit-breaking-change) for older versions of Grafana.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
For further details about how to operate a Grafana instance with envelope encryption, see the [Operational work](#operational-work) section.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
In Grafana Enterprise, you can also [encrypt secrets in AES-GCM (Galois/Counter Mode)](#changing-your-encryption-mode-to-aes-gcm) instead of the default AES-CFB (Cipher FeedBack mode).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
## Envelope encryption
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Since Grafana v9.0, you can turn envelope encryption off by adding the feature toggle `disableEnvelopeEncryption` to your [Grafana configuration](../../configure-grafana/#feature_toggles).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
Instead of encrypting all secrets with a single key, Grafana uses a set of keys called data encryption keys (DEKs) to encrypt them. These data encryption keys are themselves encrypted with a single key encryption key (KEK), configured through the `secret_key` attribute in your
|
||||
[Grafana configuration](../../configure-grafana/#secret_key) or by [Encrypting your database with a key from a key management service (KMS)](#encrypting-your-database-with-a-key-from-a-key-management-service-kms).
|
||||
@@ -79,11 +79,11 @@ You can rotate data keys to disable the active data key and therefore stop using
|
||||
|
||||
New data keys for encryption operations are generated on demand.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Data key rotation does **not** implicitly re-encrypt secrets. Grafana will continue to use rotated data keys to decrypt
|
||||
secrets still encrypted with them. To completely stop using
|
||||
rotated data keys for both encryption and decryption, see [secrets re-encryption](#re-encrypt-secrets).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
To rotate data keys, use the `/encryption/rotate-data-keys` endpoint of the Grafana [Admin API](../../../developers/http_api/admin/#rotate-data-encryption-keys). It's safe to call more than once, more recommended under maintenance mode.
|
||||
|
||||
|
||||
+4
-4
@@ -15,14 +15,14 @@ weight: 500
|
||||
|
||||
If you manage your secrets with [Hashicorp Vault](https://www.hashicorp.com/products/vault), you can use them for [Configuration](../../../configure-grafana/) and [Provisioning](../../../../administration/provisioning/).
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Available in [Grafana Enterprise](../../../../introduction/grafana-enterprise/).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
If you have Grafana [set up for high availability](../../../set-up-for-high-availability/), then we advise not to use dynamic secrets for provisioning files.
|
||||
Each Grafana instance is responsible for renewing its own leases. Your data source leases might expire when one of your Grafana servers shuts down.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
## Configuration
|
||||
|
||||
|
||||
@@ -18,13 +18,13 @@ Request security allows you to limit requests from the Grafana server by targeti
|
||||
|
||||
This can be used to limit access to internal systems that the server Grafana runs on can access but that users of Grafana should not be able to access. This feature does not affect traffic from the Grafana users browser.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Available in [Grafana Enterprise](../../../introduction/grafana-enterprise/) and [Grafana Cloud Pro and Advanced](/docs/grafana-cloud/).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Although request security works with backend plugins, you can create a backend plugin that bypasses this security.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
## IP and hostname blocking
|
||||
|
||||
|
||||
@@ -17,9 +17,9 @@ weight: 900
|
||||
|
||||
# Export logs of usage insights
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Available in [Grafana Enterprise](../../../introduction/grafana-enterprise/) and [Grafana Cloud Pro and Advanced](/docs/grafana-cloud/).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
By exporting usage logs to Loki, you can directly query them and create dashboards of the information that matters to you most, such as dashboard errors, most active organizations, or your top-10 most-used queries. This configuration is done for you in Grafana Cloud, with provisioned dashboards. Read about them in the [Grafana Cloud documentation](/docs/grafana-cloud/usage-insights/).
|
||||
|
||||
|
||||
@@ -19,9 +19,9 @@ Grafana instances, whether on-premises or on the cloud, can use this service to
|
||||
|
||||
If the service detects a leaked token, it immediately revokes it, making it useless, and logs the event.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
If the `revoke` option is disabled, the service only sends a notification to the configured webhook URL and logs the event. The token is not automatically revoked.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
You can also configure the service to send an outgoing webhook notification to a webhook URL.
|
||||
|
||||
@@ -39,9 +39,9 @@ Grafana has revoked this token",
|
||||
}
|
||||
```
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Secret scanning is disabled by default. Outgoing connections are made once you enable it.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
## Before you begin
|
||||
|
||||
|
||||
@@ -32,9 +32,9 @@ Alert notifications can include images, but rendering many images at the same ti
|
||||
|
||||
## Install Grafana Image Renderer plugin
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
All PhantomJS support has been removed. Instead, use the Grafana Image Renderer plugin or remote rendering service.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
To install the plugin, refer to the [Grafana Image Renderer Installation instructions](/grafana/plugins/grafana-image-renderer/?tab=installation#installation).
|
||||
|
||||
@@ -66,9 +66,9 @@ You can see a docker-compose example using a custom configuration file [here](ht
|
||||
|
||||
### Security
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
This feature is available in Image Renderer v3.6.1 and later.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
You can restrict access to the rendering endpoint by specifying a secret token. The token should be configured in the Grafana configuration file and the renderer configuration file. This token is important when you run the plugin in remote rendering mode.
|
||||
|
||||
@@ -104,9 +104,9 @@ You can instruct how headless browser instances are created by configuring a ren
|
||||
|
||||
Default mode will create a new browser instance on each request. When handling multiple concurrent requests, this mode increases memory usage as it will launch multiple browsers at the same time. If you want to set a maximum number of browser to open, you'll need to use the [clustered mode](#clustered).
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
When using the `default` mode, it's recommended to not remove the default Chromium flag `--disable-gpu`. When receiving a lot of concurrent requests, not using this flag can cause Puppeteer `newPage` function to freeze, causing request timeouts and leaving browsers open.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
```bash
|
||||
RENDERING_MODE=default
|
||||
@@ -177,9 +177,9 @@ To achieve better performance, monitor the machine on which your service is runn
|
||||
|
||||
### Other available settings
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Please note that not all settings are available using environment variables. If there is no example using environment variable below, it means that you need to update the configuration file.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
#### HTTP host
|
||||
|
||||
@@ -215,9 +215,9 @@ HTTP_PORT=0
|
||||
|
||||
#### HTTP protocol
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
HTTPS protocol is supported in the image renderer v3.11.0 and later.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
Change the protocol of the server, it can be `http` or `https`. Default is `http`.
|
||||
|
||||
@@ -370,9 +370,9 @@ RENDERING_DUMPIO=true
|
||||
If you already have [Chrome](https://www.google.com/chrome/) or [Chromium](https://www.chromium.org/)
|
||||
installed on your system, then you can use this instead of the pre-packaged version of Chromium.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Please note that this is not recommended, since you may encounter problems if the installed version of Chrome/Chromium is not compatible with the [Grafana Image renderer plugin](/grafana/plugins/grafana-image-renderer).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
You need to make sure that the Chrome/Chromium executable is available for the Grafana/image rendering service process.
|
||||
|
||||
|
||||
@@ -155,10 +155,10 @@ As a last resort, if you already have [Chrome](https://www.google.com/chrome/) o
|
||||
installed on your system, then you can configure the Grafana Image renderer plugin to use this
|
||||
instead of the pre-packaged version of Chromium.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Please note that this is not recommended, since you may encounter problems if the installed version of Chrome/Chromium is not
|
||||
compatible with the [Grafana Image renderer plugin](/grafana/plugins/grafana-image-renderer).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
To override the path to the Chrome/Chromium executable in plugin mode, set an environment variable and make sure that it's available for the Grafana process. For example:
|
||||
|
||||
|
||||
@@ -16,9 +16,9 @@ This topic includes instructions for installing and running Grafana on Kubernete
|
||||
|
||||
[Helm](https://helm.sh/) is an open-source command line tool used for managing Kubernetes applications. It is a graduate project in the [CNCF Landscape](https://www.cncf.io/projects/helm/).
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
The Grafana open-source community offers Helm Charts for running it on Kubernetes. Please be aware that the code is provided without any warranties. If you encounter any problems, you can report them to the [Official GitHub repository](https://github.com/grafana/helm-charts/).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
Watch this video to learn more about installing Grafana using Helm Charts: {{< youtube id="sgYrEleW24E">}}
|
||||
|
||||
|
||||
@@ -45,16 +45,16 @@ For a list of supported databases, refer to [supported databases](/docs/grafana/
|
||||
|
||||
For a list of support web browsers, refer to [supported web browsers](/docs/grafana/latest/setup-grafana/installation#supported-web-browsers).
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Enable port `3000` in your network environment, as this is the Grafana default port.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
## Deploy Grafana OSS on Kubernetes
|
||||
|
||||
This section explains how to install Grafana OSS using Kubernetes.
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
If you want to install Grafana Enterprise on Kubernetes, refer to [Deploy Grafana Enterprise on Kubernetes](#deploy-grafana-enterprise-on-kubernetes).
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
If you deploy an application in Kubernetes, it will use the default namespace which may already have other applications running. This can result in conflicts and other issues.
|
||||
|
||||
@@ -346,9 +346,9 @@ Rolling updates enable deployment updates to take place with no downtime by incr
|
||||
|
||||
The following steps use the `kubectl annotate` command to add the metadata and keep track of the deployment. For more information about `kubectl annotate`, refer to [kubectl annotate documentation](https://jamesdefabia.github.io/docs/user-guide/kubectl/kubectl_annotate/).
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
Instead of using the `annotate` flag, you can still use the `--record` flag. However, it has been deprecated and will be removed in the future version of Kubernetes. See: https://github.com/kubernetes/kubernetes/issues/40422
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
1. To view the current status of the rollout, run the following command:
|
||||
|
||||
@@ -457,9 +457,9 @@ Instead of using the `annotate` flag, you can still use the `--record` flag. How
|
||||
|
||||
This means that `REVISION#2` is the current version.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
The last line of the `kubectl rollout history deployment` command output is the one which is currently active and running on your Kubernetes environment.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
### Roll back a deployment
|
||||
|
||||
@@ -887,9 +887,9 @@ kubectl create configmap ge-config --from-file=/path/to/your/grafana.ini
|
||||
type: LoadBalancer
|
||||
```
|
||||
|
||||
{{% admonition type="caution" %}}
|
||||
{{< admonition type="caution" >}}
|
||||
If you use `LoadBalancer` in the Service and depending on your cloud platform and network configuration, doing so might expose your Grafana instance to the Internet. To eliminate this risk, use `ClusterIP` to restrict access from within the cluster Grafana is deployed to.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
1. To send the manifest to Kubernetes API Server, run the following command:
|
||||
`kubectl apply -f grafana.yaml`
|
||||
|
||||
@@ -23,9 +23,9 @@ Grafana Live is a real-time messaging engine you can use to push event data to a
|
||||
|
||||
This could be notifications about dashboard changes, new frames for rendered data, and so on. Live features can help eliminate a page reload or polling in many places, it can stream Internet of things (IoT) sensors or any other real-time data to panels.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
By `real-time`, we indicate a soft real-time. Due to network latencies, garbage collection cycles, and so on, the delay of a delivered message can be up to several hundred milliseconds or higher.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
## Concepts
|
||||
|
||||
|
||||
@@ -107,9 +107,9 @@ This section shows you how to use `openssl` tooling to generate all necessary fi
|
||||
|
||||
The examples in this section use LetsEncrypt because it is free.
|
||||
|
||||
{{% admonition type="note" %}}
|
||||
{{< admonition type="note" >}}
|
||||
The instructions provided in this section are for a Debian-based Linux system. For other distributions and operating systems, please refer to the [certbot instructions](https://certbot.eff.org/instructions). Also, these instructions require you to have a domain name that you are in control of. Dynamic domain names like those from Amazon EC2 or DynDNS providers will not function.
|
||||
{{% /admonition %}}
|
||||
{{< /admonition >}}
|
||||
|
||||
#### Install `snapd` and `certbot`
|
||||
|
||||
|
||||
Reference in New Issue
Block a user