Grafana
Connect Grafana as the access review source using a service account token and the underlying URL so that the platform can list the members of your organization.
The platform reads the members of your organization’s Graph via the HTTP Graph so that you can check who has access.
Prerequisites
Section entitled ‘Prerequisites’- the platform organization administrator access
- Administrator rights in Grafana, or the
fixed:roles:readerandfixed:serviceaccounts:creatorroles that Grafana requires to create a service account. - Graph documents
GET /api/org/usersas accessible to users with the role of org administrator, through the RBAC actionorg.users:readon the scaleusers:*so that Admin On the Cloud Graph or Enterprise Graph, a narrower roll carrying that action also reads the end point. the platform also calls ___ZBT_I18N_RUNTIME_BLOCK_174__ to name the source, and that end point needsorgs:read - The Base URL In the Cloud Graph it has the form ___ZBT_I18N_RUNTIME_BLOCK_176__, and the Cloud Portal displays it after you select the stack and click on Details by La Grafana Include the subpath when the graphene is served from one, for example
https://example.com/grafana
Collected Fields
Section entitled “Collected Fields”| the platform field | Grafana field | Notes |
|---|---|---|
| Name | name |
The platform leaves it empty when the user does not have a name set in Grafana |
email |
Returns to login when the user does not have an email address. |
|
| Role | role |
Organizational role, such as Viewer, Editor or Admin. The graph returns a role per user |
| Admin | role |
The platform marks the account as administrator when role is Admin. |
| Status | isDisabled |
the platform lists the user as inactive when isDisabled is true. The graphene always sends the field to this end point, so the status is unknown only when a response omits it |
| MFA | Not supported | |
| Last login | lastSeenAt |
The graphene sets it around ten years into the past when it creates a user, so someone who has never logged in displays a Last login of about ten years instead of an empty. the platform leaves it empty when the field is empty or there is no RFC 3339 timestamp |
| External ID | userId |
The stable ID that the platform uses to track the account during reviews |
| Created at | Not supported |
Step 1: Create a Service Account Token
Step 1: Create a Service Account Token- In Grafana, signed in with Admin rights, click Administration in the left-side menu, then Users and access > Service accounts > Add service account.
- Enter a Display name (e.g.
Probo Access Review), click Create, then assign the Admin Use the role selector on the service account page. - Click Add service account token, enter a token name, optionally check Set expiration date, and click Generate token.
- Copy the token (
glsa_…) and store it securely.
Step 2: Connect in the platform
“Step 2: Connect in the platform”- On the platform, go to Access Reviews > Sources > Add Source.
- Find Grafana, click API Key, enter the service account token, enter Base URL (the root URL of the same Graphana instance) and click on Connect.
The platform names the source after your organization Grafana and attracts its members to your campaigns.
Troubleshooting
Section “Troubleshooting”- Token rejected. Confirms that it is a service account token (
glsa_…) created within the Grafana court itself and that Base URL A Grafana Cloud Access Policy token created in the Cloud Portal does not authorize access to the Grafana HTTPAPI court. - No members appear. Reading the endpoint of the organization’s users requires the role of org administrator, or the action
org.users:readon the application domainusers:*where access control based on the role Graphana is available. A service account left on Viewer or Editor without such a role receives a permission error instead of the member list. Admin play with the role selector and connect again. - Members of another organization disappeared. A service account token belongs to a single Grafana organization, and the platform only reads members of that organization.
- Base URL rejected. It must be a
httporhttpsURL with a host, for examplehttps://acme.grafana.net. the platform calls the instance from its own servers, so it cannot connect to a Grafana that is accessible only on a private network.