Ansible role that installs Grafana and Prometheus
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Simon Cornet de42e57ca6
Some checks failed
ci/woodpecker/push/linting Pipeline failed
docs: improve readme
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-10-05 17:27:49 +02:00
.woodpecker chore(package): update cr.simoncor.net/dockerhub/davidanson/markdownlint-cli2 docker tag to v0.23.3 2026-09-20 05:47:54 +00:00
defaults feat: initial commit 2025-10-23 16:06:21 +02:00
handlers feat: initial commit 2025-10-23 16:06:21 +02:00
meta feat: move deps to playbook 2026-05-08 15:44:26 +02:00
roles ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:02 +02:00
tasks chore(package): update cr.simoncor.net/dockerhub/prom/prometheus docker tag to v3.15.0 2026-09-25 08:30:39 +00:00
.ansible-lint fix: exclude only sops yml files from lint 2026-07-14 16:23:40 +02:00
.editorconfig chore: add .editorconfig and .gitattributes 2026-05-27 14:23:44 +02:00
.gitattributes chore: add .editorconfig and .gitattributes 2026-05-27 14:23:44 +02:00
.gitignore feat: initial commit 2025-10-23 16:06:21 +02:00
.markdownlint-cli2.jsonc ci: migrate from gitlab ci to woodpecker 2026-05-15 14:31:02 +02:00
.sops.yaml fix: correct sops regex to ya?ml 2026-07-14 16:01:47 +02:00
.yamllint chore: exclude .yml files from lint configs 2026-07-14 16:17:23 +02:00
AGENTS.md chore: add AGENTS.md for opencode agents 2026-02-16 10:26:57 +01:00
ansible.cfg chore: sync linting and config files from common 2026-07-14 11:33:15 +02:00
playbook.yaml chore(playbook): run galaxy install only on first host 2026-08-13 08:49:03 +02:00
readme.md docs: improve readme 2026-10-05 17:27:49 +02:00
renovate.json feat: initial commit 2025-10-23 16:06:21 +02:00

Ansible Role: Grafana

Install and configure Grafana together with Prometheus, both as Docker containers on the host network.

Requirements

A Docker host with writable /mnt/grafana and /mnt/prometheus paths (for example mounted volumes). The role itself does not install Docker.

Dependencies

The playbook (playbook.yaml) runs these roles, in order, before grafana:

  • docker
  • traefik

Note that roles/requirements.yml only lists the grafana role itself.

Variables

Variable Required Default Description
grafana_admin_password Yes development Grafana admin password (GF_SECURITY_ADMIN_PASSWORD)

The role also uses timezone (passed as TZ to both containers). It has no default and must be set in the inventory.

Example

Keep real passwords in sops-encrypted inventory variables.

timezone: "Europe/Amsterdam"
grafana_admin_password: "change-me"

What the role does

  • Prometheus:
    • creates /mnt/prometheus and /mnt/prometheus/data (owner nobody, group nogroup, mode 0775);
    • writes /mnt/prometheus/prometheus.yml with a 15s scrape interval and one job, unbound, scraping dns01.siempie.internal:9167 and dns02.siempie.internal:9167 (hardcoded in the task);
    • restarts the container when the config changes (restart prometheus handler);
    • runs cr.simoncor.net/dockerhub/prom/prometheus:v3.14.0 as container prometheus on the host network.
  • Grafana:
    • creates /mnt/grafana (mode 0775);
    • runs cr.simoncor.net/dockerhub/grafana/grafana-oss:13.0.2 as container grafana on the host network with /mnt/grafana mounted on /var/lib/grafana.
  • Both containers are always pulled, use restart policy unless-stopped and json-file logs (max 5m x 3).
  • Cleans up Docker afterwards (tasks/cleanup.yaml): docker_prune and docker system prune --all --force --volumes, which removes all unused images, networks and volumes on the host.

Because the host network is used, Grafana listens on its default port 3000 and Prometheus on 9090.

Usage

Run playbook.yaml through Semaphore. It first runs ansible-galaxy install -f -r roles/requirements.yml on the controller (works around a Semaphore bug), then the docker, traefik and grafana roles on all hosts.