| Filename | Latest commit message | Latest commit date |
|---|---|---|
|
Some checks failed
ci/woodpecker/push/linting Pipeline failed
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com> |
||
| .woodpecker | ||
| defaults | ||
| handlers | ||
| meta | ||
| roles | ||
| tasks | ||
| .ansible-lint | ||
| .editorconfig | ||
| .gitattributes | ||
| .gitignore | ||
| .markdownlint-cli2.jsonc | ||
| .sops.yaml | ||
| .yamllint | ||
| AGENTS.md | ||
| ansible.cfg | ||
| playbook.yaml | ||
| readme.md | ||
| renovate.json | ||
Ansible Role: Grafana
Install and configure Grafana together with Prometheus, both as Docker containers on the host network.
Requirements
A Docker host with writable /mnt/grafana and /mnt/prometheus paths (for example mounted volumes). The role
itself does not install Docker.
Dependencies
The playbook (playbook.yaml) runs these roles, in order, before grafana:
dockertraefik
Note that roles/requirements.yml only lists the grafana role itself.
Variables
| Variable | Required | Default | Description |
|---|---|---|---|
grafana_admin_password |
Yes | development |
Grafana admin password (GF_SECURITY_ADMIN_PASSWORD) |
The role also uses timezone (passed as TZ to both containers). It has no default and must be set in the
inventory.
Example
Keep real passwords in sops-encrypted inventory variables.
timezone: "Europe/Amsterdam"
grafana_admin_password: "change-me"
What the role does
- Prometheus:
- creates
/mnt/prometheusand/mnt/prometheus/data(ownernobody, groupnogroup, mode0775); - writes
/mnt/prometheus/prometheus.ymlwith a 15s scrape interval and one job,unbound, scrapingdns01.siempie.internal:9167anddns02.siempie.internal:9167(hardcoded in the task); - restarts the container when the config changes (
restart prometheushandler); - runs
cr.simoncor.net/dockerhub/prom/prometheus:v3.14.0as containerprometheuson the host network.
- creates
- Grafana:
- creates
/mnt/grafana(mode0775); - runs
cr.simoncor.net/dockerhub/grafana/grafana-oss:13.0.2as containergrafanaon the host network with/mnt/grafanamounted on/var/lib/grafana.
- creates
- Both containers are always pulled, use restart policy
unless-stoppedand json-file logs (max 5m x 3). - Cleans up Docker afterwards (
tasks/cleanup.yaml):docker_pruneanddocker system prune --all --force --volumes, which removes all unused images, networks and volumes on the host.
Because the host network is used, Grafana listens on its default port 3000 and Prometheus on 9090.
Usage
Run playbook.yaml through Semaphore. It first runs ansible-galaxy install -f -r roles/requirements.yml on the
controller (works around a Semaphore bug), then the docker, traefik and grafana roles on all hosts.