Skip to main content

Expose Grafana safely

Out of the box the bundle's Grafana listens on 127.0.0.1:3000: reachable only from the machine it runs on, with login required. To share it with your team, put it behind a reverse proxy that terminates TLS, then tell Grafana its public address.

1. Put a TLS proxy in front​

Use the reverse proxy you already run (Caddy, nginx, Traefik, a cloud load balancer), forwarding to 127.0.0.1:3000 on this host. If the proxy runs on another machine, bind Grafana to an interface it can reach:

GRAFANA_BIND_ADDR=0.0.0.0

Do this only with a firewall or a private network between the proxy and Grafana. Grafana itself speaks plain HTTP.

2. Tell Grafana its public address​

In .env:

GRAFANA_ROOT_URL=https://monitoring.example.com/
GRAFANA_COOKIE_SECURE=true

GRAFANA_COOKIE_SECURE=true is required behind HTTPS and breaks login over plain HTTP. If you serve Grafana under a path, such as https://example.com/monitoring/, also set GRAFANA_SERVE_FROM_SUB_PATH=true and include the path in GRAFANA_ROOT_URL.

Apply with docker compose -f docker-compose-monitoring.yml up -d.

3. Decide who can see what​

  • Named accounts. Create users under Administration → Users and access and give them the Viewer role. Sign-up is disabled, so nobody can create their own account.
  • Read-only without login. GRAFANA_ANONYMOUS=true lets anyone who can reach Grafana view the dashboards without an account. Use it only on a network where everyone may see every run name and log.
  • Ad-hoc queries. Explore is off, because it would let any viewer run their own SQL against the logging database. GRAFANA_EXPLORE_ENABLED=true turns it on for everyone.

4. Change the admin password when needed​

GRAFANA_ADMIN_PASSWORD only applies the first time Grafana starts with an empty data volume. To change it later, change it in Grafana under Profile → Change password, and update .env so the next person reads the right value.