Expose Grafana safely
Out of the box the bundle's Grafana listens on 127.0.0.1:3000: reachable only from the machine
it runs on, with login required. To share it with your team, put it behind a reverse proxy that
terminates TLS, then tell Grafana its public address.
1. Put a TLS proxy in front
Use the reverse proxy you already run (Caddy, nginx, Traefik, a cloud load balancer), forwarding
to 127.0.0.1:3000 on this host. If the proxy runs on another machine, bind Grafana to an
interface it can reach:
GRAFANA_BIND_ADDR=0.0.0.0
Do this only with a firewall or a private network between the proxy and Grafana. Grafana itself speaks plain HTTP.
2. Tell Grafana its public address
In .env:
GRAFANA_ROOT_URL=https://monitoring.example.com/
GRAFANA_COOKIE_SECURE=true
GRAFANA_COOKIE_SECURE=true is required behind HTTPS and breaks login over plain HTTP. If you
serve Grafana under a path, such as https://example.com/monitoring/, also set
GRAFANA_SERVE_FROM_SUB_PATH=true and include the path in GRAFANA_ROOT_URL.
Apply with docker compose -f docker-compose-monitoring.yml up -d.
3. Decide who can see what
- Named accounts. Create users under Administration → Users and access and give them the Viewer role. Sign-up is disabled, so nobody can create their own account.
- Read-only without login.
GRAFANA_ANONYMOUS=truelets anyone who can reach Grafana view the dashboards without an account. Use it only on a network where everyone may see every run name and log. - Ad-hoc queries. Explore is off, because it would let any viewer run their own SQL against
the logging database.
GRAFANA_EXPLORE_ENABLED=trueturns it on for everyone.
4. Change the admin password when needed
GRAFANA_ADMIN_PASSWORD only applies the first time Grafana starts with an empty data volume.
To change it later, change it in Grafana under Profile → Change password, and update .env
so the next person reads the right value.