mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-10-06 08:52:01 +00:00
93 lines
2.8 KiB
Bash
93 lines
2.8 KiB
Bash
|
|
#!/bin/bash
|
||
|
|
# Grafana OSS bootstrap for the apm-wo-analysis dashboard host (Amazon Linux 2023,
|
||
|
|
# ARM64). Idempotent enough to re-run. Config + dashboards are pulled from S3
|
||
|
|
# (the repo is the source of truth); a systemd timer re-syncs dashboards so panel
|
||
|
|
# updates ship by re-uploading to S3 — no instance rebuild.
|
||
|
|
#
|
||
|
|
# Templated by CDK: __CONFIG_BUCKET__ / __CONFIG_PREFIX__ / __PLUGIN_VERSION__.
|
||
|
|
set -euxo pipefail
|
||
|
|
|
||
|
|
CONFIG_BUCKET="__CONFIG_BUCKET__"
|
||
|
|
CONFIG_PREFIX="__CONFIG_PREFIX__"
|
||
|
|
PLUGIN_VERSION="__PLUGIN_VERSION__"
|
||
|
|
|
||
|
|
# --- Grafana OSS repo + install ---
|
||
|
|
cat >/etc/yum.repos.d/grafana.repo <<'REPO'
|
||
|
|
[grafana]
|
||
|
|
name=grafana
|
||
|
|
baseurl=https://rpm.grafana.com
|
||
|
|
repo_gpgcheck=1
|
||
|
|
enabled=1
|
||
|
|
gpgcheck=1
|
||
|
|
gpgkey=https://rpm.grafana.com/gpg.key
|
||
|
|
sslverify=1
|
||
|
|
REPO
|
||
|
|
dnf install -y grafana
|
||
|
|
|
||
|
|
# --- Athena datasource plugin (pinned for reproducibility) ---
|
||
|
|
grafana-cli --pluginsDir /var/lib/grafana/plugins plugins install grafana-athena-datasource "${PLUGIN_VERSION}"
|
||
|
|
|
||
|
|
# --- grafana.ini: behind the ALB at grafana.seahaven.com, kiosk-friendly ---
|
||
|
|
cat >/etc/grafana/grafana.ini <<'INI'
|
||
|
|
[server]
|
||
|
|
protocol = http
|
||
|
|
http_port = 3000
|
||
|
|
root_url = https://grafana.seahaven.com/
|
||
|
|
enforce_domain = false
|
||
|
|
|
||
|
|
[security]
|
||
|
|
# Behind an office-IP-restricted ALB; allow embedding for the kiosk wall display.
|
||
|
|
allow_embedding = true
|
||
|
|
cookie_secure = true
|
||
|
|
|
||
|
|
[users]
|
||
|
|
default_theme = dark
|
||
|
|
|
||
|
|
[analytics]
|
||
|
|
reporting_enabled = false
|
||
|
|
check_for_updates = false
|
||
|
|
INI
|
||
|
|
|
||
|
|
# --- sync provisioning + dashboards from S3 (repo is source of truth) ---
|
||
|
|
sync_config() {
|
||
|
|
aws s3 sync "s3://${CONFIG_BUCKET}/${CONFIG_PREFIX}/provisioning/" /etc/grafana/provisioning/ --delete
|
||
|
|
aws s3 sync "s3://${CONFIG_BUCKET}/${CONFIG_PREFIX}/dashboards/" /var/lib/grafana/dashboards/ --delete
|
||
|
|
chown -R grafana:grafana /etc/grafana/provisioning /var/lib/grafana/dashboards
|
||
|
|
}
|
||
|
|
mkdir -p /var/lib/grafana/dashboards
|
||
|
|
sync_config
|
||
|
|
|
||
|
|
systemctl daemon-reload
|
||
|
|
systemctl enable --now grafana-server
|
||
|
|
|
||
|
|
# --- systemd timer: re-sync dashboards every 15 min so repo edits land without a rebuild ---
|
||
|
|
cat >/usr/local/bin/grafana-config-sync.sh <<SYNC
|
||
|
|
#!/bin/bash
|
||
|
|
set -euo pipefail
|
||
|
|
aws s3 sync "s3://${CONFIG_BUCKET}/${CONFIG_PREFIX}/provisioning/" /etc/grafana/provisioning/ --delete
|
||
|
|
aws s3 sync "s3://${CONFIG_BUCKET}/${CONFIG_PREFIX}/dashboards/" /var/lib/grafana/dashboards/ --delete
|
||
|
|
chown -R grafana:grafana /etc/grafana/provisioning /var/lib/grafana/dashboards
|
||
|
|
SYNC
|
||
|
|
chmod +x /usr/local/bin/grafana-config-sync.sh
|
||
|
|
|
||
|
|
cat >/etc/systemd/system/grafana-config-sync.service <<'SVC'
|
||
|
|
[Unit]
|
||
|
|
Description=Sync apm-wo Grafana config/dashboards from S3
|
||
|
|
[Service]
|
||
|
|
Type=oneshot
|
||
|
|
ExecStart=/usr/local/bin/grafana-config-sync.sh
|
||
|
|
SVC
|
||
|
|
|
||
|
|
cat >/etc/systemd/system/grafana-config-sync.timer <<'TIMER'
|
||
|
|
[Unit]
|
||
|
|
Description=Periodic apm-wo Grafana config sync
|
||
|
|
[Timer]
|
||
|
|
OnBootSec=5min
|
||
|
|
OnUnitActiveSec=15min
|
||
|
|
[Install]
|
||
|
|
WantedBy=timers.target
|
||
|
|
TIMER
|
||
|
|
|
||
|
|
systemctl daemon-reload
|
||
|
|
systemctl enable --now grafana-config-sync.timer
|