apm-wo-analysis/grafana/provisioning/datasources/athena.yaml

19 lines
766 B
YAML
Raw Normal View History

# Athena datasource, authenticated via the EC2 instance IAM role (no static keys).
# Provisioned into /etc/grafana/provisioning/datasources/ via user-data (Phase 5).
# authType "default" = AWS SDK default credential chain, which on EC2 resolves to
# the instance role via IMDS. ("ec2_iam_role" is rejected by the plugin unless
# added to [aws] allowed_auth_providers; "default" is allowed out of the box.)
apiVersion: 1
datasources:
- name: Athena
type: grafana-athena-datasource
Add self-hosted Grafana stack: EC2, ALB, dashboards-as-code (Phase 5) The one non-serverless piece — Grafana OSS on a t4g.small (AL2023, ARM64) in the imported seahaven-vpc, fronted by an internet-facing ALB locked by SG to the office CIDRs (no Client VPN exists, so "VPN-only" = office-IP restriction, the syslog-server pattern). Instance in private subnets, reachable only from the ALB SG, administered via SSM Session Manager (no SSH/key pair). grafana_stack.py: ALB (HTTPS, *.seahaven.com cert, open=False so the SG office rules aren't undone by an auto 0.0.0.0/0), instance role (Athena query + Glue read + S3 analytics/athena-results, no static keys), Route53 grafana.seahaven.com alias, gp3 root volume RETAINed, daily DLM snapshot of the tagged instance, and a BucketDeployment that uploads grafana/ to the S3 config prefix. grafana_userdata.sh: install Grafana OSS, pin the Athena datasource plugin, write grafana.ini (root_url grafana.seahaven.com, kiosk embedding), sync provisioning + dashboards from S3 on boot, and a systemd timer re-syncs every 15 min so repo edits land without an instance rebuild. Dashboard (grafana-author agent, grafana/dashboards/apm-work-orders.json, uid apm-wo so the Slack 📊 button resolves): 7 panels — category distribution, escalation summary, action/routine, escalations-by-site, trend time-series over dt (the new capability), filterable WO table (5 template vars, escalation row coloring, CSV export, no APM links), and the mismatch panel. Datasource uid "athena" pinned in the provisioning yaml. Tests: tests/test_grafana_synth.py — ALB admits only the office CIDRs on 443 (caught and fixed a default 0.0.0.0/0 listener rule), instance only-from-ALB, no static keys, scoped instance role + SSM, gp3+retained root volume, daily DLM backup, grafana.seahaven.com alias. 57/57 tests pass; full cdk synth green.
2026-05-28 18:05:20 -04:00
uid: athena
isDefault: true
jsonData:
authType: default
defaultRegion: us-east-1
catalog: AwsDataCatalog
database: apm_wo_analysis
workgroup: apm-wo-analysis
outputLocation: s3://apm-wo-analysis-exports-328440206208/athena-results/