Fix Grafana Athena auth: use default credential chain, not ec2_iam_role

Grafana rejected the datasource with 'trying to use non-allowed auth method
ec2_iam_role: Failed to create client' — the plugin's allowed_auth_providers
defaults to default,keys,credentials and excludes ec2_iam_role. Switch authType
to 'default' (AWS SDK default chain), which on EC2 resolves to the instance role
via IMDS (still no static keys) and is allowed out of the box.
This commit is contained in:
Adam Moussa 2026-05-28 18:59:09 -04:00
parent 68f3acded8
commit 3c8b7704f6

View file

@ -1,5 +1,8 @@
# Athena datasource, authenticated via the EC2 instance IAM role (no static keys).
# Provisioned into /etc/grafana/provisioning/datasources/ via user-data (Phase 5).
# authType "default" = AWS SDK default credential chain, which on EC2 resolves to
# the instance role via IMDS. ("ec2_iam_role" is rejected by the plugin unless
# added to [aws] allowed_auth_providers; "default" is allowed out of the box.)
apiVersion: 1
datasources:
- name: Athena
@ -7,7 +10,7 @@ datasources:
uid: athena
isDefault: true
jsonData:
authType: ec2_iam_role
authType: default
defaultRegion: us-east-1
catalog: AwsDataCatalog
database: apm_wo_analysis