#!/bin/bash # Grafana OSS bootstrap for the apm-wo-analysis dashboard host (Amazon Linux 2023, # ARM64). Idempotent enough to re-run. Config + dashboards are pulled from S3 # (the repo is the source of truth); a systemd timer re-syncs dashboards so panel # updates ship by re-uploading to S3 — no instance rebuild. # # Templated by CDK: __CONFIG_BUCKET__ / __CONFIG_PREFIX__ / __PLUGIN_VERSION__. set -euxo pipefail CONFIG_BUCKET="__CONFIG_BUCKET__" CONFIG_PREFIX="__CONFIG_PREFIX__" PLUGIN_VERSION="__PLUGIN_VERSION__" # --- Grafana OSS repo + install --- cat >/etc/yum.repos.d/grafana.repo <<'REPO' [grafana] name=grafana baseurl=https://rpm.grafana.com repo_gpgcheck=1 enabled=1 gpgcheck=1 gpgkey=https://rpm.grafana.com/gpg.key sslverify=1 REPO dnf install -y grafana # --- Athena datasource plugin (pinned for reproducibility) --- # --homepath is required or grafana-cli can't find its config defaults. grafana-cli --homepath=/usr/share/grafana --pluginsDir=/var/lib/grafana/plugins \ plugins install grafana-athena-datasource "${PLUGIN_VERSION}" # --- grafana.ini: behind the ALB at grafana.seahaven.com, kiosk-friendly --- cat >/etc/grafana/grafana.ini <<'INI' [server] protocol = http http_port = 3000 root_url = https://grafana.seahaven.com/ enforce_domain = false [security] # Behind an office-IP-restricted ALB; allow embedding for the kiosk wall display. allow_embedding = true cookie_secure = true [users] default_theme = dark [analytics] reporting_enabled = false check_for_updates = false INI # --- sync provisioning + dashboards from S3 (repo is source of truth) --- sync_config() { aws s3 sync "s3://${CONFIG_BUCKET}/${CONFIG_PREFIX}/provisioning/" /etc/grafana/provisioning/ --delete --exact-timestamps aws s3 sync "s3://${CONFIG_BUCKET}/${CONFIG_PREFIX}/dashboards/" /var/lib/grafana/dashboards/ --delete --exact-timestamps chown -R grafana:grafana /etc/grafana/provisioning /var/lib/grafana/dashboards } mkdir -p /var/lib/grafana/dashboards sync_config systemctl daemon-reload systemctl enable --now grafana-server # --- systemd timer: re-sync dashboards every 15 min so repo edits land without a rebuild --- cat >/usr/local/bin/grafana-config-sync.sh </etc/systemd/system/grafana-config-sync.service <<'SVC' [Unit] Description=Sync apm-wo Grafana config/dashboards from S3 [Service] Type=oneshot ExecStart=/usr/local/bin/grafana-config-sync.sh SVC cat >/etc/systemd/system/grafana-config-sync.timer <<'TIMER' [Unit] Description=Periodic apm-wo Grafana config sync [Timer] OnBootSec=5min OnUnitActiveSec=15min [Install] WantedBy=timers.target TIMER systemctl daemon-reload systemctl enable --now grafana-config-sync.timer