mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-09-30 05:23:15 +00:00
Some checks are pending
Deploy / Deploy to prod (push) Waiting to run
* feat(infra): migrate pipeline and Grafana to HCP Terraform (PLAT-75) Move apm-wo-analysis into seahaven-prod under workspace apm-wo-analysis-prod with in-repo hcptf/githubdeploy IAM, stub Lambdas, and GitHub Actions zip CD. * chore(iam): add Checkov skip comments for HCP IAM documents Pre-push HIGH findings are the DLM snapshot describe, tagged EC2 creates, exec boundary DescribeLogGroups star, and the drop-uploader user policy.
86 lines
2.5 KiB
Text
86 lines
2.5 KiB
Text
#!/bin/bash
|
|
# Grafana OSS bootstrap for the apm-wo-analysis dashboard host (Amazon Linux 2023,
|
|
# ARM64). Idempotent enough to re-run. Config + dashboards are pulled from S3
|
|
# (the repo is the source of truth); a systemd timer re-syncs dashboards so panel
|
|
# updates ship by re-uploading to S3 — no instance rebuild.
|
|
set -euxo pipefail
|
|
|
|
CONFIG_BUCKET="${config_bucket}"
|
|
CONFIG_PREFIX="${config_prefix}"
|
|
PLUGIN_VERSION="${plugin_version}"
|
|
GRAFANA_DOMAIN="${grafana_domain}"
|
|
|
|
cat >/etc/yum.repos.d/grafana.repo <<'REPO'
|
|
[grafana]
|
|
name=grafana
|
|
baseurl=https://rpm.grafana.com
|
|
repo_gpgcheck=1
|
|
enabled=1
|
|
gpgcheck=1
|
|
gpgkey=https://rpm.grafana.com/gpg.key
|
|
sslverify=1
|
|
REPO
|
|
dnf install -y grafana
|
|
|
|
grafana-cli --homepath=/usr/share/grafana --pluginsDir=/var/lib/grafana/plugins \
|
|
plugins install grafana-athena-datasource "$${PLUGIN_VERSION}"
|
|
|
|
cat >/etc/grafana/grafana.ini <<INI
|
|
[server]
|
|
protocol = http
|
|
http_port = 3000
|
|
root_url = https://$${GRAFANA_DOMAIN}/
|
|
enforce_domain = false
|
|
|
|
[security]
|
|
allow_embedding = true
|
|
cookie_secure = true
|
|
|
|
[users]
|
|
default_theme = dark
|
|
|
|
[analytics]
|
|
reporting_enabled = false
|
|
check_for_updates = false
|
|
INI
|
|
|
|
sync_config() {
|
|
aws s3 sync "s3://$${CONFIG_BUCKET}/$${CONFIG_PREFIX}/provisioning/" /etc/grafana/provisioning/ --delete --exact-timestamps
|
|
aws s3 sync "s3://$${CONFIG_BUCKET}/$${CONFIG_PREFIX}/dashboards/" /var/lib/grafana/dashboards/ --delete --exact-timestamps
|
|
chown -R grafana:grafana /etc/grafana/provisioning /var/lib/grafana/dashboards
|
|
}
|
|
mkdir -p /var/lib/grafana/dashboards
|
|
sync_config
|
|
|
|
systemctl daemon-reload
|
|
systemctl enable --now grafana-server
|
|
|
|
cat >/usr/local/bin/grafana-config-sync.sh <<SYNC
|
|
#!/bin/bash
|
|
set -euo pipefail
|
|
aws s3 sync "s3://$${CONFIG_BUCKET}/$${CONFIG_PREFIX}/provisioning/" /etc/grafana/provisioning/ --delete --exact-timestamps
|
|
aws s3 sync "s3://$${CONFIG_BUCKET}/$${CONFIG_PREFIX}/dashboards/" /var/lib/grafana/dashboards/ --delete --exact-timestamps
|
|
chown -R grafana:grafana /etc/grafana/provisioning /var/lib/grafana/dashboards
|
|
SYNC
|
|
chmod +x /usr/local/bin/grafana-config-sync.sh
|
|
|
|
cat >/etc/systemd/system/grafana-config-sync.service <<'SVC'
|
|
[Unit]
|
|
Description=Sync apm-wo Grafana config/dashboards from S3
|
|
[Service]
|
|
Type=oneshot
|
|
ExecStart=/usr/local/bin/grafana-config-sync.sh
|
|
SVC
|
|
|
|
cat >/etc/systemd/system/grafana-config-sync.timer <<'TIMER'
|
|
[Unit]
|
|
Description=Periodic apm-wo Grafana config sync
|
|
[Timer]
|
|
OnBootSec=5min
|
|
OnUnitActiveSec=15min
|
|
[Install]
|
|
WantedBy=timers.target
|
|
TIMER
|
|
|
|
systemctl daemon-reload
|
|
systemctl enable --now grafana-config-sync.timer
|