apm-wo-analysis/grafana/provisioning/datasources/athena.yaml
Adam Moussa 3c8b7704f6 Fix Grafana Athena auth: use default credential chain, not ec2_iam_role
Grafana rejected the datasource with 'trying to use non-allowed auth method
ec2_iam_role: Failed to create client' — the plugin's allowed_auth_providers
defaults to default,keys,credentials and excludes ec2_iam_role. Switch authType
to 'default' (AWS SDK default chain), which on EC2 resolves to the instance role
via IMDS (still no static keys) and is allowed out of the box.
2026-05-28 18:59:09 -04:00

18 lines
766 B
YAML

# Athena datasource, authenticated via the EC2 instance IAM role (no static keys).
# Provisioned into /etc/grafana/provisioning/datasources/ via user-data (Phase 5).
# authType "default" = AWS SDK default credential chain, which on EC2 resolves to
# the instance role via IMDS. ("ec2_iam_role" is rejected by the plugin unless
# added to [aws] allowed_auth_providers; "default" is allowed out of the box.)
apiVersion: 1
datasources:
- name: Athena
type: grafana-athena-datasource
uid: athena
isDefault: true
jsonData:
authType: default
defaultRegion: us-east-1
catalog: AwsDataCatalog
database: apm_wo_analysis
workgroup: apm-wo-analysis
outputLocation: s3://apm-wo-analysis-exports-328440206208/athena-results/