mirror of
https://github.com/Sea-Haven-Industries/apm-wo-analysis.git
synced 2026-10-02 22:43:19 +00:00
Found on first boot (cloud-init errored, grafana-server never started): - grafana-cli needs --homepath=/usr/share/grafana or it can't find config defaults; under set -e that aborted the whole bootstrap. - pinned plugin version 2.18.2 doesn't exist (conflated with awswrangler's version) — grafana-athena-datasource latest is 3.2.0. Verified by running the corrected bootstrap on the instance via SSM: plugin installs, grafana-server active, /api/health 200, ALB target healthy. NOTE: the running instance was repaired in-place (the user-data change updated the launch template but did not replace the instance). The committed user-data is now correct, so a fresh launch boots clean — a one-time clean instance replacement should validate that before prod sign-off.
94 lines
2.9 KiB
Bash
94 lines
2.9 KiB
Bash
#!/bin/bash
|
|
# Grafana OSS bootstrap for the apm-wo-analysis dashboard host (Amazon Linux 2023,
|
|
# ARM64). Idempotent enough to re-run. Config + dashboards are pulled from S3
|
|
# (the repo is the source of truth); a systemd timer re-syncs dashboards so panel
|
|
# updates ship by re-uploading to S3 — no instance rebuild.
|
|
#
|
|
# Templated by CDK: __CONFIG_BUCKET__ / __CONFIG_PREFIX__ / __PLUGIN_VERSION__.
|
|
set -euxo pipefail
|
|
|
|
CONFIG_BUCKET="__CONFIG_BUCKET__"
|
|
CONFIG_PREFIX="__CONFIG_PREFIX__"
|
|
PLUGIN_VERSION="__PLUGIN_VERSION__"
|
|
|
|
# --- Grafana OSS repo + install ---
|
|
cat >/etc/yum.repos.d/grafana.repo <<'REPO'
|
|
[grafana]
|
|
name=grafana
|
|
baseurl=https://rpm.grafana.com
|
|
repo_gpgcheck=1
|
|
enabled=1
|
|
gpgcheck=1
|
|
gpgkey=https://rpm.grafana.com/gpg.key
|
|
sslverify=1
|
|
REPO
|
|
dnf install -y grafana
|
|
|
|
# --- Athena datasource plugin (pinned for reproducibility) ---
|
|
# --homepath is required or grafana-cli can't find its config defaults.
|
|
grafana-cli --homepath=/usr/share/grafana --pluginsDir=/var/lib/grafana/plugins \
|
|
plugins install grafana-athena-datasource "${PLUGIN_VERSION}"
|
|
|
|
# --- grafana.ini: behind the ALB at grafana.seahaven.com, kiosk-friendly ---
|
|
cat >/etc/grafana/grafana.ini <<'INI'
|
|
[server]
|
|
protocol = http
|
|
http_port = 3000
|
|
root_url = https://grafana.seahaven.com/
|
|
enforce_domain = false
|
|
|
|
[security]
|
|
# Behind an office-IP-restricted ALB; allow embedding for the kiosk wall display.
|
|
allow_embedding = true
|
|
cookie_secure = true
|
|
|
|
[users]
|
|
default_theme = dark
|
|
|
|
[analytics]
|
|
reporting_enabled = false
|
|
check_for_updates = false
|
|
INI
|
|
|
|
# --- sync provisioning + dashboards from S3 (repo is source of truth) ---
|
|
sync_config() {
|
|
aws s3 sync "s3://${CONFIG_BUCKET}/${CONFIG_PREFIX}/provisioning/" /etc/grafana/provisioning/ --delete
|
|
aws s3 sync "s3://${CONFIG_BUCKET}/${CONFIG_PREFIX}/dashboards/" /var/lib/grafana/dashboards/ --delete
|
|
chown -R grafana:grafana /etc/grafana/provisioning /var/lib/grafana/dashboards
|
|
}
|
|
mkdir -p /var/lib/grafana/dashboards
|
|
sync_config
|
|
|
|
systemctl daemon-reload
|
|
systemctl enable --now grafana-server
|
|
|
|
# --- systemd timer: re-sync dashboards every 15 min so repo edits land without a rebuild ---
|
|
cat >/usr/local/bin/grafana-config-sync.sh <<SYNC
|
|
#!/bin/bash
|
|
set -euo pipefail
|
|
aws s3 sync "s3://${CONFIG_BUCKET}/${CONFIG_PREFIX}/provisioning/" /etc/grafana/provisioning/ --delete
|
|
aws s3 sync "s3://${CONFIG_BUCKET}/${CONFIG_PREFIX}/dashboards/" /var/lib/grafana/dashboards/ --delete
|
|
chown -R grafana:grafana /etc/grafana/provisioning /var/lib/grafana/dashboards
|
|
SYNC
|
|
chmod +x /usr/local/bin/grafana-config-sync.sh
|
|
|
|
cat >/etc/systemd/system/grafana-config-sync.service <<'SVC'
|
|
[Unit]
|
|
Description=Sync apm-wo Grafana config/dashboards from S3
|
|
[Service]
|
|
Type=oneshot
|
|
ExecStart=/usr/local/bin/grafana-config-sync.sh
|
|
SVC
|
|
|
|
cat >/etc/systemd/system/grafana-config-sync.timer <<'TIMER'
|
|
[Unit]
|
|
Description=Periodic apm-wo Grafana config sync
|
|
[Timer]
|
|
OnBootSec=5min
|
|
OnUnitActiveSec=15min
|
|
[Install]
|
|
WantedBy=timers.target
|
|
TIMER
|
|
|
|
systemctl daemon-reload
|
|
systemctl enable --now grafana-config-sync.timer
|