Grafana
This guide explains how to configure Single Sign-On (SSO) between SmartLink and Grafana using OpenID Connect. Grafana offers excellent native support for OAuth2/OpenID Connect.
Prerequisites
- Grafana version 7.0 or higher
- Administrator access to Grafana
- Application configured in SmartLink with OpenID Connect
- HTTPS configured on Grafana (recommended)
Configuration in SmartLink
1. Create the application
- Log in to SmartLink as an administrator
- Go to Applications → Add
- Create a new application:
- Name: Grafana
- URL:
https://grafana.example.com - Description: Monitoring and observability platform
- Icon: Choose the Grafana icon
2. Configure OpenID Connect
- In the Authentication tab
- Select OpenID Connect
- Note the information:
- Client ID:
grafana-xxxxxx - Client Secret:
secret-xxxxxx - Issuer URL:
https://votre-smartlink.link.vaultys.org/api/oidc/[appid] - App ID:
[appid](unique application identifier in SmartLink)
- Client ID:
3. Redirect URLs
Add to Allowed Redirect URLs:
https://grafana.example.com/login/generic_oauth
4. Scopes and Claims
Required scopes:
openidprofileemailgroups(for role mapping)
Configuration in Grafana
1. Configuration via INI file
Edit /etc/grafana/grafana.ini or /conf/grafana.ini:
#################################### Auth ####################################
[auth]
# Disable account creation via interface
disable_login_form = false
disable_signout_menu = false
# OAuth auto login
oauth_auto_login = true
# Automatic team synchronization
oauth_allow_insecure_email_lookup = false
#################################### Generic OAuth ##########################
[auth.generic_oauth]
enabled = true
name = SmartLink SSO
allow_sign_up = true
auto_login = false
client_id = grafana-xxxxxx
client_secret = secret-xxxxxx
scopes = openid profile email groups
email_attribute_name = email
email_attribute_path = email
login_attribute_path = email
name_attribute_path = name
groups_attribute_path = groups
role_attribute_path = contains(groups[*], 'grafana-admins') && 'Admin' || contains(groups[*], 'grafana-editors') && 'Editor' || 'Viewer'
role_attribute_strict = false
allow_assign_grafana_admin = true
auth_url = https://votre-smartlink.link.vaultys.org/api/oidc/[appid]/authorize
token_url = https://votre-smartlink.link.vaultys.org/api/oidc/[appid]/token
api_url = https://votre-smartlink.link.vaultys.org/api/oidc/[appid]/userinfo
signout_redirect_url = https://votre-smartlink.link.vaultys.org/logout
use_pkce = true
use_refresh_token = true
# Team mapping (optional)
team_ids_attribute_path = groups
teams_url = https://votre-smartlink.link.vaultys.org/api/teams
2. Configuration via environment variables
For Docker or Kubernetes:
version: '3.8'
services:
grafana:
image: grafana/grafana:latest
environment:
# OAuth configuration
- GF_AUTH_GENERIC_OAUTH_ENABLED=true
- GF_AUTH_GENERIC_OAUTH_NAME=SmartLink SSO
- GF_AUTH_GENERIC_OAUTH_ALLOW_SIGN_UP=true
- GF_AUTH_GENERIC_OAUTH_CLIENT_ID=grafana-xxxxxx
- GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET=secret-xxxxxx
- GF_AUTH_GENERIC_OAUTH_SCOPES=openid profile email groups
- GF_AUTH_GENERIC_OAUTH_EMAIL_ATTRIBUTE_NAME=email
- GF_AUTH_GENERIC_OAUTH_EMAIL_ATTRIBUTE_PATH=email
- GF_AUTH_GENERIC_OAUTH_LOGIN_ATTRIBUTE_PATH=email
- GF_AUTH_GENERIC_OAUTH_NAME_ATTRIBUTE_PATH=name
- GF_AUTH_GENERIC_OAUTH_AUTH_URL=https://votre-smartlink.link.vaultys.org/api/oidc/[appid]/authorize
- GF_AUTH_GENERIC_OAUTH_TOKEN_URL=https://votre-smartlink.link.vaultys.org/api/oidc/[appid]/token
- GF_AUTH_GENERIC_OAUTH_API_URL=https://votre-smartlink.link.vaultys.org/api/oidc/[appid]/userinfo
- GF_AUTH_GENERIC_OAUTH_USE_PKCE=true
# Auto login
- GF_AUTH_OAUTH_AUTO_LOGIN=true
# Disable anonymous authentication
- GF_AUTH_ANONYMOUS_ENABLED=false
ports:
- "3000:3000"
volumes:
- grafana-data:/var/lib/grafana
volumes:
grafana-data:
3. Helm Configuration (Kubernetes)
# values.yaml for Grafana chart
grafana:
grafana.ini:
auth:
oauth_auto_login: true
auth.generic_oauth:
enabled: true
name: SmartLink SSO
allow_sign_up: true
client_id: grafana-xxxxxx
client_secret: secret-xxxxxx
scopes: openid profile email groups
auth_url: https://votre-smartlink.link.vaultys.org/api/oidc/[appid]/authorize
token_url: https://votre-smartlink.link.vaultys.org/api/oidc/[appid]/token
api_url: https://votre-smartlink.link.vaultys.org/api/oidc/[appid]/userinfo
role_attribute_path: |
contains(groups[*], 'grafana-admins') && 'Admin' ||
contains(groups[*], 'grafana-editors') && 'Editor' ||
'Viewer'
Role and Permission Management
Automatic Role Mapping
Grafana supports three main roles: Admin, Editor, and Viewer.
Basic Configuration
# Default role for new users
[auth.generic_oauth]
role_attribute_path = contains(groups[*], 'grafana-admins') && 'Admin' || contains(groups[*], 'grafana-editors') && 'Editor' || 'Viewer'
Advanced Configuration with JMESPath
# Complex mapping based on multiple attributes
role_attribute_path = |
(contains(groups[*], 'grafana-super-admins') || email == '[email protected]') && 'GrafanaAdmin' ||
contains(groups[*], 'grafana-admins') && 'Admin' ||
contains(groups[*], 'grafana-editors') && 'Editor' ||
contains(groups[*], 'grafana-viewers') && 'Viewer' ||
'Viewer'