You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: docs/admin/observability/metrics.mdx
+30-2Lines changed: 30 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -82,8 +82,36 @@ sshuttle -r user@host 0/0
82
82
83
83
Grafana will be available at http://host:3370/-/debug/grafana.
84
84
85
-
> WARNING: Our Grafana instance runs in anonymous mode with all authentication turned off, since we rely on Sourcegraph's built-in authentication.
86
-
> Please be careful when exposing it directly to external traffic.
85
+
### Grafana Security
86
+
87
+
<Callouttype="warning">
88
+
WARNING: By default, our Grafana container runs in anonymous mode with authentication disabled, relying on Sourcegraph's authentication and authorization when accessed through your Sourcegraph instance.
89
+
90
+
We recommend you use your network security controls to prevent access to Grafana's listening ports, or enable Grafana's builtin authentication.
91
+
</Callout>
92
+
93
+
To enable Grafana's builtin authentication, configure the `GF_AUTH_ANONYMOUS_ENABLED` environment variable to `false` in the Grafana container's environment variables in your deployment override file.
94
+
95
+
We also recommend that you customize the default admin username and password by configuring the `GF_SECURITY_ADMIN_USER` and `GF_SECURITY_ADMIN_PASSWORD` environment variables, using your secrets management tool in your deployment pipeline.
0 commit comments