Deployment Overview of Grafana on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the following requirements must be met:
-
Operating System: Debian, Ubuntu, CentOS, Rocky Linux, or AlmaLinux.
-
Privileges: Root or sudo access is required for package installation and Docker management.
-
Ports:
-
80/tcp(HTTP) -
443/tcp(HTTPS) -
22/tcp(SSH) -
3000/tcp(Internal Grafana access)
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | grafana |
| Domain | hostkey.in |
| Full template | grafana{Server_ID_from_Invapi}.hostkey.in |
File and Directory Structure¶
The deployment utilizes the following directory structure for configuration and data persistence:
-
/root/grafana: Contains the application orchestration files (compose.yml). -
/data/nginx/user_conf.d/: Stores Nginx proxy configurations. -
/data/nginx/nginx-certbot.env: Environment variables for the SSL certificate management service. -
/data/grafana/datasources: Directory used for provisioning Grafana data sources.
Application installation process¶
The application is deployed using a combination of system configuration and Docker orchestration:
-
System Preparation: The installer identifies the operating system to configure the firewall (UFW on Debian/Ubuntu or Firewalld on RHEL-based systems) to allow HTTP, HTTPS, and SSH traffic.
-
Docker Environment Setup: Docker is installed if not already present, and a dedicated Docker volume named
grafana-datais created for persistent storage. -
Orchestration Deployment: The application is deployed using Docker Compose located in
/root/grafana/compose.yml. -
Security Configuration: Upon container startup, the administrator password for the default
adminuser is automatically reset via the Grafana CLI within the running container to ensure secure access.
Access Rights and Security¶
-
Firewall: The system is configured to allow incoming traffic on ports 80 (HTTP) and 443 (HTTPS).
-
SSL/TLS: SSL certificates are managed via a dedicated Nginx container using Certbot for automated certificate acquisition and renewal.
-
Container Isolation: Services run within isolated Docker containers with specific restart policies (
unless-stopped).
Databases¶
Grafana uses an internal database by default, but data persistence is maintained through the following mechanism:
-
Storage Location: Persistent data is stored in a Docker volume named
grafana-data. -
Provisioning: Custom data source configurations are mounted from
/data/grafana/datasourcesto/etc/grafana/provisioning/datasources.
Docker Containers and Their Deployment¶
The deployment consists of two primary containers:
Nginx Certbot Container¶
-
Image:
jonasal/nginx-certbot:latest -
Ports:
-
80:80 -
443:443 -
Volumes:
-
nginx_secrets:/etc/letsencrypt(SSL certificates) -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d(Proxy configurations) -
Environment Variables:
Grafana Container¶
-
Image:
grafana/grafana-oss:8.2.6 -
Ports:
3000:3000 -
Volumes:
-
/data/grafana/datasources:/etc/grafana/provisioning/datasources -
grafana-data:/var/lib/grafana(Persistent application data) -
Restart Policy:
unless-stopped
Application Update Instructions¶
To update the Grafana application, navigate to the deployment directory and pull the latest images defined in the configuration:
Location of configuration files and data¶
| Component | Path |
|---|---|
| Docker Compose File | /root/grafana/compose.yml |
| Grafana Persistent Data | grafana-data (Docker Volume) |
| Nginx Configuration | /data/nginx/user_conf.d/ |
| Data Source Configs | /data/grafana/datasources |
Available ports for connection¶
-
HTTPS:
443(External access via proxy) -
HTTP:
80(For SSL certificate challenges) -
Grafana Internal:
3000(Direct container access)
Starting and Stopping the application¶
The application is managed using Docker Compose commands from the /root/grafana directory:
-
Start the application:
-
Stop the application: