Skip to content

v5.0.2 — portable Grafana authentication

Latest

Choose a tag to compare

@SAY-5 SAY-5 released this 29 Sep 09:31
8d48f81

v5.0.2 — private observability and portable Grafana authentication

Prometheus and Grafana publish on localhost by default. Grafana's default local
dashboard is an anonymous Viewer: no dashboard writes, basic authentication, or
login form, and no known initial administrator password.

Set FAILSAFE_GRAFANA_REQUIRE_AUTH=1 to require authenticated Grafana on the same
standard localhost address, including on macOS. Supply a unique
FAILSAFE_GRAFANA_ADMIN_PASSWORD of at least 16 characters through the process
environment. Empty, short, or whitespace-only passwords stop authenticated
startup. The flag accepts only 0 or 1; invalid values stop startup too.

Non-loopback Grafana bindings always require authentication, even when the flag
is 0. The README now demonstrates authenticated local startup with a fresh
Compose project rather than an alternate loopback address.

A dedicated CI gate starts the actual Grafana 11.1.0 image through Compose and
tests provisioned resources, read-only anonymous access, authenticated local and
remote-policy modes, literal password handling, and unsafe-startup refusal. It
uses ephemeral loopback host ports and isolated disposable projects. It checks
the Prometheus datasource configuration, not live Prometheus query results.

Upgrade notes

  • Existing anonymous localhost defaults are preserved; authenticated localhost
    requires an explicit opt-in.
  • Stop an older stack if its fixed host ports conflict with a new one.
  • Use a fresh Grafana database for the demonstration. Initial password settings
    do not rotate existing accounts; audit and rotate those credentials explicitly.
  • Use TLS, firewall restrictions, and appropriate identity management before
    network exposure. This demo is not a production security configuration.
  • Gateway traffic, resilience policies, and upstream networking are unchanged.