v5.0.2 — private observability and portable Grafana authentication
Prometheus and Grafana publish on localhost by default. Grafana's default local
dashboard is an anonymous Viewer: no dashboard writes, basic authentication, or
login form, and no known initial administrator password.
Set FAILSAFE_GRAFANA_REQUIRE_AUTH=1 to require authenticated Grafana on the same
standard localhost address, including on macOS. Supply a unique
FAILSAFE_GRAFANA_ADMIN_PASSWORD of at least 16 characters through the process
environment. Empty, short, or whitespace-only passwords stop authenticated
startup. The flag accepts only 0 or 1; invalid values stop startup too.
Non-loopback Grafana bindings always require authentication, even when the flag
is 0. The README now demonstrates authenticated local startup with a fresh
Compose project rather than an alternate loopback address.
A dedicated CI gate starts the actual Grafana 11.1.0 image through Compose and
tests provisioned resources, read-only anonymous access, authenticated local and
remote-policy modes, literal password handling, and unsafe-startup refusal. It
uses ephemeral loopback host ports and isolated disposable projects. It checks
the Prometheus datasource configuration, not live Prometheus query results.
Upgrade notes
- Existing anonymous localhost defaults are preserved; authenticated localhost
requires an explicit opt-in. - Stop an older stack if its fixed host ports conflict with a new one.
- Use a fresh Grafana database for the demonstration. Initial password settings
do not rotate existing accounts; audit and rotate those credentials explicitly. - Use TLS, firewall restrictions, and appropriate identity management before
network exposure. This demo is not a production security configuration. - Gateway traffic, resilience policies, and upstream networking are unchanged.