Documentation
Grafana
Sign in to Grafana with Halo through Grafana's generic OAuth support, and give people Grafana roles based on their Halo groups.
The examples use https://auth.example.com for Halo and https://grafana.example.com for Grafana.
Register Grafana in Halo
-
In the console, open Applications and choose Add application.
-
Choose OpenID Connect and Continue.
-
Choose Web application and the Grafana template, then Continue.
-
Check the redirect URI and change the host to your Grafana address:
https://grafana.example.com/login/generic_oauth -
Choose Create application, and copy the client ID and the client secret. Halo shows the secret only once.
-
Choose Open application, go to Users & groups, choose Assign group, and pick the groups whose members may use Grafana.
The application page in the console shows the same configuration as below with your client ID filled in, under View setup guide right after creation and on the application's overview.
Configure Grafana
-
Save the client secret to a file that only Grafana can read:
printf '%s' 'hls_…' | sudo tee /etc/grafana/halo-client-secret > /dev/null sudo chown grafana:grafana /etc/grafana/halo-client-secret sudo chmod 600 /etc/grafana/halo-client-secret -
Add this block to
grafana.ini, with your client ID:[auth.generic_oauth] enabled = true name = Halo allow_sign_up = true client_id = hl_… client_secret = $__file{/etc/grafana/halo-client-secret} scopes = openid profile email groups auth_url = https://auth.example.com/oauth2/authorize token_url = https://auth.example.com/oauth2/token api_url = https://auth.example.com/oauth2/userinfo use_pkce = true groups_attribute_path = groups role_attribute_path = contains(groups[*], 'Grafana editors') && 'Editor' || 'Viewer' -
Make sure
root_urlin the[server]section is Grafana's public address. Grafana builds the redirect URI from it, and it must match the one registered in Halo:[server] root_url = https://grafana.example.com -
Restart Grafana. The sign-in page now shows Sign in with Halo.
$__file{…} makes Grafana read the secret from the file instead of keeping it in grafana.ini.
Map groups to Grafana roles
Halo's groups claim lists the names of all of the person's groups. role_attribute_path is a JMESPath expression over the claims: in the block above, members of the Halo group Grafana editors become editors and everyone else becomes a viewer.
To make another group administrators, put it first:
role_attribute_path = contains(groups[*], 'Grafana admins') && 'Admin' || contains(groups[*], 'Grafana editors') && 'Editor' || 'Viewer'
Use the group names exactly as they appear in Halo's console. Grafana updates the role every time the person signs in.
Check it
Open Grafana in a private window and choose Sign in with Halo. After you sign in to Halo, Grafana opens with your name and the role from your groups. The sign-in appears in Halo's console under Sign-in logs.
If Halo shows "You don't have access to this application", assign one of your groups to the application. For other errors, see troubleshooting.