DE 

//Cloudogu EcoSystem Docs

The Grafana CARP

Grafana authentication runs via a so-called CARP, which stands for Cas-Authentication-Reverse-Proxy. The way the CARP works is that it runs as a proxy server in front of Grafana and takes over cas authentication. If /grafana is accessed, the CARP takes over at this point. This forwards to the Cas, evaluates the service ticket or, if you are already authenticated, forwards the request to Grafana.

Grafana itself implements the proxy authentication: https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/auth-proxy/ The CARP uses this feature to authenticate. A header with the corresponding user name is simply user name when forwarding the request to Grafana.

The CARP also replicates accounts, groups (teams) and authorizations. This is done by requests are sent to Grafana's Rest API. In principle, Grafana would also have offered authorization and team (group) replication, but only in the Premium version, which we are not using here.

Grafana itself also supports other authentication methods, but during testing these proved to be less advantageous than the CARP.

Our previously built CARP was used as the basis for the CARP: https://github.com/cloudogu/carp Since its functionality had to be extended for Grafana, we decided not to use it as a dependency, but as a fork instead.

Start Carp locally

To debug the Grafana CARP locally, it can be started locally and connected to a local Grafana. For this to work, you must first run docker login (using credentials from our Harbor) so that the Docker images can be pulled outside of CES.

In addition, CAS must be switched to development mode by setting an ETCD key and restarting CAS: etcdctl set config/_global/stage development; cesapp restart cas

After that, Grafana can be built and started locally. This can be done with the following command from the project root directory: make grafana-local If needed, Grafana can be removed again with make stop-grafana-local.

Afterwards, Carp can be started locally with: cd grafana-carp && go run .

Grafana is now available locally at http://localhost:8080

At the moment, the Grafana CARP can only be used locally with a Classic CES.

Customize ports

The Carp always runs locally under port 8080 and the corresponding local Grafana under port 3000. If it is not possible to use these ports, the following files must be adapted (see comments in the files):

  • Makefile (grafana-local target)
  • dev.ini
  • grafana-carp/carp.yml