grafana azure oauth config
continuous-integration/drone/push Build is passing Details

This commit is contained in:
Philipp Glaum 2023-07-14 11:03:15 +02:00
parent e3b120464a
commit e56120b82c
2 changed files with 25 additions and 0 deletions

View File

@ -27,7 +27,12 @@ services:
grafana: grafana:
image: grafana/grafana-oss image: grafana/grafana-oss
volumes: volumes:
- lgtm-config:/lgtm-config
- grafana-data:/var/lib/grafana - grafana-data:/var/lib/grafana
environment:
GF_AUTH_AZUREAD_CLIENT_ID: ${GF_AUTH_AZUREAD_CLIENT_ID}
GF_AUTH_AZUREAD_CLIENT_SECRET: ${GF_AUTH_AZUREAD_CLIENT_SECRET}
GF_PATHS_CONFIG: "/lgtm-config/lgtm-stack/grafana.ini"
restart: unless-stopped restart: unless-stopped
user: '0' user: '0'
networks: networks:

20
grafana.ini Normal file
View File

@ -0,0 +1,20 @@
[auth.azuread]
name = Azure AD
enabled = true
allow_sign_up = true
auto_login = false
#client_id = APPLICATION_ID
#client_secret = CLIENT_SECRET
scopes = openid email profile offline_access
auth_url = https://login.microsoftonline.com/0a651be1-a772-4af3-aab3-a1d57dae5965/oauth2/v2.0/authorize
token_url = https://login.microsoftonline.com/0a651be1-a772-4af3-aab3-a1d57dae5965/oauth2/v2.0/token
allowed_domains =
allowed_groups =
allowed_organizations = 0a651be1-a772-4af3-aab3-a1d57dae5965
role_attribute_strict = false
allow_assign_grafana_admin = false
skip_org_role_sync = false
use_pkce = true
[server]
root_url = https://dev-grafana.sinetcon.com