Skip to main content
See All Integrations

Grafana

Protect self-hosted Grafana dashboards with Pomerium route policy and SSO, then pass a signed identity JWT for seamless Grafana login.

First-party Pomerium integration guide

Category
Cloud Native Tools

Overview

Grafana is an observability dashboard application. Pomerium can protect a self-hosted Grafana route and pass a signed Pomerium identity assertion to Grafana JWT authentication.

Grafana can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Grafana. Grafana remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.

Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.

Route the public HTTPS host to Grafana on port 3000. Enable Pomerium identity headers. Configure Grafana JWT authentication to read X-Pomerium-Jwt-Assertion and validate the Pomerium signing key or JWKS. Keep Grafana private.

Example

An observability team keeps Grafana private. Pomerium route policy limits access to approved engineers. Grafana validates the signed Pomerium JWT and maps the user while it keeps its own role model.

Considerations

  • Grafana roles and data-source permissions remain separate from Pomerium route policy.
  • Grafana auto-sign-up can create a Grafana user for each allowed identity.
  • Grafana JWT authentication does not support refresh tokens.
  • This route protects self-hosted Grafana.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.

Sources and official resources

  • Protect access to Prometheus metrics and administration as an upstream web application.

  • Protect access to Grafana Loki HTTP endpoints as upstream web applications.

  • Protect the Elasticsearch HTTP API while keeping cluster transport traffic on the private network.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo