Grafana
Protect self-hosted Grafana dashboards with Pomerium route policy and SSO, then pass a signed identity JWT for seamless Grafana login.
Overview
Grafana is an observability dashboard application. Pomerium can protect a self-hosted Grafana route and pass a signed Pomerium identity assertion to Grafana JWT authentication.
Grafana can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Grafana. Grafana remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.
Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.
Route the public HTTPS host to Grafana on port 3000. Enable Pomerium identity headers. Configure Grafana JWT authentication to read X-Pomerium-Jwt-Assertion and validate the Pomerium signing key or JWKS. Keep Grafana private.
Example
An observability team keeps Grafana private. Pomerium route policy limits access to approved engineers. Grafana validates the signed Pomerium JWT and maps the user while it keeps its own role model.
Considerations
- Grafana roles and data-source permissions remain separate from Pomerium route policy.
- Grafana auto-sign-up can create a Grafana user for each allowed identity.
- Grafana JWT authentication does not support refresh tokens.
- This route protects self-hosted Grafana.
- Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.
Sources and official resources
- Grafana OSSOfficial website
- Grafana JWT authenticationOfficial documentation
- Run Grafana behind a proxyPrimary source
- Grafana repositoryOfficial repository
- Secure Grafana with PomeriumPomerium documentation
- Pomerium HTTP and WebSocket routingPomerium documentation
- Pomerium route timeoutsPomerium documentation
- Pomerium TCP connection behaviorPomerium documentation
