OpenID for Grafana

This commit is contained in:
2026-04-16 21:47:12 +02:00
parent d19fae8d56
commit edd9368fea
2 changed files with 28 additions and 7 deletions
+12
View File
@@ -117,3 +117,15 @@ identity_providers:
- email
- groups
userinfo_signed_response_alg: 'none'
- id: grafana
description: Grafana via Authelia
secret: '$argon2id$v=19$m=65536,t=3,p=4$IoJjIPmtn81rI0te8lV5Yw$tptaXFfI1NOsPctEzyAYiRblzFNsWgbS9Gh160OkoqQ'
public: false
authorization_policy: one_factor
redirect_uris:
- https://grafana.quangkhai.ch/login/generic_oauth
scopes:
- openid
- profile
- email
userinfo_signed_response_alg: 'none'
+16 -7
View File
@@ -1,8 +1,17 @@
GF_SECURITY_ADMIN_PASSWORD=foobar
GF_USERS_ALLOW_SIGN_UP=false
LETSENCRYPT_HOST=grafana.quangkhai.ch
LETSENCRYPT_EMAIL=quangkhai@grafana.quangkhai.ch
VIRTUAL_HOST=grafana.quangkhai.ch
VIRTUAL_PORT=3000
GF_SERVER_DOMAIN=grafana.quangkhai.ch
GF_SERVER_ROOT_URL=https://grafana.quangkhai.ch
GF_AUTH_ANONYMOUS_ENABLED=false
GF_AUTH_DISABLE_LOGIN_FORM=true
GF_AUTH_GENERIC_OAUTH_ENABLED=true
GF_AUTH_GENERIC_OAUTH_NAME=Authelia
GF_AUTH_GENERIC_OAUTH_ALLOW_SIGN_UP=false
GF_AUTH_GENERIC_OAUTH_CLIENT_ID=grafana
GF_AUTH_GENERIC_OAUTH_CLIENT_SECRET=<grafana-client-secret-raw>
GF_AUTH_GENERIC_OAUTH_SCOPES=openid profile email
GF_AUTH_GENERIC_OAUTH_AUTH_URL=https://auth.quangkhai.ch/api/oidc/authorization
GF_AUTH_GENERIC_OAUTH_TOKEN_URL=https://auth.quangkhai.ch/api/oidc/token
GF_AUTH_GENERIC_OAUTH_API_URL=https://auth.quangkhai.ch/api/oidc/userinfo
GF_AUTH_GENERIC_OAUTH_EMAIL_ATTRIBUTE=email
GF_AUTH_GENERIC_OAUTH_NAME_ATTRIBUTE=name