From 3ccc7e784a0ed5b19910ab856f6d9774a6f27956 Mon Sep 17 00:00:00 2001 From: Kleidi Bujari Date: Sat, 23 Nov 2024 16:36:43 -0500 Subject: Initial scaffolding and layout Set up the modules of the flake. At this time, the flake is split into modules and machines. Considering that additional top-level sections -- such as packages and shells -- will also be added, it might make sense to keep all nix related things in one top-level directory, alongside the flake.nix file. This is all under the assumption that later amendments to the project will introduce other tech, such as terraform. --- modules/xnet/monitoring/grafana.nix | 51 +++++++++++++++++++++++++++++++++++++ 1 file changed, 51 insertions(+) create mode 100644 modules/xnet/monitoring/grafana.nix (limited to 'modules/xnet/monitoring/grafana.nix') diff --git a/modules/xnet/monitoring/grafana.nix b/modules/xnet/monitoring/grafana.nix new file mode 100644 index 0000000..6a37ce1 --- /dev/null +++ b/modules/xnet/monitoring/grafana.nix @@ -0,0 +1,51 @@ +{ config, pkgs, ... }: { + services.grafana.provision = { + enable = true; + datasources.settings.datasources = [{ + name = "Prometheus"; + type = "prometheus"; + url = "http://localhost:9090"; + access = "proxy"; + editable = false; + }]; + + dashboards.settings.providers = [{ + name = "Fetched Dashboards"; + options.path = "/etc/grafana/dashboards"; + }]; + }; + + environment.etc = { + "grafana/dashboards/node-exporter.json" = { + user = "grafana"; + group = "grafana"; + source = pkgs.fetchurl { + url = "https://grafana.com/api/dashboards/1860/revisions/37/download"; + hash = "sha256-1DE1aaanRHHeCOMWDGdOS1wBXxOF84UXAjJzT5Ek6mM="; + }; + }; + }; + + services.grafana = { + enable = true; + settings.server = { + domain = "grafana.web.4kb.net"; + protocol = "socket"; + }; + settings."auth.anonymous" = { + enabled = true; + org_role = "Admin"; + }; + }; + + users.groups.grafana.members = [ "nginx" ]; + systemd.services.nginx.serviceConfig.ProtectHome = false; + + services.nginx.virtualHosts."${config.services.grafana.settings.server.domain}" = { + useACMEHost = "4kb.net"; + addSSL = true; + locations."/" = { + proxyPass = "http://unix:/${toString config.services.grafana.settings.server.socket}"; + }; + }; +} -- cgit v1.3.1