A Grafana that Reads as Its Identity, Privately, without API Keys
API keys are long-lived, unscoped bearer tokens that read every dashboard and end up in CI variables; the login page is public by default; and the Essential SKU is a single instance with no SLA. Keys off, login over a private endpoint, Standard SKU zone-redundant, fixed outbound addresses for data-source allow lists, and the identity it reads with exported for its Monitoring Reader grant.
Verification
Static-verifiedPassed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).
Conformance
- Static validation (fmt · validate · tflint)
- No applicable security policies for this provider
- Plan tests (mocked: validation rules · outputs)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live test pending (no cloud run yet)
Last verified 2026-09-14 · how we verify
Use it from the registry
terraform · opentofumodule "grafana" {
source = "www.iac-bazaar.com/iac-bazaar/azure-grafana/azure"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
azure-grafana
An Azure Managed Grafana that reads through its identity, off the public
internet, without API keys. Works with Terraform and OpenTofu
(>= 1.6), azurerm provider >= 4.0, < 5.0.
api_key_enabled is a bearer token that reads every dashboard. Off
here; on needs accept_api_keys.
The endpoint is public by default. Off here, reached over a private
endpoint; on needs accept_public_endpoint.
The identity is how it reads. Grant principal_id Monitoring Reader
on what it charts, or the panels are empty.
Standard SKU for an SLA; Essential needs accept_no_sla.
Verification
Static validation runs tofu fmt, init, validate, tflint and checkov.
This module has not yet had a live test, so it is published as statically
validated with its live test pending and does not carry the live-tested mark.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
Related modules
azure-sentinel
retention_in_days defaults to 30, against intrusions usually discovered months later - so the first question, when did this start, gets silence rather than an answer. daily_quota_gb is a trap both ways and has no safe default, so the module makes you choose. And onboarding Sentinel connects no data source at all.
azure-monitor-baseline
Central Log Analytics workspace, diagnostic-settings-everywhere pattern, action groups and starter alert pack (metric + log + activity).
azure-flow-logs
enabled = false creates a flow log that logs nothing; a retention policy that is off keeps the JSON blobs until somebody deletes the storage account; and without Traffic Analytics nobody ever opens them. Every target is created enabled, retention defaults to 90 days, and Traffic Analytics is on whenever a workspace is given - raw blobs with no aggregation have to be asked for.
azure-application-insights
When the daily cap is hit everything after it is discarded until midnight and the dashboard goes flat, and the one email that says so has its own switch. Ingestion sampling stacks on the SDK's sampling and the metrics rescale. Both are refused without being named, and availability tests are created with the alerts that make an outage reach a person rather than a chart.