skills/ grafana/skills

grafana-oss

Configure Grafana OSS — provisions dashboards from YAML, sets up data sources (Prometheus / Loki / Tempo / Pyroscope), writes dashboard JSON with template variables, builds panel queries, assigns built-in roles (Viewer / Editor / Admin / GrafanaAdmin), mints service-account tokens, edits grafana.ini

0
Installs
—
Rating
—
Success rate
9
Files scanned
Scan passedtooling
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

9 files scannedscanner v1.2.0Oct 10, 2026

Content sha256 0776013fbd6b5828… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Grafana OSS

Docs: https://grafana.com/docs/grafana/latest.md

Common Workflows

Provisioning dashboards from disk

  1. Drop dashboard JSON file(s) under /var/lib/grafana/dashboards/
  2. Add a provider in provisioning/dashboards/default.yaml (see § Dashboard provisioning below)
  3. Restart Grafana so the provider config is loaded
  4. Verify the dashboard landed:
    curl https://grafana.example.com/api/dashboards/uid/<uid> \
      -H "Authorization: Bearer <token>" | jq '.dashboard.title'
    
    Returns the title → success. 404 → provisioning didn't pick it up; check Grafana server logs (journalctl -u grafana-server | grep -i provisioning) for parse errors.

Provisioning data sources

  1. Write provisioning/datasources/datasources.yaml (see § Data source provisioning below)
  2. Restart Grafana
  3. Health-check the data source via API:
    curl https://grafana.example.com/api/datasources/uid/<uid>/health \
      -H "Authorization: Bearer <token>"
    # { "status": "OK", "message": "..." } → working
    # { "status": "ERROR", ... } → URL unreachable or auth misconfigured
    

Creating a service account + token

  1. Provision via YAML or POST /api/serviceaccounts (full API in references/api.md § Users + service accounts)
  2. Mint a token via POST /api/serviceaccounts/{id}/tokens
  3. Verify the token works:
    curl https://grafana.example.com/api/org \
      -H "Authorization: Bearer <new-token>"
    # 200 + org JSON → token + role assignment work
    # 401 → token wrong; 403 → role wrong
    

Dashboard provisioning

# provisioning/dashboards/default.yaml
apiVersion: 1
providers:
  - name: default
    folder: MyFolder
    type: file
    disableDeletion: false
    updateIntervalSeconds: 30
    options:
      path: /var/lib/grafana/dashboards
      foldersFromFilesStructure: true

For the dashboard JSON shape itself (panels, queries, template variables), see references/dashboard-json.md.

Data source provisioning

# provisioning/datasources/datasources.yaml
apiVersion: 1
datasources:
  - name: Prometheus
    type: prometheus
    access: proxy
    url: http://prometheus:9090
    isDefault: true
    jsonData:
      timeInterval: 15s
      httpMethod: POST

  - name: Loki
    type: loki
    access: proxy
    url: http://loki:3100

  - name: Tempo
    type: tempo
    access: proxy
    url: http://tempo:3200
    jsonData:
      tracesToLogsV2:
        datasourceUid: loki_uid
        tags: [{ key: "service.name", value: "app" }]
      serviceMap:
        datasourceUid: prometheus_uid
      nodeGraph:
        enabled: true

  - name: Pyroscope
    type: grafana-pyroscope-datasource
    url: http://pyroscope:4040

RBAC (built-in roles)

RolePermissions
ViewerRead dashboards, alerts
EditorCreate/edit dashboards, alerts
AdminManage data sources, users, plugins
GrafanaAdminServer-wide admin (superuser)

Service-account provisioning:

# provisioning/access-control/service_accounts.yaml
apiVersion: 1
serviceAccounts:
  - name: ci-reader
    orgId: 1
    role: Viewer
    tokens:
      - name: ci-token
        # expires: optional ISO 8601 timestamp; omit for no-expiry tokens

(Custom RBAC roles with fine-grained permissions are Enterprise / Cloud only — see the grafana-cloud/admin skill if you need those.)

Plugin provisioning

# provisioning/plugins/plugins.yaml
apiVersion: 1
apps:
  - type: grafana-pyroscope-app
    disabled: false
    jsonData:
      backendUrl: http://pyroscope:4040

After restart, verify via GET /api/plugins/<plugin-id>/health.

References

  • references/dashboard-json.md — full dashboard JSON model + template variables + common problems (uid uniqueness, gridPos arithmetic, datasource uid matching)
  • references/dashboards.md — dashboard workflows, settings, variables, annotations, sharing, versions, playlists, and provisioning-as-code
  • references/datasources.md — data source setup and query examples for Prometheus, Loki, Tempo, SQL, CloudWatch, and plugins
  • references/panel-types.md — panel-type table + decision guide for picking the right one
  • references/panels.md — panel editor, visualization options, field config, transformations, query options, inspection, and performance tips
  • references/alerting.md — alerting concepts, contact points, notification policies, templates, silences, and common rule examples
  • references/api.md — full Grafana OSS API reference (dashboards, data sources, users, service accounts, annotations) with verification curls and common failure modes
  • references/config.md — grafana.ini server / database / SMTP / auth / security / feature-toggle config + restart-required issues

Files

9
51.7 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from grafana/skills8

adaptive-metrics

Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config, unused-metric detection, and Alloy remote_write fallback. Use when investigating a high Mimir/Grafana Cloud

Scan passed 0
admin

Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning. Creates stacks via the Cloud API, mints service-account tokens, applies role assignments, configures

Scan passed 0
admission-control

Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to validate or mutate re

Scan passed 0
alerting-irm

Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook), notification policies with hierarchical matchers, silences, mute timings, on-call schedules and escala

Scan passed 0
alloy

Build a unified telemetry pipeline with Grafana Alloy — one OpenTelemetry-compatible binary that collects metrics, logs, traces, and profiles and ships to Grafana Cloud / Prometheus / Loki / Tempo / Pyroscope. Covers the Alloy config language (blocks, `sys.env`, component refs), `prometheus.scrape`

Scan passed 0
app-observability

Get RED metrics + service maps + frontend RUM + AI/LLM monitoring out of Grafana Cloud — Application Observability (`traces_spanmetrics_*` from OTel traces, p50/p95/p99 latency, exemplar-to-trace, traces-to-logs / profiles), Frontend Observability with the Faro Web SDK (Core Web Vitals, session repl

Needs review 0
app-sdk-concepts

Use when starting any grafana-app-sdk work — scaffolding a Grafana app, initializing a Grafana App Platform app, picking a deployment mode (standalone operator / grafana/apps / frontend-only), wiring app-specific config, or onboarding to the SDK. Covers `grafana-app-sdk` CLI install, `project init`

Scan passed 0
assistant-mcp

Connect AI coding agents (Claude Code, Cursor, VS Code, OpenAI Codex) to Grafana Cloud via the `mcp-grafana` Model Context Protocol server. Installs the server with `go install`, generates a Grafana service-account token, wires `~/.claude/settings.json` or `~/.cursor/mcp.json` with the `command` + `

Scan passed 0

Related tooling skillsscan passed