skills/ grafana/skills

private-connectivity

Set up private network connectivity to Grafana Cloud — AWS PrivateLink, Azure Private Link, GCP Private Service Connect, and Private Data Source Connect (PDC). Provisions VPC endpoints, private endpoints, or PSC forwarding rules per signal type (metrics / logs / traces / profiles); wires Alloy to pu

0
Installs
—
Rating
—
Success rate
3
Files scanned
Scan passeddevops
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

3 files scannedscanner v1.2.0Oct 11, 2026

Content sha256 c9938e2c5b0b1550… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Grafana Cloud Private Connectivity

Docs: https://grafana.com/docs/grafana-cloud/send-data/

Send metrics, logs, traces, and profiles to Grafana Cloud entirely over your cloud provider's private backbone — no public internet exposure, no egress fees.

Common Workflows

Setting up AWS PrivateLink (most common)

  1. Find your service names. Grafana Cloud → Stack Details → "Send using AWS PrivateLink". Note one service name per signal type (metrics / logs / traces / profiles).

  2. Create an Interface VPC Endpoint per signal type:

    aws ec2 create-vpc-endpoint \
      --vpc-id vpc-12345 \
      --service-name com.amazonaws.vpce.us-east-1.vpce-svc-0abc123 \
      --vpc-endpoint-type Interface \
      --subnet-ids subnet-12345 \
      --security-group-ids sg-12345 \
      --private-dns-enabled
    
  3. Verify private DNS resolves (CRITICAL — if this returns a public IP, Alloy will silently keep using the public path and you'll keep paying egress):

    dig +short prometheus-private.us-east-0.grafana.net
    # Expected: a 10.x.x.x / 172.16-31.x.x / 192.168.x.x address
    # Public IP returned → check `private_dns_enabled = true` was set and the VPC has DNS hostnames enabled
    
  4. Update Alloy to use the private endpoint:

    prometheus.remote_write "cloud_private" {
      endpoint {
        url = "https://prometheus-private.us-east-0.grafana.net/api/prom/push"
        basic_auth {
          username = sys.env("PROM_USER")
          password = sys.env("GRAFANA_CLOUD_API_KEY")
        }
      }
    }
    
    loki.write "cloud_private" {
      endpoint {
        url = "https://logs-private.us-east-0.grafana.net/loki/api/v1/push"
        basic_auth {
          username = sys.env("LOKI_USER")
          password = sys.env("GRAFANA_CLOUD_API_KEY")
        }
      }
    }
    
  5. Confirm traffic is flowing over PrivateLink: check the VPC endpoint's CloudWatch metrics for BytesProcessed after Alloy starts pushing.

Full Terraform + per-signal-type endpoint resources in references/aws.md.

Setting up Azure Private Link / GCP Private Service Connect

Different provider, same shape: create the private endpoint → wait for approval → verify private DNS → update Alloy URLs. Full CLI + verification steps in references/azure-gcp.md.

Azure-specific prereq: Pre-register your Subscription IDs with Grafana Support before starting — without this the endpoint creation hangs at "Pending".

Prerequisites (all providers)

  • Grafana Cloud stack must be hosted on the same cloud provider (check: My Account → Stack → Details)
  • Create separate private endpoints for each signal type (metrics / logs / traces / profiles) — they have distinct service names
  • Same region only for AWS PrivateLink. Cross-region requires VPC peering first.

Choosing the right option

ScenarioSolution
Push from AWSAWS PrivateLink
Push from AzureAzure Private Link
Push from GCPGCP Private Service Connect
Query private DB / Prometheus from GrafanaPrivate Data Source Connect (PDC) — see references/azure-gcp.md § PDC

References

  • references/aws.md — full AWS PrivateLink Terraform per signal type + endpoint verification (state + DNS)
  • references/azure-gcp.md — Azure Private Link + GCP Private Service Connect setup (Portal + CLI) + verification + Private Data Source Connect (PDC) for reverse-direction private data source queries

Files

3
8.1 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from grafana/skills8

adaptive-metrics

Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config, unused-metric detection, and Alloy remote_write fallback. Use when investigating a high Mimir/Grafana Cloud

Scan passed 0
admin

Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning. Creates stacks via the Cloud API, mints service-account tokens, applies role assignments, configures

Scan passed 0
admission-control

Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to validate or mutate re

Scan passed 0
alerting-irm

Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook), notification policies with hierarchical matchers, silences, mute timings, on-call schedules and escala

Scan passed 0
alloy

Build a unified telemetry pipeline with Grafana Alloy — one OpenTelemetry-compatible binary that collects metrics, logs, traces, and profiles and ships to Grafana Cloud / Prometheus / Loki / Tempo / Pyroscope. Covers the Alloy config language (blocks, `sys.env`, component refs), `prometheus.scrape`

Scan passed 0
app-observability

Get RED metrics + service maps + frontend RUM + AI/LLM monitoring out of Grafana Cloud — Application Observability (`traces_spanmetrics_*` from OTel traces, p50/p95/p99 latency, exemplar-to-trace, traces-to-logs / profiles), Frontend Observability with the Faro Web SDK (Core Web Vitals, session repl

Needs review 0
app-sdk-concepts

Use when starting any grafana-app-sdk work — scaffolding a Grafana app, initializing a Grafana App Platform app, picking a deployment mode (standalone operator / grafana/apps / frontend-only), wiring app-specific config, or onboarding to the SDK. Covers `grafana-app-sdk` CLI install, `project init`

Scan passed 0
assistant-mcp

Connect AI coding agents (Claude Code, Cursor, VS Code, OpenAI Codex) to Grafana Cloud via the `mcp-grafana` Model Context Protocol server. Installs the server with `go install`, generates a Grafana service-account token, wires `~/.claude/settings.json` or `~/.cursor/mcp.json` with the `command` + `

Scan passed 0

Related devops skillsscan passed

enterprise-agent-ops

Operational controls for long-lived or cloud-hosted agent systems — runtime lifecycle (start, pause, stop, restart), observability (logs, metrics, traces), least-privilege safety scopes and kill switches, and rollout/rollback change management with audit logs and success/cost metrics. Use when runni

Scan passed 0
land-and-deploy

Land and deploy workflow. (gstack)

Scan passed 0
sandbox-stable

Build or maintain Cloudflare Sandbox apps on the stable @cloudflare/sandbox package. Use sandbox-next for preview apps and sandbox-migrate-to-next for stable-to-preview migrations.

Scan passed 0
adapter-aws-lambda

Deploy tRPC on AWS Lambda with awsLambdaRequestHandler() from @trpc/server/adapters/aws-lambda for API Gateway v1 (REST, APIGatewayProxyEvent) and v2 (HTTP, APIGatewayProxyEventV2), and Lambda Function URLs. Enable response streaming with awsLambdaStreamingRequestHandler() wrapped in awslambda.strea

Scan passed 0
ci-cd-and-automation

Automates CI/CD pipeline setup. Use when setting up or modifying build and deployment pipelines. Use when you need to automate quality gates, configure test runners in CI, or establish deployment strategies.

Scan passed 0
firebase-app-hosting-basics

Deploys and manages full-stack web applications (Next.js, Angular) with Server-Side Rendering (SSR) using Firebase App Hosting. Use when deploying Next.js/Angular apps, configuring apphosting.yaml or firebase.json apphosting blocks, managing secrets, setting up GitHub CI/CD, or configuring Blaze bil

Scan passed 0