private-connectivity
Set up private network connectivity to Grafana Cloud — AWS PrivateLink, Azure Private Link, GCP Private Service Connect, and Private Data Source Connect (PDC). Provisions VPC endpoints, private endpoints, or PSC forwarding rules per signal type (metrics / logs / traces / profiles); wires Alloy to pu
- 0
- Installs
- —
- Rating
- —
- Success rate
- 3
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 c9938e2c5b0b1550… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
Grafana Cloud Private Connectivity
Send metrics, logs, traces, and profiles to Grafana Cloud entirely over your cloud provider's private backbone — no public internet exposure, no egress fees.
Common Workflows
Setting up AWS PrivateLink (most common)
-
Find your service names. Grafana Cloud → Stack Details → "Send using AWS PrivateLink". Note one service name per signal type (metrics / logs / traces / profiles).
-
Create an Interface VPC Endpoint per signal type:
aws ec2 create-vpc-endpoint \ --vpc-id vpc-12345 \ --service-name com.amazonaws.vpce.us-east-1.vpce-svc-0abc123 \ --vpc-endpoint-type Interface \ --subnet-ids subnet-12345 \ --security-group-ids sg-12345 \ --private-dns-enabled -
Verify private DNS resolves (CRITICAL — if this returns a public IP, Alloy will silently keep using the public path and you'll keep paying egress):
dig +short prometheus-private.us-east-0.grafana.net # Expected: a 10.x.x.x / 172.16-31.x.x / 192.168.x.x address # Public IP returned → check `private_dns_enabled = true` was set and the VPC has DNS hostnames enabled -
Update Alloy to use the private endpoint:
prometheus.remote_write "cloud_private" { endpoint { url = "https://prometheus-private.us-east-0.grafana.net/api/prom/push" basic_auth { username = sys.env("PROM_USER") password = sys.env("GRAFANA_CLOUD_API_KEY") } } } loki.write "cloud_private" { endpoint { url = "https://logs-private.us-east-0.grafana.net/loki/api/v1/push" basic_auth { username = sys.env("LOKI_USER") password = sys.env("GRAFANA_CLOUD_API_KEY") } } } -
Confirm traffic is flowing over PrivateLink: check the VPC endpoint's CloudWatch metrics for
BytesProcessedafter Alloy starts pushing.
Full Terraform + per-signal-type endpoint resources in references/aws.md.
Setting up Azure Private Link / GCP Private Service Connect
Different provider, same shape: create the private endpoint → wait for approval → verify private DNS → update Alloy URLs. Full CLI + verification steps in references/azure-gcp.md.
Azure-specific prereq: Pre-register your Subscription IDs with Grafana Support before starting — without this the endpoint creation hangs at "Pending".
Prerequisites (all providers)
- Grafana Cloud stack must be hosted on the same cloud provider (check: My Account → Stack → Details)
- Create separate private endpoints for each signal type (metrics / logs / traces / profiles) — they have distinct service names
- Same region only for AWS PrivateLink. Cross-region requires VPC peering first.
Choosing the right option
| Scenario | Solution |
|---|---|
| Push from AWS | AWS PrivateLink |
| Push from Azure | Azure Private Link |
| Push from GCP | GCP Private Service Connect |
| Query private DB / Prometheus from Grafana | Private Data Source Connect (PDC) — see references/azure-gcp.md § PDC |
References
references/aws.md— full AWS PrivateLink Terraform per signal type + endpoint verification (state + DNS)references/azure-gcp.md— Azure Private Link + GCP Private Service Connect setup (Portal + CLI) + verification + Private Data Source Connect (PDC) for reverse-direction private data source queries
Files
3- SKILL.md
304899beee4.5 KB - references/aws.md
fd97921e631.6 KB - references/azure-gcp.md
1fc046e37d2.0 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from grafana/skills8
Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config, unused-metric detection, and Alloy remote_write fallback. Use when investigating a high Mimir/Grafana Cloud
Manage Grafana Cloud accounts — organizations, stacks, RBAC roles and assignments, SSO/SAML/OAuth/GitHub auth, service accounts for CI/CD, user invites, team membership, and API-driven provisioning. Creates stacks via the Cloud API, mints service-account tokens, applies role assignments, configures
Use when the user asks to "write a validator", "add validation", "implement admission control", "write a mutating webhook", "add a mutation handler", "validate incoming resources", "implement admission logic", "add admission webhooks", "write ingress validation", or asks how to validate or mutate re
Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook), notification policies with hierarchical matchers, silences, mute timings, on-call schedules and escala
Build a unified telemetry pipeline with Grafana Alloy — one OpenTelemetry-compatible binary that collects metrics, logs, traces, and profiles and ships to Grafana Cloud / Prometheus / Loki / Tempo / Pyroscope. Covers the Alloy config language (blocks, `sys.env`, component refs), `prometheus.scrape`
Get RED metrics + service maps + frontend RUM + AI/LLM monitoring out of Grafana Cloud — Application Observability (`traces_spanmetrics_*` from OTel traces, p50/p95/p99 latency, exemplar-to-trace, traces-to-logs / profiles), Frontend Observability with the Faro Web SDK (Core Web Vitals, session repl
Use when starting any grafana-app-sdk work — scaffolding a Grafana app, initializing a Grafana App Platform app, picking a deployment mode (standalone operator / grafana/apps / frontend-only), wiring app-specific config, or onboarding to the SDK. Covers `grafana-app-sdk` CLI install, `project init`
Connect AI coding agents (Claude Code, Cursor, VS Code, OpenAI Codex) to Grafana Cloud via the `mcp-grafana` Model Context Protocol server. Installs the server with `go install`, generates a Grafana service-account token, wires `~/.claude/settings.json` or `~/.cursor/mcp.json` with the `command` + `
Related devops skillsscan passed
Operational controls for long-lived or cloud-hosted agent systems — runtime lifecycle (start, pause, stop, restart), observability (logs, metrics, traces), least-privilege safety scopes and kill switches, and rollout/rollback change management with audit logs and success/cost metrics. Use when runni
Land and deploy workflow. (gstack)
Build or maintain Cloudflare Sandbox apps on the stable @cloudflare/sandbox package. Use sandbox-next for preview apps and sandbox-migrate-to-next for stable-to-preview migrations.
Deploy tRPC on AWS Lambda with awsLambdaRequestHandler() from @trpc/server/adapters/aws-lambda for API Gateway v1 (REST, APIGatewayProxyEvent) and v2 (HTTP, APIGatewayProxyEventV2), and Lambda Function URLs. Enable response streaming with awsLambdaStreamingRequestHandler() wrapped in awslambda.strea
Automates CI/CD pipeline setup. Use when setting up or modifying build and deployment pipelines. Use when you need to automate quality gates, configure test runners in CI, or establish deployment strategies.
Deploys and manages full-stack web applications (Next.js, Angular) with Server-Side Rendering (SSR) using Firebase App Hosting. Use when deploying Next.js/Angular apps, configuring apphosting.yaml or firebase.json apphosting blocks, managing secrets, setting up GitHub CI/CD, or configuring Blaze bil