Grafana
Explore metrics and build dashboards from connected data sources.
Choose your deployment and the way you want to use Selfhost. The instructions below follow that choice.
Set up Grafana
Editable Compose files in your own directory.
- Sign in using the generated administrator credentials and change them in Grafana as needed.
- Connect an IdP, optionally selecting a verified human account for organization administration.
selfhost app --directory ./grafana init grafana Initialization writes portable files and does not start the app. Review compose.yaml, the private .env and any files in files/, then start it:
selfhost app --directory ./grafana startNo Selfhost dashboard or background service is needed. You can also start these files directly:
cd grafana
docker compose -f compose.yaml up -dConnect an existing installation
Use Existing apps → Link an app in the dashboard, or the CLI’s existing-app commands. Choose Grafana, its URL and, optionally, its exact Docker container on a connected server.
Save existing.json with your app URL. Add server_id and container for container inspection and actions.
{
"profile": "grafana",
"name": "Grafana",
"url": "https://app.example.com"
}selfhost existing link --file existing.json
selfhost existing list
selfhost existing inspect EXISTING_IDLinking enables the existing-app profile’s supported inspection and actions. It does not import Compose or attach the new-deployment settings and onboarding profiles described below.
Existing app commands, permissions and unlinkingActions for a linked container
List installed plugins
Show plugins installed in this Grafana instance.
selfhost existing action EXISTING_ID list-pluginsBefore configuring integrations
- Other OIDC users receive Viewer; server-wide Grafana administrator access is never automatically granted.
- PostgreSQL can be dedicated, shared or external.
- Database placement includes PostgreSQL, MySQL and MariaDB using app-specific connection settings. Select a fresh or already migrated database before first start; changing the engine does not convert existing data.
- MySQL and MariaDB TLS uses server certificate verification whenever enabled. A source configured as require therefore still needs a certificate trusted by the app; private CA certificates must be installed in the app trust store.
- Datasource provisioning and dashboard import remain separate from login configuration.
Grafana integrations
Compose service: grafana. These operations use the profile saved when this deployment is created.
Native settings
Changes use the app’s Compose environment. Unrelated settings are preserved.
Supported fields (3)
- Public URL
public-url - string
- OpenID Connect enabled
oauth-enabled - stringChoices: true, false
- OIDC client secret
oauth-client-secret - secret · advanced
Save a JSON map of the field IDs you want to change as changes.json. Replace FIELD_ID with an ID from the supported fields above, and use its declared value type. Review the plan and replace REVIEWED_REVISION with the revision it returns.
{
"FIELD_ID": "YOUR_VALUE"
}selfhost app --directory ./grafana config grafana
selfhost app --directory ./grafana plan grafana changes.json
selfhost app --directory ./grafana apply grafana changes.json --revision REVIEWED_REVISION Saved changes need service recreation to become active. Existing interpolated environment values stay under your control in .env or Compose.
Identity provider login
Selfhost can register a client with a supported provider and configure this app. Callback path: /login/generic_oauth.
This profile can explicitly map a verified human account to Grafana organization administrator after review.
Save connection.json and replace the URLs. Supply SELFHOST_IDP_TOKEN privately in your shell.
{
"provider": "zitadel",
"issuer": "https://identity.example.com",
"app_url": "https://app.example.com",
"name": "Grafana"
}selfhost app --directory ./grafana connect-account grafana connection.json
selfhost app --directory ./grafana connect-plan grafana connection.json
selfhost app --directory ./grafana connect grafana connection.json --revision REVIEWED_REVISIONTest sign-in in a separate browser session. HTTPS domains and HTTP loopback development origins are supported by Selfhost; the chosen app and provider must also accept the resulting callback. Provider permissions, localhost and recovery.
Database placement
This recipe supports postgres, mysql, mariadb. Workspace projects can choose a dedicated database, a shared source with a separate database and account, or an existing external database before their first start.
- postgres adapter TLS modes: disable, require, verify-full. Use a private network for connections with TLS disabled.
- mysql adapter TLS modes: disable, require, verify-full. Use a private network for connections with TLS disabled.
- mariadb adapter TLS modes: disable, require, verify-full. Use a private network for connections with TLS disabled.
Standalone directories use the generated Compose and environment files directly. Configure the database there before first start. Selfhost’s source provisioning commands belong to workspace projects and are optional.
Database setup, CLI commands and backupsApp actions
List installed plugins
Show plugins installed in this Grafana instance.
selfhost app --directory ./grafana action grafana list-pluginsVersions and updates
This deployment uses the following images. Existing projects retain their saved recipe and images. A new catalogue version does not silently update them.
- grafana:
grafana/grafana:13.2.2
- 13.2.2
grafana/grafana:13.2.2Local Docker startup, generated administrator login, plugin action and volume persistence verified. OIDC browser login must be tested separately.
Review compatibility and back up app data before an update. Choose an image version and review the change.
Keep control of your setup
Selfhost remains optional. Your app runs using ordinary Compose files, its own settings and persistent data. Keep the Compose project name and volumes to preserve storage. Configuration exports and setting backups do not include application data.
Standalone CLI guide · Backups and removal · Grafana documentation