Skip to main content
Connect your Grafana instance to enable CloudThinker agents to access dashboards, query metrics, and reference visualizations during analysis. Grafana authenticates with a service account token scoped to the Viewer role.

Supported platforms

PlatformSupport
Grafana OSS9.x, 10.x
Grafana EnterpriseAll versions
Grafana CloudAll tiers

Prerequisites

  • A Grafana instance (OSS, Enterprise, or Cloud) reachable from CloudThinker.
  • Admin access to create a service account under Administration → Users and access → Service Accounts.
  • The Grafana instance URL.

Setup

1

Open Grafana

Navigate to your Grafana instance and sign in with admin access.
2

Navigate to service accounts

Go to Administration → Users and access → Service Accounts.
3

Create service account

Click Add service account and enter:
  • Name: cloudthinker-readonly
  • Role: Select Viewer
Click Create to create the service account.
4

Generate token

On the new service account page:
  1. Click Add service account token
  2. Enter a token name (e.g., cloudthinker-token)
  3. Optionally set an expiration date
  4. Click Generate token
  5. Immediately copy the token — it won’t be shown again
5

Add connection in CloudThinker

Navigate to Connections → Grafana and enter:
  • Grafana URL: your instance URL (e.g., https://grafana.your-domain.com)
  • Service Account Token: the token you just copied
Click Connect. CloudThinker verifies the credentials and shows a Connected status.
Copy the service account token immediately after generation. Grafana will not show it again, and you’ll need to create a new token if lost.

Connection details

FieldDescriptionExample
GRAFANA_URLYour Grafana instance URLhttps://your-instance.grafana.net
GRAFANA_SERVICE_ACCOUNT_TOKENThe generated service account tokenglsa_xxxxx...

Required permissions

RoleWhat it grants
ViewerView dashboards, query data sources, view annotations, access folder contents
EditorViewer permissions, plus create annotations and save dashboard snapshots
Assign the Viewer role for read-only investigation. Only use Editor if you need annotation creation or dashboard snapshots.

Agent capabilities

Once connected, agents can:
CapabilityDescription
Dashboard accessReference existing dashboards in analysis
Metric queriesQuery data sources through Grafana
Annotation readingAccess dashboard annotations for context
Alert statusCheck Grafana alerting rules status

Verify the connection

@alex check Grafana for active alert rules and summarize any that are firing

Example prompts

@alex check the AWS cost dashboard for anomalies
@kai reference the Kubernetes cluster dashboard for pod health
@tony query database metrics from the Grafana data source

Supported data sources

CloudThinker can query through Grafana’s configured data sources:
Data sourceQuery support
PrometheusPromQL queries
InfluxDBInfluxQL / Flux
ElasticsearchLucene / KQL
CloudWatchCloudWatch metrics
LokiLogQL queries

Troubleshooting

  • Verify the Grafana URL is accessible from CloudThinker.
  • Check the SSL certificate is valid.
  • Ensure no proxy is blocking the connection.
  • Confirm Grafana is running and reachable.
  • Verify the service account token is correct.
  • Check the token has not expired.
  • Ensure the service account is active.
  • Confirm no IP restrictions are set on the account.
  • Navigate to Administration → Service Accounts.
  • Select the CloudThinker service account.
  • Generate a new token.
  • Update the token in CloudThinker connection settings.
  • Verify the service account has the Viewer role.
  • Check folder permissions include the service account.
  • Ensure the dashboards are not in restricted folders.

Security

  • Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
  • Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
  • Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
  • Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
  • Viewer role only — never grant Editor or Admin roles to the CloudThinker service account
  • Token expiration — set an expiration date and rotate the service account token every 90 days

https://mintcdn.com/cloudthinker/aLd-ttc-SCW-aFky/images/icons/elasticsearch.svg?fit=max&auto=format&n=aLd-ttc-SCW-aFky&q=85&s=c7389cfcd0bc8d303aeeb68bd19199ca

Elasticsearch Connection

Connect log data source
https://mintcdn.com/cloudthinker/aLd-ttc-SCW-aFky/images/icons/aws.svg?fit=max&auto=format&n=aLd-ttc-SCW-aFky&q=85&s=45d526a3e9345214c0345f277da2e829

AWS Connection

Connect CloudWatch metrics