Creating an OIDC application in Yandex Identity Hub for integration with Grafana Cloud
Note
This feature is at the Preview stage.
Grafana Cloud
To authenticate your organization's users to Grafana Cloud with OpenID Connect
OIDC apps can be managed by users with the organization-manager.oauthApplications.admin role or higher.
For the users of your organization to be able to access Grafana Cloud:
- Create a Grafana Cloud account.
- Create an app.
- Set up the integration.
- Make sure the application works correctly.
Create a Grafana Cloud account
If you do not have a Grafana Cloud account, create one:
- Go to the Grafana Cloud sign up page
. - Fill out the registration form:
- Enter your email address.
- Create a secure password.
- Click Create my account.
- Verify your new account by following the instructions sent to the email address you provided.
- Select a name for your organization; this name will be part of your instance's URL, e.g.,
your-org. - Once logged in, make sure you have administrator permissions to configure OIDC in your Grafana Cloud organization.
- Write down your Grafana Cloud instance’s URL, e.g.,
https://your-org.grafana.net, as you will need it to set up the integration.
Note
To configure OIDC in Grafana Cloud, you need organization administrator permissions. If you do not have the required permissions, contact your organization's administrator in Grafana Cloud.
Create an app
- Log in to Yandex Identity Hub
. - In the left-hand panel, select
Apps. - In the top-right corner, click
Create application and in the window that opens:-
Select the OIDC (OpenID Connect) single sign-on method.
-
In the Name field, specify a name for your new app:
grafana-cloud-oidc-app. -
In the Folder field, select the folder where you want to create an OAuth client for your app.
-
Optionally, in the Description field, enter a description for the new app.
-
Optionally, add labels:
- Click Add label.
- Enter a label in
key: valueformat. - Press Enter.
-
Click Create application.
-
Set up the integration
To integrate Grafana Cloud with the OIDC app you created in Identity Hub, complete the setup both on the Grafana Cloud side and in Identity Hub.
Configure your OIDC application in Yandex Identity Hub
Get the application’s credentials
-
Log in to Yandex Identity Hub
. -
In the left-hand panel, select
Apps and then, the OIDC app. -
On the Overview tab, under Identity provider (IdP) configuration, expand the Additional attributes section and copy the parameter values you need to specify in Grafana Cloud:
ClientID: Unique application ID.OpenID Configuration: URL with the configuration of all parameters required to set up the integration.
-
Under App secrets, click Add secret, and in the window that opens:
- Optionally, add a description for the new secret.
- Click Create.
The window will display the generated application secret. Save this value.
Warning
If you refresh or close the application information page, you will not be able to view the secret again.
If you closed or refreshed the page before saving the secret, click Add secret to create a new one.
To delete a secret, in the list of secrets on the OIDC app page, click
in the secret row and select Delete.
Configure the redirect URI
-
Log in to Yandex Identity Hub
. -
In the left-hand panel, select
Apps and then, the OIDC app. -
At the top right, click
Edit and in the window that opens:- In the Redirect URI field, specify the authentication endpoint for your Grafana Cloud instance formatted as follows:
<Grafana_Cloud_instance_URL>/login/generic_oauthFor example:
https://your-org.grafana.net/login/generic_oauth.- Click Save.
Set up the OIDC application in Grafana Cloud
To configure OpenID Connect authentication in Grafana Cloud, in the left-hand panel, navigate to Administration and then to Authentication.
In the main window, select Generic OAuth.
In the Generic OAuth settings:
- Under Name, specify
OpenID Connect. - In the Scopes field, enter the following, one by one:
openid,email,profile. - Under Client ID, specify the value you copied from the ClientID field when setting up the OIDC application in Identity Hub.
- In the Client Secret field, specify the value you copied from the App secrets section when setting up the OIDC application in Identity Hub.
- Click Enter OpenID Connect Discovery URL and then, in the window that opens, specify the URL you copied from the OpenID Configuration field when setting up the OIDC application in Identity Hub.
- Enable Allow sign up to automatically create users on first sign-in.
Add a user
For your organization's users to be able to authenticate in Grafana Cloud with Identity Hub's OIDC app, you need to explicitly add these users and/or user groups to the OIDC application.
Note
Users and groups added to an OIDC application can be managed by a user with the organization-manager.oidcApplications.userAdmin role or higher.
Add a user to the application:
- Log in to Yandex Identity Hub
. - In the left-hand panel, select
Apps and select the required app. - Navigate to the Users and groups tab.
- Click
Add users. - In the window that opens, select the required user or user group.
- Click Add.
Make sure your application works correctly
To make sure both your OIDC app and Grafana Cloud integration work correctly, authenticate to Grafana Cloud as one of the users you added to the app.
Proceed as follows:
- In your browser, navigate to the address of your Grafana Cloud instance, e.g.,
https://your-org.grafana.net. - If you were logged in to Grafana Cloud, log out.
- On the Grafana Cloud sign in page, click Sign in with OpenID Connect.
- On the Yandex Cloud sign in page, enter the user email and password. The user or group they belong to must be added to the application.
- Make sure you are logged in to Grafana Cloud.