Supported platforms
Prerequisites
- A Grafana instance (OSS, Enterprise, or Cloud) reachable from CloudThinker.
- Admin access to create a service account under Administration → Users and access → Service Accounts.
- The Grafana instance URL.
Setup
1
Open Grafana
Navigate to your Grafana instance and sign in with admin access.
2
Navigate to service accounts
Go to Administration → Users and access → Service Accounts.
3
Create service account
Click Add service account and enter:
- Name:
cloudthinker-readonly - Role: Select Viewer
4
Generate token
On the new service account page:
- Click Add service account token
- Enter a token name (e.g.,
cloudthinker-token) - Optionally set an expiration date
- Click Generate token
- Immediately copy the token — it won’t be shown again
5
Add connection in CloudThinker
Navigate to Connections → Grafana and enter:
- Grafana URL: your instance URL (e.g.,
https://grafana.your-domain.com) - Service Account Token: the token you just copied
Connection details
Required permissions
Agent capabilities
Once connected, agents can:Verify the connection
Example prompts
Supported data sources
CloudThinker can query through Grafana’s configured data sources:Troubleshooting
Connection failed
Connection failed
- Verify the Grafana URL is accessible from CloudThinker.
- Check the SSL certificate is valid.
- Ensure no proxy is blocking the connection.
- Confirm Grafana is running and reachable.
Authentication failed
Authentication failed
- Verify the service account token is correct.
- Check the token has not expired.
- Ensure the service account is active.
- Confirm no IP restrictions are set on the account.
Token expired
Token expired
- Navigate to Administration → Service Accounts.
- Select the CloudThinker service account.
- Generate a new token.
- Update the token in CloudThinker connection settings.
Cannot access dashboards
Cannot access dashboards
- Verify the service account has the Viewer role.
- Check folder permissions include the service account.
- Ensure the dashboards are not in restricted folders.
Security
- Least privilege — grant only the permissions the agents need for your use case; start read-only and widen later.
- Read-only by default — use read-only credentials unless you want agents to make changes through this connection.
- Rotate credentials — rotate keys and tokens on your normal schedule; CloudThinker picks up the new value when you update the connection.
- Revoke on offboarding — remove the credential at the provider when you delete a connection or a teammate leaves.
- Viewer role only — never grant Editor or Admin roles to the CloudThinker service account
- Token expiration — set an expiration date and rotate the service account token every 90 days
Related
Elasticsearch Connection
Connect log data source
AWS Connection
Connect CloudWatch metrics