You can create a private network interface in Managed Service for Grafana to allow a Grafana workspace to access data sources within a VPC without exposing them to the public network. This action also creates a private domain name accessible only from within the VPC.
Prerequisites
-
You must have an active Managed Service for Grafana Pro or Advanced Edition subscription.
-
This feature is available only for Grafana workspaces created after August 31, 2023.
-
The VPC must be in the same region as the Grafana workspace.
Procedure
-
Log on to the ARMS console. In the left-side navigation pane, choose .
-
On the Workspace Management page, click the ID of the workspace that you want to manage.
-
In the left-side navigation pane, click Whitelists and Security Groups. On the Private IP Address Whitelist tab, click Enable Private Endpoint. In the dialog box that appears, select a VPC, VSwitch, and Security Group, and then click Activate.
After you enable the endpoint, the Private IP Address Whitelist tab displays information such as the VPC, VSwitch, security group, private domain name, and security group rules.
The workspace information page also displays the private domain name.
This private domain name corresponds to the Private Endpoint field in the Basic Information section.
Next Steps
-
In the upper-right corner of the Private IP Address Whitelist page, click Configure Security Group Rules. The system redirects you to the security group page in the ECS console. Follow the on-screen instructions to configure security group rules.
-
To uninstall the private network interface and private domain name, click Disable Private Endpoint in the upper-right corner of the Private IP Address Whitelist page and then click OK.