feat(grafana): apply fhirworx theme + clean up home page

Theme: bake the <link rel="stylesheet" href="/public/fhirworx.css">
into Grafana's index.html at startup (sed-patch, idempotent) and bind
the inject.css from assets/ as Grafana's own /public asset. Traefik's
rewrite-body plugin is unreliable on Grafana's heavy SPA — patching
the template directly guarantees the link survives client-side
re-renders. Runs as root since the patch writes to a root-owned
file; grafana-server doesn't require a specific UID.

Home page: kill the news feed, update-check nags, plugin-update
nags, telemetry, feedback links, and help menu. Make
homelab-overview the default landing dashboard so users land on
fleet health, not the stock "Welcome to Grafana" splash.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
This commit is contained in:
kert
2026-05-01 12:31:42 -04:00
parent dd4b5c0a80
commit 9dfbcf5940

View File

@@ -727,6 +727,20 @@ services:
networks: networks:
- gateway - gateway
- observability - observability
# Theme injection: Grafana 12 is a heavy SPA, and Traefik's
# rewrite-body fires on the upstream HTML response but Grafana
# re-renders the head client-side. Patching index.html in place at
# startup guarantees the <link> survives. Runs as root so the patch
# can write the root-owned template; grafana-server itself doesn't
# require a specific UID.
user: "0:0"
entrypoint:
- /bin/sh
- -c
- |
grep -q fhirworx.css /usr/share/grafana/public/views/index.html || \
sed -i 's|</head>|<link rel="stylesheet" type="text/css" href="/public/fhirworx.css"></head>|' /usr/share/grafana/public/views/index.html
exec /run.sh
env_file: env_file:
- path: .state/gitea/grafana.env - path: .state/gitea/grafana.env
required: false required: false
@@ -748,6 +762,17 @@ services:
- GF_AUTH_OAUTH_ALLOW_INSECURE_EMAIL_LOOKUP=true - GF_AUTH_OAUTH_ALLOW_INSECURE_EMAIL_LOOKUP=true
- GF_AUTH_GENERIC_OAUTH_ROLE_ATTRIBUTE_PATH=is_admin && 'GrafanaAdmin' - GF_AUTH_GENERIC_OAUTH_ROLE_ATTRIBUTE_PATH=is_admin && 'GrafanaAdmin'
- GF_AUTH_GENERIC_OAUTH_ALLOW_ASSIGN_GRAFANA_ADMIN=true - GF_AUTH_GENERIC_OAUTH_ALLOW_ASSIGN_GRAFANA_ADMIN=true
# Strip Grafana's stock home-page cruft (news feed, "welcome",
# tutorials, update nags, telemetry). Our homelab-overview
# dashboard is the default landing page.
- GF_NEWS_NEWS_FEED_ENABLED=false
- GF_ANALYTICS_REPORTING_ENABLED=false
- GF_ANALYTICS_CHECK_FOR_UPDATES=false
- GF_ANALYTICS_CHECK_FOR_PLUGIN_UPDATES=false
- GF_ANALYTICS_FEEDBACK_LINKS_ENABLED=false
- GF_HELP_ENABLED=false
- GF_PLUGINS_PUBLIC_KEY_RETRIEVAL_DISABLED=true
- GF_DASHBOARDS_DEFAULT_HOME_DASHBOARD_PATH=/var/lib/grafana/dashboards/homelab-overview.json
volumes: volumes:
- ./infra/grafana/provisioning:/etc/grafana/provisioning:ro - ./infra/grafana/provisioning:/etc/grafana/provisioning:ro
- ./infra/grafana/dashboards:/var/lib/grafana/dashboards:ro - ./infra/grafana/dashboards:/var/lib/grafana/dashboards:ro
@@ -755,6 +780,7 @@ services:
- ./assets/icons/favicon.svg:/usr/share/grafana/public/img/grafana_icon.svg:ro - ./assets/icons/favicon.svg:/usr/share/grafana/public/img/grafana_icon.svg:ro
- ./assets/icons/fav32.png:/usr/share/grafana/public/img/fav32.png:ro - ./assets/icons/fav32.png:/usr/share/grafana/public/img/fav32.png:ro
- ./assets/icons/apple-touch-icon.png:/usr/share/grafana/public/img/apple-touch-icon.png:ro - ./assets/icons/apple-touch-icon.png:/usr/share/grafana/public/img/apple-touch-icon.png:ro
- ./assets/css/inject.css:/usr/share/grafana/public/fhirworx.css:ro
depends_on: depends_on:
- loki - loki
- tempo - tempo