Grafana
Manage Grafana data-plane folders, data sources and dashboards from Bicep.
Community Maintained
| Version | 0.0.1 |
| Artifact | br:ghcr.io/anthony-c-martin/bicep-ext-grafana:0.0.1 |
| Source | github.com/anthony-c-martin/bicep-ext-grafana |
| Publisher | anthony-c-martin |
| Licence | MIT |
| Category | Observability |
Installation
Register the extension in bicepconfig.json:
{
"experimentalFeaturesEnabled": {
"localDeploy": true,
"ociEnabled": true
},
"implicitExtensions": [],
"extensions": {
"grafana": "br:ghcr.io/anthony-c-martin/bicep-ext-grafana:0.0.1"
}
}
Then reference it from your Bicep file:
extension grafana
Configuration
Configuration is supplied using extension grafana with { ... }.
| Property | Type | Attributes | Description |
|---|---|---|---|
baseUrl | string | Required | The absolute Grafana URL. The /api suffix is optional. |
token | string | Required, Sensitive | A Grafana service account token or an Azure Managed Grafana Microsoft Entra access token. |
Authentication
The extension calls the Grafana HTTP API directly. Configure the Grafana endpoint and a token with permission to manage the resources in your template:
@secure()
param grafanaToken string
param grafanaUrl string
extension grafana with {
baseUrl: grafanaUrl
token: grafanaToken
}
Keep the token out of source control by supplying it through a secure parameter or a deployment environment variable. The token can be a Grafana service account token or an Azure Managed Grafana Microsoft Entra access token.
Resources
The extension manages these Grafana data-plane resources:
Folder, identified by its stableuid.DataSource, identified by its stableuid.Dashboard, identified by its stableuid.
JSON properties such as definitionJson, jsonDataJson, and
secureJsonDataJson accept serialized JSON strings. The secure data source
property is write-only and is omitted from deployment outputs.
Example
Create a folder, a Prometheus data source, and a dashboard:
targetScope = 'local'
@description('The absolute URL of the Grafana instance.')
param grafanaUrl string
@secure()
@description('A Grafana token with folder, data source, and dashboard permissions.')
param grafanaToken string
@description('The URL of the Prometheus server.')
param prometheusUrl string
extension grafana with {
baseUrl: grafanaUrl
token: grafanaToken
}
resource operations 'Folder' = {
uid: 'operations'
title: 'Operations'
description: 'Operational dashboards managed by Bicep'
}
resource prometheus 'DataSource' = {
uid: 'prometheus'
name: 'Prometheus'
type: 'prometheus'
url: prometheusUrl
access: 'proxy'
isDefault: true
jsonDataJson: string({
httpMethod: 'POST'
timeInterval: '30s'
})
}
resource overview 'Dashboard' = {
uid: 'operations-overview'
title: 'Operations overview'
folderUid: operations.uid
message: 'Managed by Bicep'
definitionJson: string({
tags: [
'bicep'
'operations'
]
timezone: 'browser'
schemaVersion: 41
refresh: '30s'
time: {
from: 'now-6h'
to: 'now'
}
panels: [
{
id: 1
type: 'timeseries'
title: 'Prometheus up'
datasource: {
type: 'prometheus'
uid: prometheus.uid
}
targets: [
{
refId: 'A'
expr: 'up'
}
]
gridPos: {
h: 8
w: 24
x: 0
y: 0
}
}
]
})
}
output dashboardUid string = overview.uid
Azure Managed Grafana
The extension does not create or configure the Azure Managed Grafana control-plane
resource. Create the workspace with the standard Microsoft.Dashboard/grafana
resource, then use this extension against its endpoint.
For Microsoft Entra authentication, request a token for the
https://dashboard.azure.com audience and grant the deploying identity an
appropriate Grafana role. The endpoint must be available when the local deploy
starts, so a workspace created in an earlier deployment stage may be required.
Notes
- The Grafana URL may be supplied with or without the
/apisuffix. - Resource updates are applied as upserts through the Grafana API.
- Use a narrowly scoped service account token or Entra identity rather than an administrator token where possible.
Samples
1 example Bicep file is available under Samples.
Resource types
This extension exposes 3 resource types, documented under Reference.
Reference generated from ghcr.io/anthony-c-martin/bicep-ext-grafana:0.0.1 on 2026-09-12.