# Grafana

> Use the Grafana that ships with Falak — login, provisioned datasources, per-organization folders, the six Falak dashboards and deployment annotations.

Source: https://falak.sh/docs/observability/grafana/

With `--observability`, Falak runs Grafana (OSS) at `https://grafana.<your panel domain>` and provisions it for you.

## Log in

| | |
|---|---|
| URL | `https://grafana.falak.example.com` |
| User | `admin` |
| Password | `GRAFANA_ADMIN_PASSWORD` in `/opt/falak/.env` on the control plane host |

```bash
sudo grep GRAFANA_ADMIN_PASSWORD /opt/falak/.env
```

Falak itself talks to Grafana with a service account token (`FALAK_GRAFANA_TOKEN`), created by the installer.

## What Falak provisions

- **Datasources**: VictoriaMetrics (Prometheus API via the gateway), Loki and Tempo.
- **A folder per organization** with the Falak dashboards.
- **Deployment annotations**: every deployment adds an annotation, and telemetry carries the `deployment.id` resource attribute.

| Dashboard | Shows |
|---|---|
| Falak Server | CPU, memory, disk, load, network and disk I/O per host |
| Falak Laravel site | Requests, latency, errors, queries, cache, mail, notifications for a Laravel site |
| Falak Node app | Requests, latency and errors for Node/Bun/Deno apps |
| Falak Containers | CPU, memory and network per container (Compose) |
| Falak Queues | Jobs by class and status, queue sizes, scheduled tasks |
| Falak Deployments | Deployments over time with status |

Re-provision from **Settings → Observability** (`telemetry.manage`) or on the host:

```bash
falak-ctl artisan telemetry:grafana:provision
falak-ctl artisan telemetry:grafana:provision --organization=01k…
```

## Grafana's memory

Grafana 12+ downloads its Drilldown, Advisor and Pyroscope apps on first start (about 110 MB extra). Falak does not use them, so the stack skips that step. Set `FALAK_GRAFANA_PREINSTALL_DISABLED=false` in `.env` to restore it.

## Limits

- Dashboards are copied into a folder per organization, but queries are **not filtered by organization** inside Grafana. Anyone with Grafana access sees all organizations' data. Keep Grafana logins to operators.
- The Grafana provisioning API is covered by unit and feature tests, not yet by the end-to-end suite.

## Next steps
