Skip to main content
See All Integrations

Grafana Loki

Protect access to Grafana Loki HTTP endpoints as upstream web applications.

Standard protected service pattern

Categories
Monitoring and Observability, Upstream Applications

Overview

Grafana Loki is a log aggregation system. It exposes an HTTP API, normally on port 3100. The log tail endpoint uses WebSocket. Loki does not include a complete authentication layer by itself.

Grafana Loki can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.

Pomerium controls who can establish the selected route to Grafana Loki. Grafana Loki remains responsible for its application, protocol, data, and service-level permissions.

How it works

Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL, trusted proxy settings, WebSocket forwarding, and suitable timeouts.

Keep application authentication and granular authorization active. Test interactive terminals, streaming views, agents, and other long-lived connections separately.

Separate interactive query access from write and machine-to-machine ingestion paths. Preserve WebSocket upgrades for the tail endpoint and test tenant headers and API credentials.

Example

Engineers query a private Loki endpoint through Pomerium. The browser query route uses identity-aware policy. Promtail, Grafana, and ingestion services use a separate reviewed noninteractive path.

Considerations

  • Loki has no included authentication layer. Keep tenant controls and downstream authorization explicit.
  • Promtail, Grafana, ingestion, and automation cannot complete an interactive sign-in redirect. The tail endpoint needs WebSocket forwarding.
  • Pomerium checks TCP and WebSocket policy when the connection starts. A later policy change does not terminate an established connection.

Sources and official resources

  • Protect access to Prometheus metrics and administration as an upstream web application.

  • Protect access to Kibana dashboards and administration as an upstream web application.

  • Protect the Elasticsearch HTTP API while keeping cluster transport traffic on the private network.

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo