Oracle Kerberos integration
This document explains how to configure Kerberos authentication for the Oracle data source on both standalone and Docker-based Grafana servers. Kerberos authentication requires the tnsnames.ora file for connection configuration.
Note
Kerberos authentication is not supported in Grafana Cloud. Use the Host with TCP Port connection method with Basic authentication and Private data source connect (PDC) instead.
Oracle configuration files
Kerberos authentication requires three configuration files:
tnsnames.ora—stores connection information for Oracle databases. Refer to Local Naming Parameters in the tnsnames.ora File for more information.
sqlnet.ora—Oracle profile configuration file for managing database connections. Refer to Parameters for the sqlnet.ora File.
krb5.conf—Kerberos configuration file containing realm and KDC information. Refer to Oracle’s Configuring Kerberos Authentication for details.
File locations
The Oracle plugin resolves configuration files using standard Oracle networking search paths. Set the ORACLE_HOME environment variable to specify where configuration files are located.
When ORACLE_HOME is set to /opt/oracle, the files are found in:
Alternative search paths include:
/home/grafana/.sqlnet.ora/home/grafana/.tnsnames.ora/etc/tnsnames.ora
Configure the data source connection
When setting up the Oracle data source, select TNSNames Entry as the connection method. The name entered into the text field should use the following convention:
/@DBNAMEDBNAME must correspond to an entry in tnsnames.ora.
In the following example configuration file, the connection string is /@XE:
XE =
(DESCRIPTION =
(ADDRESS = (PROTOCOL = TCP)(HOST = krbclient1.plugins.grafana.net)(PORT = 1521))
(CONNECT_DATA =
(SERVER = DEDICATED)
(SERVICE_NAME = XE)
)
)Refer to Configure the Oracle data source for the full configuration walkthrough.
Docker configuration
The following Docker Compose file shows the expected configuration files mapped into a Docker container.
Key volume mappings:
krb5.conf—Kerberos configuration- Ticket cache mapped to the Grafana UID (472)
tnsnames.ora—Oracle connection descriptorssqlnet.ora—Oracle networking parameters
version: '3.7'
services:
grafana:
image: grafana/grafana:latest
ports:
- 3000:3000
volumes:
- ./kerb5_client/krb5.conf:/etc/krb5.conf
- ./ticketcache/krb5cc_1000:/tmp/krb5cc_472
- ./plugin:/var/lib/grafana/plugins/grafana-oracle-datasource
- ./network/admin/tnsnames.ora:/etc/tnsnames.ora
- ./network/admin:/opt/oracle/network/admin
extra_hosts:
krb5.plugins.grafana.net: 172.16.0.4
krbclient1.plugins.grafana.net: 172.16.0.11
environment:
- TERM=linux
- ORACLE_HOME=/opt/oracle
- GF_DATAPROXY_LOGGING=true
- GF_LOG_LEVEL=debug
- GF_LOG_FILTERS=oracle-datasource:debug
# Sets [plugin.grafana-oracle-datasource] poolsize and max_response_size,
# which Grafana forwards to the plugin process
- GF_PLUGIN_GRAFANA_ORACLE_DATASOURCE_POOLSIZE=50
- GF_PLUGIN_GRAFANA_ORACLE_DATASOURCE_MAX_RESPONSE_SIZE=16Kerberos configuration example
The following example shows a basic krb5.conf for Oracle Kerberos authentication.
/opt/oracle/network/admin/krb5.conf:
[libdefaults]
default_realm = PLUGINS.GRAFANA.NET
kdc_timesync = 1
ccache_type = 4
forwardable = true
proxiable = true
fcc-mit-ticketflags = true
[realms]
PLUGINS.GRAFANA.NET = {
kdc = krb5.plugins.grafana.net:9088
admin_server = krb5.plugins.grafana.net:9749
}
[domain_realm]
.plugins.grafana.net = PLUGINS.GRAFANA.NET
plugins.grafana.net = PLUGINS.GRAFANA.NETRefer to Oracle’s Configuring Kerberos Authentication to integrate Oracle with Kerberos.
sqlnet.ora configuration
Key parameters in the sqlnet.ora configuration file:
/opt/oracle/network/admin/sqlnet.ora:
NAMES.DIRECTORY_PATH= (TNSNAMES, EZCONNECT)
SQLNET.AUTHENTICATION_SERVICES=(KERBEROS5)
SQLNET.FALLBACK_AUTHENTICATION=TRUE
SQLNET.AUTHENTICATION_KERBEROS5_SERVICE=oraclesvc
SQLNET.KERBEROS5_CC_NAME=/tmp/krb5cc_472
SQLNET.KERBEROS5_CONF_MIT=TRUE
SQLNET.KERBEROS5_CONF=/etc/krb5.conf
SQLNET.KERBEROS5_CONF_LOCATION=/etc
SQLNET.KERBEROS5_KEYTAB=/etc/v5srvtab

