Enterprise
Last reviewed: May 22, 2026

Oracle Kerberos integration

This document explains how to configure Kerberos authentication for the Oracle data source on both standalone and Docker-based Grafana servers. Kerberos authentication requires the tnsnames.ora file for connection configuration.

Note

Kerberos authentication is not supported in Grafana Cloud. Use the Host with TCP Port connection method with Basic authentication and Private data source connect (PDC) instead.

Oracle configuration files

Kerberos authentication requires three configuration files:

File locations

The Oracle plugin resolves configuration files using standard Oracle networking search paths. Set the ORACLE_HOME environment variable to specify where configuration files are located.

When ORACLE_HOME is set to /opt/oracle, the files are found in:

FilePath
tnsnames.ora/opt/oracle/network/admin
sqlnet.ora/opt/oracle/network/admin
krb5.conf/opt/oracle/network/admin
Kerberos ticket cache/tmp/krb5cc_472

Alternative search paths include:

  • /home/grafana/.sqlnet.ora
  • /home/grafana/.tnsnames.ora
  • /etc/tnsnames.ora

Configure the data source connection

When setting up the Oracle data source, select TNSNames Entry as the connection method. The name entered into the text field should use the following convention:

/@DBNAME

DBNAME must correspond to an entry in tnsnames.ora.

In the following example configuration file, the connection string is /@XE:

ini
XE =
  (DESCRIPTION =
    (ADDRESS = (PROTOCOL = TCP)(HOST = krbclient1.plugins.grafana.net)(PORT = 1521))
    (CONNECT_DATA =
      (SERVER = DEDICATED)
      (SERVICE_NAME = XE)
    )
  )

Refer to Configure the Oracle data source for the full configuration walkthrough.

Docker configuration

The following Docker Compose file shows the expected configuration files mapped into a Docker container.

Key volume mappings:

  • krb5.conf—Kerberos configuration
  • Ticket cache mapped to the Grafana UID (472)
  • tnsnames.ora—Oracle connection descriptors
  • sqlnet.ora—Oracle networking parameters
YAML
version: '3.7'
services:
  grafana:
    image: grafana/grafana:latest
    ports:
      - 3000:3000
    volumes:
      - ./kerb5_client/krb5.conf:/etc/krb5.conf
      - ./ticketcache/krb5cc_1000:/tmp/krb5cc_472
      - ./plugin:/var/lib/grafana/plugins/grafana-oracle-datasource
      - ./network/admin/tnsnames.ora:/etc/tnsnames.ora
      - ./network/admin:/opt/oracle/network/admin
    extra_hosts:
      krb5.plugins.grafana.net: 172.16.0.4
      krbclient1.plugins.grafana.net: 172.16.0.11
    environment:
      - TERM=linux
      - ORACLE_HOME=/opt/oracle
      - GF_DATAPROXY_LOGGING=true
      - GF_LOG_LEVEL=debug
      - GF_LOG_FILTERS=oracle-datasource:debug
      - GF_PLUGINS_ORACLE_DATASOURCE_POOLSIZE=15

Kerberos configuration example

The following example shows a basic krb5.conf for Oracle Kerberos authentication.

/opt/oracle/network/admin/krb5.conf:

ini
[libdefaults]
    default_realm = PLUGINS.GRAFANA.NET
    kdc_timesync = 1
    ccache_type = 4
    forwardable = true
    proxiable = true
    fcc-mit-ticketflags = true
[realms]
    PLUGINS.GRAFANA.NET = {
        kdc = krb5.plugins.grafana.net:9088
        admin_server = krb5.plugins.grafana.net:9749
    }
[domain_realm]
    .plugins.grafana.net = PLUGINS.GRAFANA.NET
    plugins.grafana.net = PLUGINS.GRAFANA.NET

Refer to Oracle’s Configuring Kerberos Authentication to integrate Oracle with Kerberos.

sqlnet.ora configuration

Key parameters in the sqlnet.ora configuration file:

ParameterDescription
SQLNET.AUTHENTICATION_SERVICESSet to (KERBEROS5) to enable Kerberos.
AUTHENTICATION_KERBEROS5_SERVICEThe Kerberos service name for the Oracle database.
SQLNET.KERBEROS5_CC_NAMEPath to the Kerberos ticket cache file.
SQLNET.KERBEROS5_KEYTABPath to the Kerberos keytab file.

/opt/oracle/network/admin/sqlnet.ora:

ini
NAMES.DIRECTORY_PATH= (TNSNAMES, EZCONNECT)
SQLNET.AUTHENTICATION_SERVICES=(KERBEROS5)
SQLNET.FALLBACK_AUTHENTICATION=TRUE
SQLNET.AUTHENTICATION_KERBEROS5_SERVICE=oraclesvc
SQLNET.KERBEROS5_CC_NAME=/tmp/krb5cc_472
SQLNET.KERBEROS5_CONF_MIT=TRUE
SQLNET.KERBEROS5_CONF=/etc/krb5.conf
SQLNET.KERBEROS5_CONF_LOCATION=/etc
SQLNET.KERBEROS5_KEYTAB=/etc/v5srvtab

Additional references