npx skills add ...
npx skills add grafana/skills --skill cloud-integrations
Set up, configure, and troubleshoot Grafana Cloud integrations for AWS, Azure, and other cloud providers. Use when the user asks to connect AWS CloudWatch, set up Azure Monitor, configure Confluent Cloud observability, install a Grafana integration, set up hosted exporters, use AWS Firehose for CloudWatch logs, or troubleshoot a cloud integration. Triggers on phrases like "AWS CloudWatch", "Azure Monitor", "Confluent integration", "cloud integration", "hosted exporter", "AWS Firehose", "install integration", "cloud metrics", or "cloud logs".
npx skills add grafana/skills --skill cloud-integrations
Grafana Cloud Integrations connect cloud provider monitoring APIs to your Grafana stack without running your own exporters. Hosted exporters scrape cloud APIs on your behalf and push metrics to your Grafana Cloud stack.
Supported hosted exporters:
/metrics endpoint behind authAWS Firehose receiver - ingests CloudWatch Logs and Metrics Streams pushed via Kinesis Firehose (near real-time, lower latency than API scraping).
In Grafana Cloud: Connections > Add new connection (or Connections > Cloud Provider).
Available paths:
The hosted exporter scrapes CloudWatch API every 60s. Latency: ~1-5 minutes.
Required IAM permissions (minimum):
Setup steps:
Supported namespaces: EC2, RDS, ELB/ALB, S3, Lambda, ECS, SQS, SNS, ElastiCache, Kinesis, DynamoDB, and 50+ others.
Near-real-time metrics and logs via CloudWatch Metric Streams and CloudWatch Logs subscriptions.
Architecture:
Setup:
OpenTelemetry 1.0Terraform for Firehose setup:
Required Azure permissions:
Create a service principal with the Monitoring Reader role on the subscription(s) to monitor.
Setup in Grafana Cloud:
Supported resource types: Virtual Machines, App Service Plans, AKS, Azure SQL, CosmosDB, Storage Accounts, Event Hubs, Service Bus, Application Gateway, and others.
Required Confluent API credentials:
MetricsViewer roleSetup in Grafana Cloud:
Available metrics: Consumer lag, broker request rates, partition counts, replication lag, active controller count, and cluster-level health metrics.
The integration status is also visible in: Connections > [Integration name] > Status
Integration health indicators:
Last successful scrape - should be within the last 2 minutesSeries count - should be non-zero and stableError rate - should be 0%Every integration installs a set of pre-configured dashboards and alert rules automatically.
Find installed dashboards:
Find installed alert rules:
Modify without losing updates:
Hosted exporter not receiving data:
Common errors:
| Error | Cause | Fix |
|---|---|---|
AccessDenied (AWS) | IAM policy missing permissions | Add required actions to the IAM policy |
AuthorizationFailed (Azure) | Service principal missing role | Grant Monitoring Reader on the subscription |
401 Unauthorized (Confluent) | Wrong API credentials | Re-enter credentials; confirm Metrics API key (not Kafka key) |
No metrics found | Wrong namespace/resource type selected | Add the namespace in integration settings |
Scrape timeout | Network restriction | Ensure Grafana Cloud's IPs can reach the cloud provider API |
AWS-specific: CloudWatch API rate limiting
CloudWatch GetMetricData has a rate limit. If you have many resources, enable Metric Streams (Option B) instead of API polling to avoid throttling.
Hosted exporters scrape all metrics by default. Filter to reduce series count and cost.
AWS - select specific namespaces: In integration settings, switch from "All namespaces" to specific ones (e.g. EC2, RDS only).
AWS - filter by resource tags:
Azure - select specific resource types: Only enable the resource types you actually have dashboards for.
Use Adaptive Metrics to aggregate away unused label dimensions:
See the grafana-cloud/adaptive-metrics skill.
CloudWatch Metric Streams → Kinesis Firehose → Grafana Cloud Firehose Receiver
CloudWatch Logs (subscription filter) → Kinesis Firehose → Grafana Cloud Firehose Receiverresource "aws_cloudwatch_metric_stream" "grafana_cloud" {
name = "grafana-cloud-metrics"
role_arn = aws_iam_role.firehose_role.arn
firehose_arn = aws_kinesis_firehose_delivery_stream.grafana.arn
output_format = "opentelemetry1.0"
# Optionally scope to specific namespaces
# include_filter { namespace = "AWS/EC2" }
# include_filter { namespace = "AWS/RDS" }
}
resource "aws_kinesis_firehose_delivery_stream" "grafana" {
name = "grafana-cloud-stream"
destination = "http_endpoint"
http_endpoint_configuration {
url = var.grafana_firehose_endpoint
access_key = var.grafana_firehose_access_key
name = "Grafana Cloud"
content_encoding = "GZIP"
s3_configuration {
role_arn = aws_iam_role.firehose_role.arn
bucket_arn = aws_s3_bucket.firehose_backup.arn
}
}
}# Create service principal
az ad sp create-for-rbac --name grafana-cloud-monitoring \
--role "Monitoring Reader" \
--scopes /subscriptions/<SUBSCRIPTION_ID>
# Output: appId (client ID), password (client secret), tenant# Check in Grafana Explore — query for the integration's job label
# For AWS:
{job="integrations/cloudwatch"}
# For Azure:
{job="integrations/azure-monitor"}
# Check metric arrival (replace with your stack's Prometheus endpoint)
curl -s -H "Authorization: Bearer <USER>:<API_KEY>" \
"https://prometheus-prod-XX-XX-X.grafana.net/api/prom/api/v1/labels" | \
jq '.data | map(select(startswith("aws_") or startswith("azure_")))'# Check the integration status via Grafana Cloud API
curl -s -H "Authorization: Bearer <STACK_ID>:<API_TOKEN>" \
"https://integrations-api.grafana.net/api/v1/integrations" | \
jq '.integrations[] | {name, status, lastScrapeTime, errorMessage}'# In exporter configuration, add tag filters
discovery:
- type: AWS/EC2
filters:
- key: Environment
values: ["production"]