amazon-managed-grafana-roadmap icon indicating copy to clipboard operation
amazon-managed-grafana-roadmap copied to clipboard

Support custom Content Security Policy template

Open midoxc opened this issue 1 year ago • 7 comments

To use the Parca plugin with AMG, I need to be able to add to the Content-Security-Policy used to allow connections from a custom endpoint where the parca server is deployed.

https://grafana.com/docs/grafana/latest/administration/configuration/#content_security_policy

This config would need to be exposed in some way.

midoxc avatar Jun 20 '24 17:06 midoxc

Yes, please, we wish to include external images in our dashboards and are unable to do so.

ZoneMR avatar Jul 04 '24 14:07 ZoneMR

This would be useful! Thanks!

pavolzibrita avatar Jul 10 '24 17:07 pavolzibrita

We have a usecase for this as well which is blocked due to this.

sadnan1994 avatar Jul 11 '24 14:07 sadnan1994

@sadnan1994 Can you share details of your use-case?

VermaPriyanka avatar Jul 12 '24 14:07 VermaPriyanka

Hi @VermaPriyanka . We have the same requirement and a simple use case would be importing a database of user profiles and wanting to display each user's profile picture alongside their details. The profile picture may come from a 3rd party domain, which would need to be added to the CSP img-src list. This is a serious limitation for us that we were easily able to overcome on our self-hosted Grafana instance.

rawnsley avatar Sep 23 '24 15:09 rawnsley

Hi @VermaPriyanka, I would also like to use the Business Forms plugin but facing the issue of not being able to execute the javascript code inside it. This was easily achieved in the self managed grafana. Can you give us a roadmap of when this might be added?

LoLZeS666 avatar Apr 08 '25 06:04 LoLZeS666

I have mentioned this in my issue also https://github.com/aws/amazon-managed-grafana-roadmap/issues/97

Please ! this is causing weird workarounds. In my opinion, its a bigger security risk to go through workarounds then have custom content security policies

I can give you a very good use case - there is a possibility of creating 3D IoT factory charts that is quite meaningful for anybody looking to see whats happening on factory production line.

stefan-stojanovic-s avatar Aug 22 '25 11:08 stefan-stojanovic-s