Grant Grafana user Access to view logs from Kubernetes namespace

  • Grafana OSS 8.5.6, willing to upgrade to 9.x.x

  • Grafana stack (Grafana, Tempo, Loki along with Prometheus) used for app observabiliity

  • Grafana stack (Grafana, Tempo, Loki along with Prometheus) used for app observability

  • Different apps are running in K8s different namespaces. e.g. App1 in K8s App1NS, App2 in K8s App2NS, App3 in K8s App3NS. Can we restrict Grafana users to access logs, trace, dashboards/graphs, alerts based on namespaces (one or more) ? e.g. User1 should be able to see/access logs from APP1NS & APP2NS but not from APP3NS

  • As it is not a defect but trying to achieve, I do not have any config/logs to share.

  • If there is a better way to manage multitenancy, please let me know.