Official agent skill

Cloud Integrations

by grafana in grafana/skills

Set up, configure, and troubleshoot Grafana Cloud integrations for AWS, Azure, and other cloud providers.

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Cloud Integrations

skills CLI
$ npx skills add grafana/skills --skill cloud-integrations -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install grafana/skills cloud-integrations --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/grafana/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/grafana-cloud/cloud-integrations .claude/skills/cloud-integrations && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloud-integrations
GitHub stars
278
Token cost
~2.5k tokens
SKILL.md length
838 words
Files
1
Skills in repo
51
Repo updated
First seen
Licence
Apache-2.0

At a glance

Set up, configure, and troubleshoot Grafana Cloud integrations for AWS, Azure, and other cloud providers.

  • Works in 8 steps: Navigate to Connections → AWS CloudWatch integration → Azure Monitor integration → …
  • The user asks to connect AWS CloudWatch
  • SKILL.md covers Step 1: Navigate to Connections, Step 2: AWS CloudWatch…, Step 3: Azure Monitor… and Step 4: Confluent Cloud…, plus 5 more sections
  • Calls curl, jq and az; reaches prometheus-prod-xx-xx-x.grafana.net and integrations-api.grafana.net; needs API_KEY and API_TOKEN

What it does

Cloud Integrations is an agent skill from grafana/skills, published by the product's own GitHub organization. Set up, configure, and troubleshoot Grafana Cloud integrations for AWS, Azure, and other cloud providers. Use when the user asks to connect AWS CloudWatch, set up Azure Monitor, configure Confluent Cloud observability, install a Grafana integration, set up hosted exporters, use AWS Firehose for CloudWatch logs, or troubleshoot a cloud integration. Triggers on phrases like "AWS CloudWatch", "Azure Monitor", "Confluent integration", "cloud integration", "hosted exporter", "AWS Firehose", "install integration"…

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Monitoring and alerting. It works with Grafana, Amazon Web Services, Azure Monitor and Microsoft Azure. The licence is Apache-2.0.

When your agent uses it

  • The user asks to connect AWS CloudWatch
  • Set up Azure Monitor
  • Configure Confluent Cloud observability
  • Install a Grafana integration

Example prompts

  • “AWS CloudWatch”
  • “Azure Monitor”
  • “Confluent integration”
  • “/cloud-integrations”

Requirements

  • A credential in API_KEY
  • A credential in API_TOKEN

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. Navigate to Connections
  2. AWS CloudWatch integration
  3. Azure Monitor integration
  4. Confluent Cloud integration
  5. Verify the integration is working
  6. Pre-built dashboards and alerts
  7. Troubleshoot integration failures
  8. Reduce costs with metric filtering

What it can do on your machine

Read from SKILL.md and the folder at commit 1ccacf2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq
    • az

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • prometheus-prod-xx-xx-x.grafana.net
    • integrations-api.grafana.net

    Also links to:

    • grafana.com
    • github.com
    • docs.aws.amazon.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloud Integrations loads about 2.5k tokens when it runs. Until then it costs about 142 tokens; SKILL.md has 838 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~142
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from grafana/skills at commit 1ccacf2, republished under its Apache-2.0 licence (© grafana). 838 words, ~2,496 tokens.

Download SKILL.mdSave it as .claude/skills/cloud-integrations/SKILL.md (or your agent's skills folder).
name
cloud-integrations
description
Set up, configure, and troubleshoot Grafana Cloud integrations for AWS, Azure, and other cloud providers. Use when the user asks to connect AWS CloudWatch, set up Azure Monitor, configure Confluent Cloud observability, install a Grafana integration, set up hosted exporters, use AWS Firehose for CloudWatch logs, or troubleshoot a cloud integration. Triggers on phrases like "AWS CloudWatch", "Azure Monitor", "Confluent integration", "cloud integration", "hosted exporter", "AWS Firehose", "install integration", "cloud metrics", or "cloud logs".
license
Apache-2.0

Grafana Cloud Integrations

Grafana Cloud Integrations connect cloud provider monitoring APIs to your Grafana stack without running your own exporters. Hosted exporters scrape cloud APIs on your behalf and push metrics to your Grafana Cloud stack.

Supported hosted exporters:

  • AWS CloudWatch - all CloudWatch namespaces via YACE (Yet Another CloudWatch Exporter)
  • Azure Monitor - Azure resource metrics via the Azure Monitor API
  • Confluent Cloud - Kafka cluster metrics via the Confluent Metrics API
  • Generic HTTP endpoint - any Prometheus-format /metrics endpoint behind auth

AWS Firehose receiver - ingests CloudWatch Logs and Metrics Streams pushed via Kinesis Firehose (near real-time, lower latency than API scraping).


Step 1: Navigate to Connections

In Grafana Cloud: Connections > Add new connection (or Connections > Cloud Provider).

Available paths:

  • AWS CloudWatch - hosted exporter + optional Firehose receiver
  • Azure Monitor - hosted exporter
  • Confluent Cloud - hosted exporter
  • All integrations - full catalog including Linux, MySQL, Kubernetes, etc.

Step 2: AWS CloudWatch integration

Option A: Hosted exporter (polling)

The hosted exporter scrapes CloudWatch API every 60s. Latency: ~1-5 minutes.

Required IAM permissions (minimum):

json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "cloudwatch:GetMetricData",
        "cloudwatch:GetMetricStatistics",
        "cloudwatch:ListMetrics",
        "tag:GetResources",
        "ec2:DescribeInstances",
        "ec2:DescribeRegions"
      ],
      "Resource": "*"
    }
  ]
}

Setup steps:

  1. Create an IAM user or role with the policy above
  2. Generate an access key pair (for IAM user) or configure cross-account role assumption
  3. In Grafana Cloud: Connections > AWS > Configure hosted exporter
  4. Enter: AWS Access Key ID, Secret Access Key, region(s), CloudWatch namespaces to scrape
  5. Grafana provisions the exporter and begins scraping within 2-3 minutes

Supported namespaces: EC2, RDS, ELB/ALB, S3, Lambda, ECS, SQS, SNS, ElastiCache, Kinesis, DynamoDB, and 50+ others.

Option B: AWS Firehose receiver (streaming)

Near-real-time metrics and logs via CloudWatch Metric Streams and CloudWatch Logs subscriptions.

Architecture:

CloudWatch Metric Streams → Kinesis Firehose → Grafana Cloud Firehose Receiver
CloudWatch Logs (subscription filter) → Kinesis Firehose → Grafana Cloud Firehose Receiver

Setup:

  1. In Grafana Cloud: Connections > AWS > Firehose receiver
  2. Grafana provides an HTTPS endpoint URL and access token
  3. In AWS, create a Kinesis Firehose delivery stream:
    • Destination: HTTP endpoint
    • Endpoint URL: (from step 2)
    • Access key: (from step 2)
    • Content encoding: GZIP
  4. Create a CloudWatch Metric Stream pointing at the Firehose stream:
    • Output format: OpenTelemetry 1.0
    • Namespaces: select or include all
  5. For logs: add a CloudWatch Logs subscription filter pointing at the Firehose stream

Terraform for Firehose setup:

hcl
resource "aws_cloudwatch_metric_stream" "grafana_cloud" {
  name          = "grafana-cloud-metrics"
  role_arn      = aws_iam_role.firehose_role.arn
  firehose_arn  = aws_kinesis_firehose_delivery_stream.grafana.arn
  output_format = "opentelemetry1.0"

  # Optionally scope to specific namespaces
  # include_filter { namespace = "AWS/EC2" }
  # include_filter { namespace = "AWS/RDS" }
}

resource "aws_kinesis_firehose_delivery_stream" "grafana" {
  name        = "grafana-cloud-stream"
  destination = "http_endpoint"

  http_endpoint_configuration {
    url            = var.grafana_firehose_endpoint
    access_key     = var.grafana_firehose_access_key
    name           = "Grafana Cloud"
    content_encoding = "GZIP"

    s3_configuration {
      role_arn   = aws_iam_role.firehose_role.arn
      bucket_arn = aws_s3_bucket.firehose_backup.arn
    }
  }
}

Step 3: Azure Monitor integration

Required Azure permissions:

Create a service principal with the Monitoring Reader role on the subscription(s) to monitor.

bash
# Create service principal
az ad sp create-for-rbac --name grafana-cloud-monitoring \
  --role "Monitoring Reader" \
  --scopes /subscriptions/<SUBSCRIPTION_ID>

# Output: appId (client ID), password (client secret), tenant

Setup in Grafana Cloud:

  1. Connections > Azure > Configure hosted exporter
  2. Enter: Tenant ID, Client ID, Client Secret, Subscription IDs
  3. Select resource types to monitor (VMs, App Services, AKS, SQL, etc.)
  4. The exporter begins scraping within 2-3 minutes

Supported resource types: Virtual Machines, App Service Plans, AKS, Azure SQL, CosmosDB, Storage Accounts, Event Hubs, Service Bus, Application Gateway, and others.


Step 4: Confluent Cloud integration

Required Confluent API credentials:

  1. In Confluent Cloud: Environment > API Keys (or Cloud API Keys for organization-level)
  2. Create a Metrics API key (not a Kafka API key) with MetricsViewer role
  3. Note the API Key and Secret

Setup in Grafana Cloud:

  1. Connections > Confluent > Configure hosted exporter
  2. Enter: Confluent API Key, API Secret, Environment ID(s), Cluster ID(s)
  3. The exporter scrapes the Confluent Metrics API every 60s

Available metrics: Consumer lag, broker request rates, partition counts, replication lag, active controller count, and cluster-level health metrics.


Show full SKILL.md (318 more words)Show less

Step 5: Verify the integration is working

bash
# Check in Grafana Explore — query for the integration's job label
# For AWS:
{job="integrations/cloudwatch"}

# For Azure:
{job="integrations/azure-monitor"}

# Check metric arrival (replace with your stack's Prometheus endpoint)
curl -s -H "Authorization: Bearer <USER>:<API_KEY>" \
  "https://prometheus-prod-XX-XX-X.grafana.net/api/prom/api/v1/labels" | \
  jq '.data | map(select(startswith("aws_") or startswith("azure_")))'

The integration status is also visible in: Connections > [Integration name] > Status

Integration health indicators:

  • Last successful scrape - should be within the last 2 minutes
  • Series count - should be non-zero and stable
  • Error rate - should be 0%

Step 6: Pre-built dashboards and alerts

Every integration installs a set of pre-configured dashboards and alert rules automatically.

Find installed dashboards:

  • Dashboards > Browse > folder named after the integration (e.g. "AWS CloudWatch")

Find installed alert rules:

  • Alerting > Alert rules > filter by datasource or folder

Modify without losing updates:

  1. Do not edit the provisioned dashboards directly (they may be overwritten on updates)
  2. Duplicate the dashboard (Dashboard settings > Save as copy)
  3. Edit the copy

Step 7: Troubleshoot integration failures

Hosted exporter not receiving data:

bash
# Check the integration status via Grafana Cloud API
curl -s -H "Authorization: Bearer <STACK_ID>:<API_TOKEN>" \
  "https://integrations-api.grafana.net/api/v1/integrations" | \
  jq '.integrations[] | {name, status, lastScrapeTime, errorMessage}'

Common errors:

ErrorCauseFix
AccessDenied (AWS)IAM policy missing permissionsAdd required actions to the IAM policy
AuthorizationFailed (Azure)Service principal missing roleGrant Monitoring Reader on the subscription
401 Unauthorized (Confluent)Wrong API credentialsRe-enter credentials; confirm Metrics API key (not Kafka key)
No metrics foundWrong namespace/resource type selectedAdd the namespace in integration settings
Scrape timeoutNetwork restrictionEnsure Grafana Cloud's IPs can reach the cloud provider API

AWS-specific: CloudWatch API rate limiting

CloudWatch GetMetricData has a rate limit. If you have many resources, enable Metric Streams (Option B) instead of API polling to avoid throttling.


Step 8: Reduce costs with metric filtering

Hosted exporters scrape all metrics by default. Filter to reduce series count and cost.

AWS - select specific namespaces: In integration settings, switch from "All namespaces" to specific ones (e.g. EC2, RDS only).

AWS - filter by resource tags:

yaml
# In exporter configuration, add tag filters
discovery:
  - type: AWS/EC2
    filters:
      - key: Environment
        values: ["production"]

Azure - select specific resource types: Only enable the resource types you actually have dashboards for.

Use Adaptive Metrics to aggregate away unused label dimensions: See the grafana-cloud/adaptive-metrics skill.


References

© grafana, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/grafana-cloud/cloud-integrations of grafana/skills.

Open the folder on GitHubat commit 1ccacf2

Compare with similar skills

Cloud Integrations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloud Integrations compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloud Integrations this skillgrafana/skills278—~2.5kAutomated safety check: PassApache-2.0
Azure Managed GrafanaMicrosoftDocs/Agent-Skills775—~2kAutomated safety check: PassCC-BY-4.0
Azure Mgmt Applicationinsights Dotnetmicrosoft/skills3.1k6 repos~4.6kAutomated safety check: PassMIT
Fleet Intelligencemicrosoft/physical-ai-toolchain122—~598Automated safety check: PassMIT
Cloud Devopsdavila7/claude-code-templates32k4 repos~1.4kAutomated safety check: PassMIT
Appinsights Instrumentationmicrosoft/GitHub-Copilot-for-Azure2551 repos~951Automated safety check: PassMIT

Similar skills

  • Azure Managed Grafana

    MicrosoftDocs/Agent-Skills

    Official

    Expert knowledge for Azure Managed Grafana development including troubleshooting, decision making, limits & quotas, security, configuration, and integrations & coding patterns.

    775 GitHub stars~2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Official

    Azure Application Insights SDK for .NET. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 6 repos~4.6k tokens
    DevOps & CloudAuto-check passed
  • Fleet Intelligence

    microsoft/physical-ai-toolchain

    Official

    Monitor robot fleet telemetry via Azure IoT Operations, drift detection, Grafana dashboards, and Fabric analytics

    122 GitHub stars~598 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Cloud Devops

    davila7/claude-code-templates

    Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.

    32k GitHub starsUsed in 4 repos~1.4k tokens
    DevOps & CloudAuto-check passed
  • Appinsights Instrumentation

    microsoft/GitHub-Copilot-for-Azure

    Official

    Guidance for instrumenting webapps with Azure Application Insights.

    255 GitHub starsUsed in 1 repo~951 tokens
    DevOps & CloudAuto-check passed
  • Dt Obs Network Flows

    Dynatrace/dynatrace-for-ai

    Network flow analysis in Dynatrace across three sources: OneAgent flows (host/process/pod-to-peer connections in the defaultnetworkflows Grail bucket), NetFlow/IPFIX/sFlow (via an OpenTelemetry…

    161 GitHub starsUsed in 1 repo~2k tokens
    DevOps & CloudAuto-check passed

More from grafana/skills

All 51 skills in this repo
  • K6 Docs

    grafana/skills

    Official

    Write or review k6 documentation across the three k6 repositories - k6-DefinitelyTyped (TypeScript types), k6-docs (user documentation), and k6 (release notes / changelog).

    278 GitHub stars~678 tokensUpdated today
    Auto-check passed
  • Alerting Irm

    grafana/skills

    Official

    Configure Grafana Alerting, Incident Response Management (IRM), and SLOs end-to-end — provisions Grafana-managed and data-source-managed alert rules, contact points (Slack/PagerDuty/email/webhook)…

    278 GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Dashboarding

    grafana/skills

    Official

    Build, modify, and ship Grafana dashboards as JSON via the HTTP API — panel types (timeseries / stat / gauge / table / heatmap / logs / traces / node-graph), gridPos 24-column layout, units…

    278 GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • K6 Perf Test Website

    grafana/skills

    Official

    A skill your agent uses when the user wants to performance-test, load-test, or stress-test a public website end-to-end with k6.

    278 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Promql

    grafana/skills

    Official

    Write, validate, and optimize PromQL for Prometheus / Grafana Mimir / Grafana Cloud Metrics.

    278 GitHub starsUsed in 1 repo~1.1k tokens
    Auto-check passed
  • Adaptive Metrics

    grafana/skills

    Official

    Cut Grafana Cloud Metrics cost by shrinking active-series count with Adaptive Metrics aggregation rules — auto-recommendations from query history, custom exact/regex rules, label-drop config…

    278 GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Categories

Questions about Cloud Integrations

What does Cloud Integrations do?

Set up, configure, and troubleshoot Grafana Cloud integrations for AWS, Azure, and other cloud providers. Cloud Integrations is an agent skill from grafana/skills, published by the product's own GitHub organization. Set up, configure, and troubleshoot Grafana Cloud integrations for AWS, Azure, and other cloud providers.

When should I use Cloud Integrations?

Cloud Integrations fits situations like: the user asks to connect AWS CloudWatch; set up Azure Monitor; configure Confluent Cloud observability; install a Grafana integration.

How do I install Cloud Integrations in Claude Code?

Run `npx skills add grafana/skills --skill cloud-integrations -a claude-code`. Or copy the skill folder (skills/grafana-cloud/cloud-integrations in grafana/skills) into .claude/skills/cloud-integrations in your project. Claude Code loads it when a task matches its description.

How do I install Cloud Integrations in Codex?

Run `npx skills add grafana/skills --skill cloud-integrations -a codex`. Or copy the skill folder (skills/grafana-cloud/cloud-integrations in grafana/skills) into .agents/skills/cloud-integrations in your project. Codex loads it when a task matches its description.

Can I use Cloud Integrations in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add grafana/skills --skill cloud-integrations -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloud-integrations, .gemini/skills/cloud-integrations, .github/skills/cloud-integrations and .opencode/skills/cloud-integrations in your project.

What does Cloud Integrations need to run?

Going by SKILL.md and its folder, Cloud Integrations needs the command-line tools its instructions call (curl, jq and az) and credentials named API_KEY and API_TOKEN. Our summary lists: A credential in API_KEY; A credential in API_TOKEN.

Does Cloud Integrations access the network?

SKILL.md names 5 domains. In commands or code: prometheus-prod-xx-xx-x.grafana.net and integrations-api.grafana.net; the agent is likely to contact these when it follows the instructions. As links in the text: grafana.com, github.com and docs.aws.amazon.com. This is read from the text; nothing was executed.

Is Cloud Integrations safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloud Integrations use?

Cloud Integrations is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloud Integrations use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cloud Integrations?

Skills that share tags, products or a category with Cloud Integrations: Azure Managed Grafana (MicrosoftDocs/Agent-Skills, 775 stars), Azure Mgmt Applicationinsights Dotnet (microsoft/skills, 3.1k stars), Fleet Intelligence (microsoft/physical-ai-toolchain, 122 stars) and Cloud Devops (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloud Integrations?

grafana (a GitHub organization, an official publisher) maintains it in grafana/skills, which has 278 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 6, 2026.

Source: grafana/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.