Enable "guest account" in Zabbix #13488

Closed
opened 2026-08-03 04:43:45 +00:00 by praiskup · 8 comments
Member

Description of request

It would be great to have 'anonymous' guest access configured for Zabbix. We have a few ways at Copr to propagate status checks to downstream monitoring tools, but getting it working again after our migration from Nagios to Zabbix is non-trivial. Generally speaking, having Nagios open was very convenient—anyone in the community could quickly check if something was broken without having to log in. It would be awesome if we could recreate that experience using documented guest access."

### Description of request It would be great to have 'anonymous' guest access configured for Zabbix. We have a few ways at Copr to propagate status checks to downstream monitoring tools, but getting it working again after our migration from Nagios to Zabbix is non-trivial. Generally speaking, having Nagios open was very convenient—anyone in the community could quickly check if something was broken without having to log in. It would be awesome if we could recreate that experience using documented guest access."
Member

I'll take a look, last time I was looking at this, I think it was not possible.

However, also note that any FAS account can log in with guest permissions via the "SAML login" link on the login page, and I presume most community members will have a FAS account, so they can still check. I agree that's not the same as no-login, but it's pretty close ;)

I'll take a look, last time I was looking at this, I think it was not possible. However, also note that *any* FAS account can log in with guest permissions via the "SAML login" link on the login page, and I presume most community members will have a FAS account, so they can still check. I agree that's not the same as no-login, but it's pretty close ;)
Author
Member

The point is to have a naive way to forward statuses ... Considering there's an account guest with password guest, it's almost trivial to make our Red Hat grafana work again. Having a service account, doing SAML or so, is a bit more complicated way for the thing we need.

The point is to have a naive way to forward statuses ... Considering there's an account `guest` with password `guest`, it's almost trivial to make our Red Hat grafana work again. Having a service account, doing SAML or so, is a bit more complicated way for the thing we need.
Member

I can probably re-enable the guest internal account, if that's sufficient? There's a Zabbix plugin for Grafana I believe, so then you'd be able to hook it up with guest access?

I can probably re-enable the `guest` internal account, if that's sufficient? There's a Zabbix plugin for Grafana I believe, so then you'd be able to hook it up with guest access?
Author
Member

Heh, not sure what is "internal account"? It may be sufficient, but dunno. Not sure I have enough spare cycles to work with the zabbix plugin for grafana, well ... I'd just use the previous mechanism to re-enable our metrics.

Heh, not sure what is "internal account"? It may be sufficient, but dunno. Not sure I have enough spare cycles to work with the zabbix plugin for grafana, well ... I'd just use the previous mechanism to re-enable our metrics.
Member

"Internal" just means local auth, not FAS. So a basic username & password. If that gives you want you need, I'm OK with enabling that.

"Internal" just means local auth, not FAS. So a basic username & password. If that gives you want you need, I'm OK with enabling that.
Author
Member

Originally I thought we could have a "generally known" user auth (like guest user, with password guest), for any random user (seems like worth documenting for a general passerby). But if you want to generate one user/pass pair specificially for us, I don't object.

Originally I thought we could have a "generally known" user auth (like `guest` user, with password `guest`), for any random user (seems like worth documenting for a general passerby). But if you want to generate one user/pass pair specificially for us, I don't object.
Member

well it will be a generic user, but it's all a bit arbitrary because everyone has guest access via FAS anyway 😁

I'll ping you with login details separately.

well it will be a generic user, but it's all a bit arbitrary because everyone has guest access via FAS anyway 😁 I'll ping you with login details separately.
Member

Seems to work, closing this :)

Seems to work, closing this :)
Sign in to join this conversation.
No milestone
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
infra/tickets#13488
No description provided.