---
title: Charmhub | Deploy Grafana Agent using Charmhub - The Open Operator Collection
description: Deploy the latest version of Grafana Agent on any cloud.
url: https://charmhub.io/grafana-agent/docs/Security
---

# Grafana Agent

[Canonical Observability](https://charmhub.io/publisher/observability "View all packages from Canonical Observability")

* [Canonical Observability](https://charmhub.io/publisher/observability "View all packages from Canonical Observability")

Platform:

24.04

22.04

20.04

0.44/stable rev817-1-g0adb5a8

```
juju deploy grafana-agent --channel 0.44/stable
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

---

#### Relevant links

* [Homepage](https://charmhub.io/grafana-agent)

---

#### Contacts

* [Submit a bug](https://github.com/canonical/grafana-agent-operator/issues)

---

Share your thoughts on this charm with the community on discourse.

[Join the discussion](https://discourse.charmhub.io/)

This document provides cryptographic documentation for the COS-Lite bundle.
Its purpose is to track the exposure of charm code to cryptographic attack vectors.

What is not included in this document and regarded as out of scope:

* Workload code (refer to the workloads’ cryptographic documentation)
* Data at rest encryption

The COS-Lite charms have a very similar exposure. Unless specified otherwise in the charm’s own documentation, this cryptographic documentation applies to all.

# Usage of cryptographic technology

COS-Lite charm code uses cryptographic technology for mainly two purposes:

* enabling TLS communication between their workloads
* securing admin login to their workloads

## [Cryptographic use internal to cos-lite](https://charmhub.io/grafana-agent/docs/Security#p-32937-cryptographic-use-internal-to-cos-lite)

COS-Lite charm code can use cryptographic technology to generate a private key to sign their TLS certificate requests. They do so via the [tls-certificates-interface](https://github.com/canonical/tls-certificates-interface) which in turn uses the [cryptography](https://pypi.org/project/cryptography/) python library and Juju secrets to exchange data with the CA.

Also, charms that deal with large configuration files use sha256 to efficiently detect diffs in them.

## [Cryptographic use in how cos-lite communicates externally](https://charmhub.io/grafana-agent/docs/Security#p-32937-cryptographic-use-in-how-cos-lite-communicates-externally)

COS-Lite charm users use passwords generated by charm code that depends on python’s [`secrets`](https://docs.python.org/3/library/secrets.html) module. No configuration is exposed to the user.
These passwords secure admin login to the user-facing server provided by the workload. For example, in [grafana-k8s](https://github.com/canonical/grafana-k8s-operator/blob/main/src/charm.py#L1289).

Additionally, charms supporting BasicAuth [such as traefik](https://discourse.charmhub.io/t/15407) accept a `<username>:<hashed-password>` config option by which the user can configure basic authentication. The supported hashing algorithm are MD5, SHA1, or BCrypt, [as per official documentation](https://doc.traefik.io/traefik/middlewares/http/basicauth/#general). Also following the official guidelines, we recommend cloud admins to use `htpasswd` for hashing the password and formatting the configuration string.

# List of packages and cryptographic tech used

* to generate private keys for setting up TLS communication: the `rsa.generate_private_key` function from the [`rsa` package](https://stuvel.eu/software/rsa/). They use the following parameters (hardcoded, not user-configurable):
  + `key_size = 2048`
  + `public_exponent = 65537`
* to generate admin passwords for user admin login: the [`secrets`](https://docs.python.org/3/library/secrets.html) module from the python standard library. See for example: [usage in grafana](https://github.com/canonical/grafana-k8s-operator/blob/main/src/charm.py#L1289).

---
