Another "guide" pushing the shiny OAuth2 bandwagon. Fine. Here's what actually matters when you wire Grafana to Google Workspace.
Everyone glosses over the mapping. Grafana expects specific claims, Google sends something else. Your config will fail silently if you don't get this right.
```ini
[auth.generic_oauth]
enabled = true
name = Google
allow_sign_up = false
client_id = YOUR_CLIENT_ID
client_secret = YOUR_SECRET
scopes = openid email profile
auth_url = https://accounts.google.com/o/oauth2/auth
token_url = https://https://accounts.google.com/o/oauth2/token
api_url = https://www.googleapis.com/oauth2/v1/userinfo
role_attribute_path = contains(groups[*], 'grafana-admins') && 'Admin' || contains(groups[*], 'grafana-editors') && 'Editor' || 'Viewer'
```
Key points everyone misses:
* That `role_attribute_path` is JMESPath. It won't work unless you pass groups via a custom claim in Google's OIDC config.
* Set `allow_sign_up = false`. Manage users via Google Groups, not random sign-ups.
* The "verified" email flag from Google is crucial. Grafana's default config might ignore it.
Also, your reverse proxy (nginx, Apache) needs to pass headers correctly. Otherwise, you'll get infinite redirects.
```nginx
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Forwarded-Host $host;
```
Test with `curl -v` before declaring victory. Check the logs, not the UI.
-- old school
-- old school
Yes, that custom claim for groups is the biggest hurdle. You need to map a Google Workspace group to a custom OIDC claim in your admin console first, or the JMESPath will have nothing to check.
I'd also add a quick test: after you set it up, curl the `api_url` endpoint with a valid token to see the exact JSON structure you're getting. Grafana's debug logs help, but seeing the raw payload confirms the `groups` array is actually present.
Oh, and on the reverse proxy point, don't forget `proxy_set_header X-Forwarded-Proto https;` if you terminate TLS there. Missing that can cause weird redirect loops.
Cloud cost nerd. No, I don't use Reserved Instances.