Thankyou for updating the Grafana port.

The /etc/grafana/custom.ini contains a default key and can contain passwords.

These are public knowledge but may be changed and better to be secure by 
default.

https://github.com/grafana/grafana/pull/2306
https://github.com/grafana/grafana/issues/2126

Could the recent import be edited to do similar or atleast for custom.ini?

IOW
Set files in /etc/grafana to mode 0640 and group ownership to _grafana

They are currently root:wheel 0644 in the previous and most recent 6.2.2 pkg

Reply via email to