I see, another important point to check is what URL you are using to access the service. Specifically, are you accessing it using the service IP, a short hostname, or an FQDN? Grafana can be sensitive to the hostname used because cephadm configures its domain/root_url for the mgmt-gateway setup. If you access it using an IP while Grafana is configured for a hostname/FQDN, the Grafana panels may not work correctly even though the backend services are healthy. You can see the URL configured for grafana by running:
ceph dashboard get-grafana-api-url
On Tue, Sep 15, 2026 at 1:08 PM Robert Sander <r.sander@heinlein-support.de> wrote:
Hi Redouane,
Am 15.09.26 um 12:43 PM schrieb Redouane Kachach:
When mgmt-gateway is deployed, direct external access to Grafana/ Prometheus is intentionally disabled. The monitoring services are expected to be accessed/routed through mgmt-gateway. That's the whole point behind the mgmt-gateway design. Client certs are required bcz when the mgmt-gateway is deployed strict mTLS is enforced for service-to-service communication.
I understand. We did not try to access them directly but through the service IP of the mgmt-gateway service.
Grafana was not displaying the metrics and when investigating further we found timeouts that pointed to mTLS client certificates.
I will try to reproduce the setup in a test cluster.
Regards -- Robert Sander Linux Consultant
Heinlein Consulting GmbH Schwedter Str. 8/9b, 10119 Berlin
https://www.heinlein-support.de
Tel: +49 30 405051 <+49%2030%20405051> - 0 Fax: +49 30 405051 - 19 <+49%2030%2040505119>
Amtsgericht Berlin-Charlottenburg - HRB 220009 B Geschäftsführer: Peer Heinlein - Sitz: Berlin