Skip to main content

Grafana OnCall Provider

Grafana OnCall is the recommended provider for self-hosted hrida-ai-studio deployments. It runs in the same Docker Compose stack as hrida-ai-studio, sharing the existing PostgreSQL and Redis containers.


What You Get​

  • On-call rotation schedules and escalation policies
  • Alert routing from Prometheus, Grafana alerting, or any HTTP integration
  • Incident timeline with full message history
  • MCP tool server via hrida-mcpo so agents can list, acknowledge, and resolve incidents

Prerequisites​

  • docker-compose.yaml already running (hrida-ai-studio + postgres + redis-valkey + keycloak)
  • Docker Compose v2
  • docker-compose.otel.yaml if you want Grafana UI at port 3001

Step 1 — Environment Variables​

Add to your .env file:

# OnCall internal secrets — generate random strings of the specified length
ONCALL_SECRET_KEY=<50-character random string>
ONCALL_MIRAGE_SECRET_KEY=<50-character random string>
ONCALL_MIRAGE_CIPHER_IV=<exactly 16 characters>

# Filled in after steps 4 and 5 below
GRAFANA_ONCALL_TOKEN=
ONCALL_API_TOKEN=

# Webhook shared secret — create any random string
HRIDA_ONCALL_WEBHOOK_TOKEN=<random string>

Step 2 — Start the Stack​

docker compose \
  -f docker-compose.yaml \
  -f docker-compose.oncall.yaml \
  up -d

Add -f docker-compose.otel.yaml to also get the Grafana UI.

What happens on first start:

ContainerRoleExits after?
oncall-db-initCreates the oncall database in your existing postgresYes
oncall-migrateRuns schema migrationsYes
oncallOnCall API server (port 8090)No — stays running
oncall-celeryBackground worker (escalations, notifications)No — stays running
hrida-mcpo-oncallMCP tool server wrapping OnCall API (port 8091)No — stays running

Step 3 — Verify OnCall is Running​

http://localhost:8090    # OnCall API (JSON, not a UI)
http://localhost:3001 # Grafana UI (only if using docker-compose.otel.yaml)

Step 4 — Install the OnCall Plugin in Grafana​

This step is only needed if you are using Grafana (docker-compose.otel.yaml)

If you don't need the Grafana UI, skip to Step 5.

  1. Open http://localhost:3001 and log in with admin / admin@123.
  2. Go to Administration → Plugins, search for Grafana OnCall.
  3. Click Install, then Enable.
  4. When prompted for the OnCall API URL, enter http://oncall:8090 (Docker internal network).
  5. Create a Service Account with the Admin role.
  6. Generate a token, then set GRAFANA_ONCALL_TOKEN in your .env and restart:
docker compose -f docker-compose.yaml -f docker-compose.oncall.yaml restart oncall oncall-celery

Step 5 — Create an OnCall API Token​

  1. Open the OnCall UI (via Grafana → OnCall menu, or http://localhost:8090).
  2. Go to Settings → API Tokens.
  3. Create a token — copy it and set ONCALL_API_TOKEN in your .env.
  4. Restart hrida-ai-studio:
docker compose -f docker-compose.yaml restart hrida-ai-studio

Step 6 — Configure the Provider in hrida-ai-studio​

  1. Go to Admin Panel → Incidents → Providers.
  2. Click + Add Provider and select Grafana OnCall.
  3. Fill in:
    • Name: e.g. Production OnCall
    • OnCall API URL: http://oncall:8080 (Docker network) or your external URL
    • API Token: the token from Step 5
    • Webhook Secret: the value of HRIDA_ONCALL_WEBHOOK_TOKEN from your .env
  4. Click Save — the card shows the Webhook URL.

Step 7 — Configure the Outgoing Webhook in OnCall​

This tells OnCall to POST state changes to hrida-ai-studio.

  1. In the OnCall UI, go to Outgoing Webhooks → Create.
  2. Set:
FieldValue
URLThe Webhook URL from the provider card
HTTP MethodPOST
Trigger typeAlert group status change
Authorization headerBearer <HRIDA_ONCALL_WEBHOOK_TOKEN>
  1. Save. OnCall will now POST to hrida-ai-studio on every incident state change.
Legacy webhook URL

If you had hrida-ai-studio configured before the plugin system was added, your OnCall webhook may still point to /api/v1/webhooks/oncall. This legacy URL still works — it automatically redirects to your first enabled OnCall provider.


Webhook Authentication​

OnCall sends a Bearer token in the Authorization header:

Authorization: Bearer <HRIDA_ONCALL_WEBHOOK_TOKEN>

hrida-ai-studio validates this with a constant-time comparison (hmac.compare_digest) against the webhook_secret stored in the provider config.


Agent Tools (via hrida-mcpo)​

Add the mcpo sidecar as a tool server in Admin Panel → Settings → Tool Servers:

http://hrida-mcpo-oncall:8000   (Docker internal network)
http://localhost:8091 (host machine)
ToolDescription
list_alert_groupsList incidents filtered by state
get_alert_groupGet full details of one incident
acknowledge_alert_groupAcknowledge a firing incident
resolve_alert_groupResolve an incident
list_schedulesList on-call rotation schedules
list_usersList users registered in OnCall
list_on_call_shiftsList upcoming on-call shifts

Ports​

ServiceDefault portOverride env var
OnCall API8090ONCALL_PORT
hrida-mcpo-oncall8091MCPO_ONCALL_PORT
Grafana UI3001(otel stack)

Environment Variable Reference​

VariableRequiredDescription
ONCALL_SECRET_KEYYes50-char secret for OnCall's Django app
ONCALL_MIRAGE_SECRET_KEYYes50-char secret for encrypted DB fields
ONCALL_MIRAGE_CIPHER_IVYesExactly 16-char IV for encryption
GRAFANA_ONCALL_TOKENYes (if using Grafana UI)Grafana service-account token
HRIDA_ONCALL_WEBHOOK_TOKENYesShared secret on outgoing webhook
ONCALL_API_TOKENYesOnCall API key for the incidents panel
ONCALL_PORTNoExternal port (default: 8090)
MCPO_ONCALL_PORTNomcpo port (default: 8091)
ONCALL_BASE_URLNoPublic URL for OnCall callbacks (default: http://localhost:8090)

Troubleshooting​

Incidents panel shows "No providers configured" → You haven't saved an OnCall provider yet in Admin Panel → Incidents → Providers.

Webhook delivers 401 Unauthorized → The Authorization: Bearer ... header in OnCall's outgoing webhook doesn't match the webhook_secret in your provider config. Both must be the same value as HRIDA_ONCALL_WEBHOOK_TOKEN.

oncall-migrate container keeps restarting → The oncall database may not have been created. Check docker logs hrida-oncall-db-init. The postgres container must be running and accepting connections before migration runs.

Celery worker not processing escalations → Check docker logs hrida-oncall-celery. Redis must be reachable at redis://redis-valkey:6379/2.

Hrida.ai is proprietary software of Zlabs Innovation. See the license for terms. © 2026 Zlabs Innovation.