# Pmm-client connection with pmm-server

**URL:** <https://forums.percona.com/t/pmm-client-connection-with-pmm-server/29518>\
**Category:** PMM 2.x\
**Created:** [April 3, 2024, 3:32am UTC](https://forums.percona.com/t/pmm-client-connection-with-pmm-server/29518 "2024-04-03T03:32:00Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wali\_Hasan](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wali_hasan/32/14587_2.png) [@Wali\_Hasan](https://forums.percona.com/u/Wali_Hasan)\
**Post date:** [April 3, 2024, 3:32am UTC](https://forums.percona.com/t/pmm-client-connection-with-pmm-server/29518/1 "2024-04-03T03:32:00Z")

</div>

## Description:

Hi,  
I’m running pmm-server v2.41.0 on my kubernetes cluster and pmm-client for monitoring my MongoDB running on GCE instances.  
I want to know if there is any other way of registering the node with pmm server apart from using admin username & password? maybe through service accounts or api-keys??  
The issue is that i wish to push PMM monitoring in production and before i do that i want to put it behind IAP. If i put it behind IAP,then i’m not able to register the node with admin username & password. So is there any other way of registering the node maybe through service accounts,api-keys or maybe creating an internal LB for PMM server.

## Expected Result:

It should be able to register the node with pmm-server through some other way too.

## Actual Result:

Can only register through username & password.

Any help would be appreciated,thanks.

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [April 3, 2024, 2:50pm UTC](https://forums.percona.com/t/pmm-client-connection-with-pmm-server/29518/2 "2024-04-03T14:50:30Z")

</div>

Hello @Wali_Hasan,  
Unfortunately, at this time using username/password is the only way to add the _local agent_ to PMM. However, you can add a remote Mongo monitoring instance to PMM using the API/UI. But you won’t get any disk/OS/memory stats this way.

---

<div class="post-metadata">

**Author:** ![Wali\_Hasan](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wali_hasan/32/14587_2.png) [@Wali\_Hasan](https://forums.percona.com/u/Wali_Hasan)\
**Post date:** [April 4, 2024, 4:18am UTC](https://forums.percona.com/t/pmm-client-connection-with-pmm-server/29518/3 "2024-04-04T04:18:14Z")

</div>

Hello @matthewb ,  
which means i won’t be able to put PMM behind Google Single Sign on?? This would defeat the purpose…I couldn’t find any official document to implement google authentication,is that also not supported?

---

<div class="post-metadata">

**Author:** ![matthewb](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/matthewb/32/34_2.png) [@matthewb](https://forums.percona.com/u/matthewb)\
**Post date:** [April 4, 2024, 4:45am UTC](https://forums.percona.com/t/pmm-client-connection-with-pmm-server/29518/4 "2024-04-04T04:45:08Z")

</div>

Hello @Wali_Hasan,  
Grafana, the UI of PMM, fully supports OAuth2-style authentication.

> **[Configure generic OAuth2 authentication | Grafana documentation](https://grafana.com/docs/grafana/latest/setup-grafana/configure-security/configure-authentication/generic-oauth/)**
>
> Configure generic OAuth2 authentication

Our public demo, [https://pmmdemo.percona.com/](https://pmmdemo.percona.com/) uses OAuth2 for employee SSO, so it does indeed work.

---

<div class="post-metadata">

**Author:** ![Wali\_Hasan](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/wali_hasan/32/14587_2.png) [@Wali\_Hasan](https://forums.percona.com/u/Wali_Hasan)\
**Post date:** [April 4, 2024, 5:12am UTC](https://forums.percona.com/t/pmm-client-connection-with-pmm-server/29518/5 "2024-04-04T05:12:37Z")

</div>

Hello @matthewb ,  
I’m trying to implement Google OAuth2 authentication but facing issue.  
So i’ve installed pmm server using helm charts,

pmmEnv:  
GF\_AUTH\_GENERIC\_OAUTH\_ENABLED: “true”  
GF\_AUTH\_GENERIC\_OAUTH\_SCOPES: “[https://www.googleapis.com/auth/userinfo.profile](https://www.googleapis.com/auth/userinfo.profile) [https://www.googleapis.com/auth/userinfo.email](https://www.googleapis.com/auth/userinfo.email)”  
GF\_AUTH\_GENERIC\_OAUTH\_AUTH\_URL: “[Sign in - Google Accounts](https://accounts.google.com/o/oauth2/auth)”  
GF\_AUTH\_GENERIC\_OAUTH\_TOKEN\_URL: “[https://accounts.google.com/o/oauth2/token](https://accounts.google.com/o/oauth2/token)”  
GF\_AUTH\_GENERIC\_OAUTH\_API\_URL: “[https://accounts.google.com/o/oauth2/authorize](https://accounts.google.com/o/oauth2/authorize)”  
GF\_AUTH\_GENERIC\_OAUTH\_ALLOWED\_DOMAINS: “[gmail.com](http://gmail.com)”  
GF\_SERVER\_ROOT\_URL: “[https://pmm-example.com/graph](https://pmm-example.com/graph)”

I’ve passed these values under pmmEnv in helmchart to pass as environment variables,  
and passed clientID & clientSecret as Secrets in helmchart

secret:  
GF\_AUTH\_GENERIC\_OAUTH\_CLIENT\_ID: “base64 encoded value”  
GF\_AUTH\_GENERIC\_OAUTH\_CLIENT\_SECRET: “base64 encoded value”

My redirect URI at google end is [https://pmm-example.com/graph/login/generic\_oauth](https://pmm-example.com/graph/login/generic_oauth)

But it dont seem to work…i get “Error 401: invalid\_client” when i try to sigin with OAuth,can please help as to what i’m doing wrong in this??  
Any help would be highly appreciated.

Thanks.
