
Apache Superset
Protect access to Apache Superset dashboards and data exploration as an upstream web application.
Overview
Apache Superset is an open-source data exploration and visualization platform. Its web application provides dashboards, charts, SQL workflows, and APIs. Some optional asynchronous features use a separate WebSocket service.
Apache Superset can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Apache Superset. Apache Superset remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Keep Superset authentication, row-level security, dataset permissions, and database credentials active. Test embedded views and API clients with their own supported authentication model.
Example
A private Superset deployment sits behind Pomerium. Analysts authenticate at the Pomerium route. Superset continues to control which databases, dashboards, and datasets each analyst can use.
Considerations
- Configure ProxyFix, forwarded scheme, and the public application URL for the Pomerium origin.
- When the deployment enables asynchronous query features, configure and test the separate WebSocket service. A normal HTTP route does not cover it automatically.
