Metabase
Protect access to Metabase analytics and administration as an upstream web application.
Overview
Metabase is an open-source business intelligence application. It exposes a browser interface and HTTP API for queries, dashboards, administration, and embedding.
Metabase can expose sensitive application data or administrative functions. A Pomerium route adds identity-aware policy before a user reaches the selected endpoint while the service keeps its own detailed permissions.
Pomerium controls who can establish the selected route to Metabase. Metabase remains responsible for its application, protocol, data, and service-level permissions.
How it works
Create a Pomerium HTTPS route for the selected private HTTP endpoint. Configure the application public URL and trusted proxy settings for the Pomerium origin.
Keep application authentication and granular authorization active when the service needs them. Give API and automation clients a reviewed noninteractive authentication path.
Expose the selected Metabase application endpoint. Test dashboards, query results, downloads, embedding, and API calls under the intended authentication model.
Example
Analysts reach a private Metabase deployment through Pomerium. Metabase keeps collection, database, row, embedding, and administrator permissions.
Considerations
- Set the Metabase site URL and forwarded scheme to the public Pomerium origin.
- Embedding and API clients need a compatible noninteractive path. Preserve Metabase database credentials and permissions.
