Superset
Platform:
| Channel | Revision | Published | Runs on |
|---|---|---|---|
| latest/stable | 39 | 30 Apr 2025 | |
| latest/edge | 97 | Yesterday | |
| 6/stable | 82 | 07 Oct 2026 | |
| 6/edge | 81 | 23 Sep 2026 | |
| 5/stable | 48 | 26 Nov 2025 | |
| 5/edge | 48 | 21 Nov 2025 |
juju deploy superset-k8s --channel 6/stable
-
allow-image-domains | string
Comma separated list of domains from which to allow images according to the CSP.
Applies to: the UI application, which is what serves the policy.
-
cache-warmup | boolean
Boolean representing if the cache warm-up functionality should be enabled. It adds a daily
cache-warmupentry to the beat schedule; the warm-up itself is run by the worker.Applies to: the beat application, which holds the schedule.
-
celery-worker-concurrency | int
Number of concurrent Celery worker processes per worker pod. Valid range: 0-128. Zero leaves the Celery default, which is one process per CPU.
Applies to: the worker application.
-
charm-function | string
Default: app-gunicorn
The Superset function this application fulfills. A complete deployment runs one application of each: 'app-gunicorn' serves the web UI and is the only one that migrates the metadata database, 'worker' executes Celery tasks, and 'beat' schedules them.
Allowed options are: 'app-gunicorn', 'worker', 'beat'
Applies to: every application. It is what makes them differ.
-
dashboard-size-limit | int
Default: 65535
Integer representing how many characters to allow in a dashboard definition.
Applies to: the UI application.
-
data-access-request-url | string
URL users are directed to when they hit a Trino/Ranger permission-denied error while viewing a dashboard, so they can request access to the restricted data. When unset, the message tells users to contact their administrator instead.
Applies to: the UI application, which rewrites the error for the browser.
-
email-subject-prefix | string
Default: [Superset]
The prefix put in front of the subject line of every alert and report email. The
smtpinterface carries no field for it, so it is set here.Applies to: the worker application, and only when
ALERT_REPORTSis set. -
enable-raise-for-access-patch | boolean
Enables the Superset 6.1.0 SQL Lab-to-chart access workaround. This changes Superset's upstream access authorization behavior and is disabled by default.
Applies to: the UI application, which authorizes the request.
-
external-url | string
The URL report recipients open from an alert or report email. The worker holds no ingress relation and cannot learn it, so it is not derived from anything and has to be set.
Applies to: the worker application, which writes the link into the email. The UI application also reads it, as one of the hosts its
/redirectpage treats as internal, but every link a report email sends there is external by construction. Only takes effect whenALERT_REPORTSis set. -
extra-categorical-color-schemes | string
JSON string representation of EXTRA_CATEGORICAL_COLOR_SCHEMES array. It allows to add custom color schemes to customise dashboards coloring. Example value: '[{"id": "custom_greyscale", "description": "Clean greyscale palette optimized for high-contrast category differentiation.", "label": "Smooth Greyscale", "colors": ["#333333", "#AEA79F", "#CECAC5", "#DEDBD8", "#666666", "#F2F1F0"]}]'
Applies to: the UI application
-
extra-sequential-color-schemes | string
JSON string representation of EXTRA_SEQUENTIAL_COLOR_SCHEMES array. It allows to add custom color schemes to customise dashboards coloring. Example value: '[{"id": "custom_grey_sequential", "description": "Smooth greyscale sequential gradient using warm grey brand assets.", "label": "Smooth Grey Sequential", "isLinear": true, "colors": ["#F6F6F5", "#E6E4E2", "#D6D3CF", "#C6C1BB", "#B6AFA8", "#AEA79F"]}]'
Applies to: the UI application
-
feature-flags | string
A comma-separated list of feature defined in https://github.com/apache/superset/blob/HEAD/RESOURCES/FEATURE_FLAGS.md. To disable features enabled by default, precede them with a ! symbol. E.g: ENABLED_FEATURE,!DISABLED_FEATURE.
Two flags span the applications and only work when set on all three.
ALERT_REPORTSmakes the UI offer alerts and reports, makes the beat scheduler addreports.schedulerto its schedule, and makes the worker load the SMTP and screenshot settings it needs to deliver them. It is what turns on every worker option in the report group below:screenshot-timeout,report-dry-run,server-alias,external-urlandemail-subject-prefix. It also requires thesmtprelation to deliver with, so the charm blocks when it is set without one, unlessreport-dry-runsays nothing is to be delivered.GLOBAL_ASYNC_QUERIESsplits query execution between the UI and the worker, which both have to agree that it is enabled.Applies to: every application, and the two flags above must be set on all three to take effect.
-
global-async-queries-polling-delay | int
Default: 500
The timedelay in milliseconds for polling during asynchronous query execution. It only takes effect when the
GLOBAL_ASYNC_QUERIESfeature flag is set on every application.Applies to: the UI application, which serves the delay to the browser.
-
gunicorn-timeout | int
Default: 60
Gunicorn worker timeout in seconds. Valid range: 30-600.
Applies to: the UI application.
-
html-sanitization | boolean
Default: True
Sanitizes the HTML content used in markdowns to allow its rendering in a safe manner. Disabling this option is not recommended for security reasons
Applies to: the UI application, which renders the markdown.
-
html-sanitization-schema-extensions | string
Use this configuration to extend the HTML sanitization schema.
Applies to: the UI application, as for
html-sanitization. -
load-examples | boolean
Loads example data source with corresponding data sets and charts for testing. The examples are loaded by the one-time initialisation the UI runs, which can add several minutes to a first deployment.
Applies to: the UI application, which is the only one that initialises the metadata database.
-
log-retention-days | int
Default: 730
Number of days to retain rows in the
logstable (user action audit log) before they are pruned by the dailyprune_logsCelery beat task. Only takes effect iflog-retention-enabledis true. The beat scheduler puts the value in the task message, so changing it takes effect on the next scheduled run.Applies to: the beat application, which holds the schedule.
-
log-retention-enabled | boolean
Default: True
Whether to automatically prune old rows from the
logstable (user action audit log) via the dailyprune_logsCelery beat task. Disable if you don't want thelogstable pruned at all.Applies to: the beat application, which holds the schedule.
-
max-content-length | int
Werkzeug limit for the number of bytes to allow in a request body as measured by the 'Content-Length' header.
Applies to: the UI application, which is what receives requests.
-
max-form-memory-size | int
Werkzeug limit for the number of bytes to allow in a single part of a multipart form.
Applies to: the UI application, as for
max-content-length. -
max-form-parts | int
Werkzeug limit for the number of parts to allow in a multipart form.
Applies to: the UI application, as for
max-content-length. -
oauth-admin-email | string
Default: admin@superset.com
Email(s) to be given an Admin role on initialization. Either a single email or a comma separated list. eg. "example.email@company.com, example.email2@company.com"
Applies to: the UI application, which is where users authenticate.
-
redis-timeout | int
Default: 300
The time in seconds cached data will remain valid in Redis. It is the default timeout for every cache backend, including the results and the asynchronous query caches.
Applies to: the UI and the worker, which are the applications that read and write the caches.
-
report-dry-run | boolean
When true, render alert and report screenshots but do not deliver email or Slack notifications. Intended for testing the rendering pipeline; leave false in production.
Applies to: the worker application, and only when
ALERT_REPORTSis set. -
screenshot-timeout | int
Default: 600
Maximum time in seconds to wait for report and alert screenshots to render. The screenshots are taken by the worker, with Playwright.
Applies to: the worker application, and only when
ALERT_REPORTSis set. -
self-registration-role | string
Default: Public
The default role to be provided to users that self-register via OAuth. This role must exist already in Superset and is case sensitive.
Applies to: the UI application, which is where users authenticate. Note that every application validates the value against the roles in the metadata database, so a role that does not exist blocks all three.
-
sentry-dsn | string
The unique key for the Sentry project in which to log exceptions. Exception reporting is only turned on when
sentry-dsn,sentry-environmentandsentry-releaseare all set.Applies to: every application. Set it on all three to see worker and scheduler exceptions as well as UI ones.
-
sentry-environment | string
The environment to log errors to in Sentry.
Applies to: every application.
-
sentry-redact-params | boolean
Indicates whether or not event parameters sent to Sentry should be redacted.
Applies to: every application.
-
sentry-release | string
The version of code deployed to an environment.
Applies to: every application.
-
sentry-sample-rate | string
Default: 1
A number between 0 and 1 representing what % of errors should be sent to Sentry. ie for 0.25, 25% of errors will be sent to Sentry.
Applies to: every application.
-
server-alias | string
Default: superset-k8s
The alias the server charm has been deployed with if it differs from the default. It is the hostname the worker loads dashboards from when rendering a report screenshot, so it has to resolve to the UI application.
Applies to: the worker application, and only when
ALERT_REPORTSis set. -
server-worker-amount | int
Default: 1
Number of Gunicorn worker processes per UI pod. Valid range: 1-32.
Applies to: the UI application.
-
signing-keys-secret-id | string
ID of the Juju secret holding the signing keys for this deployment. The secret must contain
secret-key, used to sign the session cookie and to encrypt the database connection passwords stored in the metadata database, andasync-queries-jwt, used to sign the asynchronous query channel cookie. It must be granted withjuju grant-secretto the UI, worker and beat applications of one deployment, which must all name the same secret. Keepsecret-keystable for the lifetime of a deployment: changing it makes every stored connection password unreadable.Applies to: every application, which must all be given the same secret.
-
sqlalchemy-max-overflow | int
Default: 5
Sets the maximum number of connections that can be created beyond the pool size when the pool is exhausted.
Applies to: every application, as for
sqlalchemy-pool-size. -
sqlalchemy-pool-size | int
Default: 5
Specifies the maximum number of database connections that can be kept in the connection pool.
Applies to: every application. The UI and the worker query the metadata database throughout their run; a beat scheduler only does so while starting up.
-
sqlalchemy-pool-timeout | int
Default: 300
Defines the maximum time (in seconds) a thread is allowed to wait for a connection from the pool.
Applies to: every application, as for
sqlalchemy-pool-size. -
webserver-timeout | int
Default: 180
The time in seconds the server can maintain a database connection.
Applies to: the UI application.