Superset

Business Data Publisher

Platform:

Channel Revision Published Runs on
latest/stable 39 30 Apr 2025
Ubuntu 22.04
latest/edge 97 Yesterday
Ubuntu 22.04
6/stable 82 07 Oct 2026
Ubuntu 22.04
6/edge 81 23 Sep 2026
Ubuntu 22.04
5/stable 48 26 Nov 2025
Ubuntu 22.04
5/edge 48 21 Nov 2025
Ubuntu 22.04
juju deploy superset-k8s --channel 6/stable

Learn about configurations >

  • allow-image-domains | string

    Comma separated list of domains from which to allow images according to the CSP.

    Applies to: the UI application, which is what serves the policy.

  • cache-warmup | boolean

    Boolean representing if the cache warm-up functionality should be enabled. It adds a daily cache-warmup entry to the beat schedule; the warm-up itself is run by the worker.

    Applies to: the beat application, which holds the schedule.

  • celery-worker-concurrency | int

    Number of concurrent Celery worker processes per worker pod. Valid range: 0-128. Zero leaves the Celery default, which is one process per CPU.

    Applies to: the worker application.

  • charm-function | string

    Default: app-gunicorn

    The Superset function this application fulfills. A complete deployment runs one application of each: 'app-gunicorn' serves the web UI and is the only one that migrates the metadata database, 'worker' executes Celery tasks, and 'beat' schedules them.

    Allowed options are: 'app-gunicorn', 'worker', 'beat'

    Applies to: every application. It is what makes them differ.

  • dashboard-size-limit | int

    Default: 65535

    Integer representing how many characters to allow in a dashboard definition.

    Applies to: the UI application.

  • data-access-request-url | string

    URL users are directed to when they hit a Trino/Ranger permission-denied error while viewing a dashboard, so they can request access to the restricted data. When unset, the message tells users to contact their administrator instead.

    Applies to: the UI application, which rewrites the error for the browser.

  • email-subject-prefix | string

    Default: [Superset]

    The prefix put in front of the subject line of every alert and report email. The smtp interface carries no field for it, so it is set here.

    Applies to: the worker application, and only when ALERT_REPORTS is set.

  • enable-raise-for-access-patch | boolean

    Enables the Superset 6.1.0 SQL Lab-to-chart access workaround. This changes Superset's upstream access authorization behavior and is disabled by default.

    Applies to: the UI application, which authorizes the request.

  • external-url | string

    The URL report recipients open from an alert or report email. The worker holds no ingress relation and cannot learn it, so it is not derived from anything and has to be set.

    Applies to: the worker application, which writes the link into the email. The UI application also reads it, as one of the hosts its /redirect page treats as internal, but every link a report email sends there is external by construction. Only takes effect when ALERT_REPORTS is set.

  • extra-categorical-color-schemes | string

    JSON string representation of EXTRA_CATEGORICAL_COLOR_SCHEMES array. It allows to add custom color schemes to customise dashboards coloring. Example value: '[{"id": "custom_greyscale", "description": "Clean greyscale palette optimized for high-contrast category differentiation.", "label": "Smooth Greyscale", "colors": ["#333333", "#AEA79F", "#CECAC5", "#DEDBD8", "#666666", "#F2F1F0"]}]'

    Applies to: the UI application

  • extra-sequential-color-schemes | string

    JSON string representation of EXTRA_SEQUENTIAL_COLOR_SCHEMES array. It allows to add custom color schemes to customise dashboards coloring. Example value: '[{"id": "custom_grey_sequential", "description": "Smooth greyscale sequential gradient using warm grey brand assets.", "label": "Smooth Grey Sequential", "isLinear": true, "colors": ["#F6F6F5", "#E6E4E2", "#D6D3CF", "#C6C1BB", "#B6AFA8", "#AEA79F"]}]'

    Applies to: the UI application

  • feature-flags | string

    A comma-separated list of feature defined in https://github.com/apache/superset/blob/HEAD/RESOURCES/FEATURE_FLAGS.md. To disable features enabled by default, precede them with a ! symbol. E.g: ENABLED_FEATURE,!DISABLED_FEATURE.

    Two flags span the applications and only work when set on all three. ALERT_REPORTS makes the UI offer alerts and reports, makes the beat scheduler add reports.scheduler to its schedule, and makes the worker load the SMTP and screenshot settings it needs to deliver them. It is what turns on every worker option in the report group below: screenshot-timeout, report-dry-run, server-alias, external-url and email-subject-prefix. It also requires the smtp relation to deliver with, so the charm blocks when it is set without one, unless report-dry-run says nothing is to be delivered. GLOBAL_ASYNC_QUERIES splits query execution between the UI and the worker, which both have to agree that it is enabled.

    Applies to: every application, and the two flags above must be set on all three to take effect.

  • global-async-queries-polling-delay | int

    Default: 500

    The timedelay in milliseconds for polling during asynchronous query execution. It only takes effect when the GLOBAL_ASYNC_QUERIES feature flag is set on every application.

    Applies to: the UI application, which serves the delay to the browser.

  • gunicorn-timeout | int

    Default: 60

    Gunicorn worker timeout in seconds. Valid range: 30-600.

    Applies to: the UI application.

  • html-sanitization | boolean

    Default: True

    Sanitizes the HTML content used in markdowns to allow its rendering in a safe manner. Disabling this option is not recommended for security reasons

    Applies to: the UI application, which renders the markdown.

  • html-sanitization-schema-extensions | string

    Use this configuration to extend the HTML sanitization schema.

    Applies to: the UI application, as for html-sanitization.

  • load-examples | boolean

    Loads example data source with corresponding data sets and charts for testing. The examples are loaded by the one-time initialisation the UI runs, which can add several minutes to a first deployment.

    Applies to: the UI application, which is the only one that initialises the metadata database.

  • log-retention-days | int

    Default: 730

    Number of days to retain rows in the logs table (user action audit log) before they are pruned by the daily prune_logs Celery beat task. Only takes effect if log-retention-enabled is true. The beat scheduler puts the value in the task message, so changing it takes effect on the next scheduled run.

    Applies to: the beat application, which holds the schedule.

  • log-retention-enabled | boolean

    Default: True

    Whether to automatically prune old rows from the logs table (user action audit log) via the daily prune_logs Celery beat task. Disable if you don't want the logs table pruned at all.

    Applies to: the beat application, which holds the schedule.

  • max-content-length | int

    Werkzeug limit for the number of bytes to allow in a request body as measured by the 'Content-Length' header.

    Applies to: the UI application, which is what receives requests.

  • max-form-memory-size | int

    Werkzeug limit for the number of bytes to allow in a single part of a multipart form.

    Applies to: the UI application, as for max-content-length.

  • max-form-parts | int

    Werkzeug limit for the number of parts to allow in a multipart form.

    Applies to: the UI application, as for max-content-length.

  • oauth-admin-email | string

    Default: admin@superset.com

    Email(s) to be given an Admin role on initialization. Either a single email or a comma separated list. eg. "example.email@company.com, example.email2@company.com"

    Applies to: the UI application, which is where users authenticate.

  • redis-timeout | int

    Default: 300

    The time in seconds cached data will remain valid in Redis. It is the default timeout for every cache backend, including the results and the asynchronous query caches.

    Applies to: the UI and the worker, which are the applications that read and write the caches.

  • report-dry-run | boolean

    When true, render alert and report screenshots but do not deliver email or Slack notifications. Intended for testing the rendering pipeline; leave false in production.

    Applies to: the worker application, and only when ALERT_REPORTS is set.

  • screenshot-timeout | int

    Default: 600

    Maximum time in seconds to wait for report and alert screenshots to render. The screenshots are taken by the worker, with Playwright.

    Applies to: the worker application, and only when ALERT_REPORTS is set.

  • self-registration-role | string

    Default: Public

    The default role to be provided to users that self-register via OAuth. This role must exist already in Superset and is case sensitive.

    Applies to: the UI application, which is where users authenticate. Note that every application validates the value against the roles in the metadata database, so a role that does not exist blocks all three.

  • sentry-dsn | string

    The unique key for the Sentry project in which to log exceptions. Exception reporting is only turned on when sentry-dsn, sentry-environment and sentry-release are all set.

    Applies to: every application. Set it on all three to see worker and scheduler exceptions as well as UI ones.

  • sentry-environment | string

    The environment to log errors to in Sentry.

    Applies to: every application.

  • sentry-redact-params | boolean

    Indicates whether or not event parameters sent to Sentry should be redacted.

    Applies to: every application.

  • sentry-release | string

    The version of code deployed to an environment.

    Applies to: every application.

  • sentry-sample-rate | string

    Default: 1

    A number between 0 and 1 representing what % of errors should be sent to Sentry. ie for 0.25, 25% of errors will be sent to Sentry.

    Applies to: every application.

  • server-alias | string

    Default: superset-k8s

    The alias the server charm has been deployed with if it differs from the default. It is the hostname the worker loads dashboards from when rendering a report screenshot, so it has to resolve to the UI application.

    Applies to: the worker application, and only when ALERT_REPORTS is set.

  • server-worker-amount | int

    Default: 1

    Number of Gunicorn worker processes per UI pod. Valid range: 1-32.

    Applies to: the UI application.

  • signing-keys-secret-id | string

    ID of the Juju secret holding the signing keys for this deployment. The secret must contain secret-key, used to sign the session cookie and to encrypt the database connection passwords stored in the metadata database, and async-queries-jwt, used to sign the asynchronous query channel cookie. It must be granted with juju grant-secret to the UI, worker and beat applications of one deployment, which must all name the same secret. Keep secret-key stable for the lifetime of a deployment: changing it makes every stored connection password unreadable.

    Applies to: every application, which must all be given the same secret.

  • sqlalchemy-max-overflow | int

    Default: 5

    Sets the maximum number of connections that can be created beyond the pool size when the pool is exhausted.

    Applies to: every application, as for sqlalchemy-pool-size.

  • sqlalchemy-pool-size | int

    Default: 5

    Specifies the maximum number of database connections that can be kept in the connection pool.

    Applies to: every application. The UI and the worker query the metadata database throughout their run; a beat scheduler only does so while starting up.

  • sqlalchemy-pool-timeout | int

    Default: 300

    Defines the maximum time (in seconds) a thread is allowed to wait for a connection from the pool.

    Applies to: every application, as for sqlalchemy-pool-size.

  • webserver-timeout | int

    Default: 180

    The time in seconds the server can maintain a database connection.

    Applies to: the UI application.