Derek Coleman & Associates Inc logoDerek Coleman & Associates Inc

Home / Support / Oracle Cloud Marketplace / Apache Superset

In Oracle review

DCA Hardened Business Intelligence Platform for Apache Superset — Support & Quick Start

A hardened, CVE-patched image running Apache Superset™ business intelligence on Oracle Linux 9.

In Oracle certification review. This listing is not in the public Oracle Cloud Marketplace catalog yet; Oracle publishes it automatically when certification completes, and this page then links to it. The procedure below is the one submitted with the listing.

At a glance

StatusIn Oracle certification review
Version6.1.0
PlatformOracle Linux 9
Ports open in the host firewallSSH (22/tcp), 8088/tcp
CategoryBusiness applications
Upstream licenceApache-2.0
PricingPay-as-you-go software fee per OCPU-hour, billed by Oracle on your OCI invoice — see the listing's Pricing tab

Quick start

This is the listing's usage information, verbatim. Every command in it is run by our QA on a freshly launched instance before an image version can publish, so the text and the tested procedure cannot drift apart.

After launch:

  1. Connect over SSH as the opc user with the key you supplied at launch:
    ssh opc@<public-ip>
  2. Superset runs as the superset systemd service (gunicorn web server) bound to loopback on port 8088; its metadata lives in a local PostgreSQL 16 database that is reachable only over a Unix socket. On first boot, superset-firstboot.service minted this instance's secret keys, built the metadata database and created your administrator, which takes three to five minutes. Check all three:
    sudo systemctl status superset-firstboot superset postgresql

    If first boot failed, read sudo journalctl -u superset-firstboot, fix the cause and reboot: it runs again on every boot until it completes, and superset starts only after it has.

  3. The administrator dcaadmin and its password were generated uniquely for this instance at first boot. Read them (root only):
    sudo cat /root/.superset_default_credentials
  4. Smoke-test from the instance: the health check, then a login through Superset's REST API with the generated password, which answers with an access token:
    curl -fsS http://127.0.0.1:8088/health
    curl -fsS -X POST http://127.0.0.1:8088/api/v1/security/login -H 'Content-Type: application/json' -d '{"username":"dcaadmin","password":"<password>","provider":"db"}'
  5. Open the web UI through an SSH tunnel from your workstation (no exposure needed), browse to http://localhost:8088 and sign in as dcaadmin. PostgreSQL data sources work out of the box; add connections under Settings > Database Connections.
    ssh -L 8088:127.0.0.1:8088 opc@<public-ip>
  6. To serve users on your network, expose it deliberately: bind the web server to all interfaces, then restart it.
    sudo sed -i 's/^SUPERSET_BIND=.*/SUPERSET_BIND=0.0.0.0:8088/' /etc/superset/superset.env
    sudo systemctl restart superset

    Port 8088 is already permitted in the host firewall. Restrict it in your VCN security list to your users' CIDR, never expose it to the internet, and terminate TLS in front of it (for example on an OCI load balancer).

  7. Rotate the administrator password at any time (you are prompted twice, so it never appears on the command line), then update /root/.superset_default_credentials. Give each person a named account under Settings > List Users instead of sharing dcaadmin:
    sudo /usr/local/sbin/superset-cli fab reset-password --username dcaadmin
  8. Superset's state is the PostgreSQL database superset (data in /var/lib/pgsql/data) plus the keys in /etc/superset. Back them up together, because the secret key encrypts the database passwords Superset stores:
    sudo -u postgres pg_dump -Fc -f /var/lib/pgsql/superset.dump superset

The image is CVE-patched at build time. Apply ongoing Oracle Linux, Python 3.12 and PostgreSQL updates with:

sudo dnf -y update

Superset and its Python libraries are pinned in /opt/superset/venv and are not changed by dnf; new Superset releases ship as new versions of this image.

What the image provides

Still stuck?

Email support@dcassociatesgroup.com (response within 1 business day) or use the contact form. Include the listing name, your OCI region, the instance OCID and the output of sudo journalctl -u <service> -n 100 for the unit named in the quick start.

Apache Superset is open-source software released under the Apache License 2.0. Apache®, Apache Superset™, Superset™ and the Superset logo are either registered trademarks or trademarks of the Apache Software Foundation, used here only to identify the software this image runs. This image is an independent hardened distribution and is not affiliated with, endorsed by, or sponsored by the Apache Software Foundation.