# # Licensed to the Apache Software Foundation (ASF) under one or more # contributor license agreements. See the NOTICE file distributed with # this work for additional information regarding copyright ownership. # The ASF licenses this file to You under the Apache License, Version 2.0 # (the "License"); you may not use this file except in compliance with # the License. You may obtain a copy of the License at # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, software # distributed under the License is distributed on an "AS IS" BASIS, # WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. # See the License for the specific language governing permissions and # limitations under the License. # # ----------------------------------------------------------------------- # We don't support docker compose for production environments. # If you choose to use this type of deployment make sure to # create you own docker environment file (docker/.env) with your own # unique random secure passwords and SECRET_KEY. # # For verbose logging during development: # - Set SUPERSET_LOG_LEVEL=debug in docker/.env-local for detailed Superset logs # ----------------------------------------------------------------------- x-superset-volumes: &superset-volumes # /app/pythonpath_docker will be appended to the PYTHONPATH in the final container - ./docker:/app/docker - superset_home:/app/superset_home x-common-build: &common-build context: . target: dev cache_from: - apache/superset-cache:3.11-slim-trixie services: redis: image: redis:7 container_name: superset_cache restart: unless-stopped volumes: - redis:/data db: env_file: - path: docker/.env # default required: true - path: docker/.env-local # optional override required: false image: postgres:17 container_name: superset_db restart: unless-stopped volumes: - db_home:/var/lib/postgresql/data - ./docker/docker-entrypoint-initdb.d:/docker-entrypoint-initdb.d superset: env_file: - path: docker/.env # default required: true - path: docker/.env-local # optional override required: false build: <<: *common-build container_name: superset_app command: ["/app/docker/docker-bootstrap.sh", "app-gunicorn"] user: "root" restart: unless-stopped ports: - 8088:8088 depends_on: superset-init: condition: service_completed_successfully volumes: *superset-volumes superset-init: container_name: superset_init build: <<: *common-build command: ["/app/docker/docker-init.sh"] env_file: - path: docker/.env # default required: true - path: docker/.env-local # optional override required: false depends_on: db: condition: service_started redis: condition: service_started user: "root" volumes: *superset-volumes healthcheck: disable: true superset-worker: build: <<: *common-build container_name: superset_worker command: ["/app/docker/docker-bootstrap.sh", "worker"] env_file: - path: docker/.env # default required: true - path: docker/.env-local # optional override required: false restart: unless-stopped depends_on: superset-init: condition: service_completed_successfully user: "root" volumes: *superset-volumes healthcheck: test: [ "CMD-SHELL", "celery -A superset.tasks.celery_app:app inspect ping -d celery@$$HOSTNAME", ] superset-worker-beat: build: <<: *common-build container_name: superset_worker_beat command: ["/app/docker/docker-bootstrap.sh", "beat"] env_file: - path: docker/.env # default required: true - path: docker/.env-local # optional override required: false restart: unless-stopped depends_on: superset-init: condition: service_completed_successfully user: "root" volumes: *superset-volumes healthcheck: disable: true # Realtime WebSocket transport, launched from the official image via its # alternate entrypoint (no separate image needed). Opt-in — start it with # `docker compose --profile websocket up`. To actually use it, the Superset # app must also set WEBSOCKET_ENABLE=true, WEBSOCKET_URL, and a matching # WEBSOCKET_JWT_SECRET (== the JWT_SECRET below) in docker/.env-local. superset-websocket: build: <<: *common-build container_name: superset_websocket profiles: - websocket # Neither a volume mount nor the root user is needed: the entrypoint and the # Node bundle it runs are both baked into the image, and the server is # configured entirely through the environment below. command: ["/app/docker/entrypoints/run-websocket.sh"] environment: REDIS_HOST: redis REDIS_PORT: 6379 PORT: 8080 JWT_COOKIE_NAME: superset-ws-token # Dev-only default; must match the app's WEBSOCKET_JWT_SECRET and be # replaced with a strong secret (>= 32 bytes) outside local development. JWT_SECRET: ${WEBSOCKET_JWT_SECRET:-dev-only-websocket-secret-change-me!} # Optional verify-only old key for websocket JWT secret rotation. PREVIOUS_JWT_SECRET: ${WEBSOCKET_PREVIOUS_JWT_SECRET:-} restart: unless-stopped ports: - 8080:8080 depends_on: redis: condition: service_started # Overrides the image-level HEALTHCHECK, which probes the Superset app. healthcheck: test: ["CMD-SHELL", "curl -f http://localhost:8080/health"] volumes: superset_home: external: false db_home: external: false redis: external: false