如何配置Superset通过HTTPS连接启用SSL的Druid
Hey there! I’ve dealt with this exact problem when setting up Superset with a Druid cluster that blocks HTTP traffic entirely. Let’s walk through the steps to get this working properly:
1. Update the Druid Connection String in Superset
When you add or edit your Druid data source in Superset, the default connection URL uses HTTP—you need to adjust this to force HTTPS:
- Replace the
druid://prefix withdruid+s://(the+sexplicitly tells the underlying connector to use HTTPS) - Make sure you’re using Druid’s HTTPS port (common defaults are 8443 or 8888, depending on your cluster setup)
- Example corrected connection string:
druid+s://your-druid-host:8443/druid/v2/sql/
If your Druid cluster requires basic auth, append your credentials directly in the string:
druid+s://username:password@your-druid-host:8443/druid/v2/sql/
2. Handle SSL Certificate Verification (Critical for Production)
If your Druid cluster uses a self-signed certificate or one issued by an internal CA, Superset will reject the connection by default because it doesn’t trust the certificate. Here’s how to fix this:
- First, save Druid’s CA certificate to a path accessible by Superset (e.g.,
/etc/superset/ssl/druid-ca.crt) - Open your Superset configuration file (
superset_config.py) and add these lines:# Enable SSL verification for Druid DRUID_VERIFY_SSL = True # Path to the CA certificate file DRUID_SSL_CA_CERT = '/etc/superset/ssl/druid-ca.crt' - Note: For testing environments only, you can skip verification (not recommended for production) by setting
DRUID_VERIFY_SSL = False
3. Restart Superset Services
Any configuration changes won’t take effect until you restart Superset’s web server and worker processes:
- If you’re using Docker Compose:
docker-compose restart superset-web superset-worker - For bare-metal or virtual machine deployments, restart the Superset service (e.g.,
systemctl restart supersetor restart your Gunicorn/Uvicorn process)
4. Validate the Connection First (Troubleshooting Step)
Before testing in Superset, confirm that the Superset server can reach Druid’s HTTPS endpoint using curl:
curl -v https://your-druid-host:8443/druid/v2/sql/
If this command succeeds, you know the network and certificate setup is correct—any remaining issues are likely in Superset’s configuration.
Common Pitfalls to Watch For:
- Double-check that you’re using the correct HTTPS port for your Druid cluster (some setups use 8888 for HTTP and 8443 for HTTPS)
- Ensure the Superset server has network access to Druid’s HTTPS port (firewalls/security groups often block non-standard ports)
- If you’re using environment variables for Superset config, make sure
DRUID_VERIFY_SSLandDRUID_SSL_CA_CERTare set correctly
内容的提问来源于stack exchange,提问作者Larry

