readystack/redash:v26.3.0-CE-trixie-r1
A cosign-signed build of github.com/getredash/redash v26.3.0 (BSD-2-Clause), built clean-room from official upstream source by ReadyStack.
Signature, user, attestations and grade below were measured on the published digest sha256:ef1b0e2388b7ddde668a7e9c8b76c003efd1acf9852bda5f1e20390558918ed6 on 2026-10-07.
docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue.b698e6e62c09a245) on this release's index digest sha256:ef1b0e2388b7ddde668a7e9c8b76c003efd1acf9852bda5f1e20390558918ed6; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/redash:v26.3.0-CE-trixie-r1. The linux/amd64 image-manifest digest sha256:3eac4c94725c0fdf6130ed1cbdb5eb19a7b6e542ae72cbd45c86d983cca2ee15 carries no signature of its own; verify the tag (or the index digest).redash).This image follows the ReadyStack release-tag convention:
The current release is v26.3.0-CE-trixie-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement.
Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.
Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.
# ✓ current release
docker pull readystack/redash:v26.3.0-CE-trixie-r1
# ✗ unsupported (do not pull)
docker pull readystack/redash:internal-...
This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/redash:v26.3.0-CE-trixie-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected], as set out in the ReadyStack Agreement.
ONE product container (supervisord runs the gunicorn web server [:5000] + an RQ worker listening on all six queues + the RQ scheduler) PLUS two required datastore sidecars the customer provides: PostgreSQL and Redis. NOT self-contained. This LEAN CE image ships the MAIN dependency set only: the ~45 optional datasource drivers (all_ds: snowflake/pandas/cassandra/mssql-ODBC/etc), the GPL-conflicting ldap3 extra, and the proprietary msodbcsql18/Simba ODBC blobs are NOT included — query runners degrade gracefully (a runner is enabled only when its driver imports). Postgres/MySQL-via-HTTP/JSON/CSV/URL/Prometheus/Elasticsearch/ClickHouse-class runners work out of the box.
docker network create redash-net
docker run -d --name db --network redash-net -e POSTGRES_DB=redash -e POSTGRES_USER=redash -e 'POSTGRES_PASSWORD=YOUR_POSTGRES_PW' -v redash-db:/var/lib/postgresql/data postgres:16
docker run -d --name redis --network redash-net redis:7-alpine
docker run -d --name redash --network redash-net -p 5000:5000 -e 'REDASH_COOKIE_SECRET=YOUR_LONG_RANDOM_SECRET' -e 'REDASH_SECRET_KEY=YOUR_OTHER_RANDOM_SECRET' -e 'REDASH_DATABASE_URL=postgresql://redash:YOUR_POSTGRES_PW@db:5432/redash' -e REDASH_REDIS_URL=redis://redis:6379/0 readystack/redash:v26.3.0-CE-trixie-r1
The three containers share the redash-net network; db is the PostgreSQL container the backup and restore steps name. The database password appears twice, in POSTGRES_PASSWORD and inside REDASH_DATABASE_URL: in the URL, percent-encode characters such as @ : / % # and spaces. Keep each -e value in single quotes. Generate REDASH_COOKIE_SECRET and REDASH_SECRET_KEY once and keep them. The first start creates the schema; /ping answers when Redash is up, then open /setup to create your organisation and administrator. The archive ships no Compose file.
The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html. A clean-room rebuild from this release's archive on an egress-blocked host reproduced its linux/amd64 digest sha256:3eac4c94725c0fdf6130ed1cbdb5eb19a7b6e542ae72cbd45c86d983cca2ee15 on 2026-09-25.
— ReadyStack · readystack.dev
Content type
Image
Digest
sha256:3bbcf4a22…
Size
336 Bytes
Last updated
about 3 hours ago
docker pull readystack/redash:sha256-3eac4c94725c0fdf6130ed1cbdb5eb19a7b6e542ae72cbd45c86d983cca2ee15.sig