Sign inSign up

readystack/redash

By readystack

•Updated about 3 hours ago

Image
0

1.5K

readystack/redash repository overview

⁠Redash

Signed: cosign SBOM: SPDX attached Provenance: SLSA v0.2

readystack/redash:v26.3.0-CE-trixie-r1

A cosign-signed build of github.com/getredash/redash v26.3.0 (BSD-2-Clause), built clean-room from official upstream source by ReadyStack⁠.

⁠What you get

Signature, user, attestations and grade below were measured on the published digest sha256:ef1b0e2388b7ddde668a7e9c8b76c003efd1acf9852bda5f1e20390558918ed6 on 2026-10-07.

  • Docker Scout grade D (44%) on 2026-10-07 — 4 of Docker's 7 default policies fail:
    • 2 fixable critical/high vulnerabilities (2 high) in 2 packages, e.g. libpcre2-8-0 10.46-1deb13u2 (fixed in 10.46-1deb13u3); openssl 3.5.7-1deb13u2 (fixed in 3.5.7-1deb13u3).
    • Provenance attestation is SLSA v0.2; Docker Scout now requires v1.
    • Base image docker.io/library/python:3.13-slim-trixie has been updated since this image was built (built on sha256:afe189875f1d…, the tag now points to sha256:bf44cdfcb76c…).
    • 87 packages carry copyleft licences (GPL, LGPL, MPL), 86 of them operating-system packages.
    • Measured with Docker Scout CLI 1.26.0 (docker scout policy, Docker's default policies); re-checked daily at https://readystack.dev/queue⁠.
  • ReadyStack release check — passed at release on 2026-09-22: no fixable critical or high vulnerability (Docker Scout and OSV), a non-root user, SBOM and provenance attached. This is ReadyStack's own test, not a Docker grade; vulnerabilities published since then are in today's result at https://readystack.dev/queue⁠.
  • Signed — cosign signature by the ReadyStack release key (fingerprint b698e6e62c09a245) on this release's index digest sha256:ef1b0e2388b7ddde668a7e9c8b76c003efd1acf9852bda5f1e20390558918ed6; verify with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/redash:v26.3.0-CE-trixie-r1. The linux/amd64 image-manifest digest sha256:3eac4c94725c0fdf6130ed1cbdb5eb19a7b6e542ae72cbd45c86d983cca2ee15 carries no signature of its own; verify the tag (or the index digest).
  • Attestations — An SPDX SBOM and SLSA v0.2 build provenance are attached to this digest (Docker Scout now requires SLSA v1).
  • Runs as a non-root user (redash).
  • Built from source by ReadyStack.

⁠Which tag should I pull?

This image follows the ReadyStack release-tag convention:

  • The current release is v26.3.0-CE-trixie-r1 — the release on sale at readystack.dev. Release tags use the pattern <upstream-version>-CE-<base-os>-r<N>; the current one is signed, attested (SBOM + provenance), and is provided under the ReadyStack Agreement⁠.

  • Earlier release tags (an older version or revision in the same pattern) are superseded. They stay pullable so existing deployments can pin them, but they are no longer re-graded, and fixes appear only in newer releases: move to the current release. For a superseded release's build kit, ask support.

  • Any tag beginning with internal- is an engineering-pipeline artifact published for build observability. It is unsupported, may change or disappear without notice, and must not be used in production.

# ✓ current release
docker pull readystack/redash:v26.3.0-CE-trixie-r1

# ✗ unsupported (do not pull)
docker pull readystack/redash:internal-...

This release is signed; verify it with cosign verify --key https://readystack.dev/keys/cosign.pub --insecure-ignore-tlog=true readystack/redash:v26.3.0-CE-trixie-r1 (ReadyStack keeps signatures off the public transparency log, so the check is key-only). Support: [email protected]⁠, as set out in the ReadyStack Agreement⁠.

⁠Deployment

ONE product container (supervisord runs the gunicorn web server [:5000] + an RQ worker listening on all six queues + the RQ scheduler) PLUS two required datastore sidecars the customer provides: PostgreSQL and Redis. NOT self-contained. This LEAN CE image ships the MAIN dependency set only: the ~45 optional datasource drivers (all_ds: snowflake/pandas/cassandra/mssql-ODBC/etc), the GPL-conflicting ldap3 extra, and the proprietary msodbcsql18/Simba ODBC blobs are NOT included — query runners degrade gracefully (a runner is enabled only when its driver imports). Postgres/MySQL-via-HTTP/JSON/CSV/URL/Prometheus/Elasticsearch/ClickHouse-class runners work out of the box.

docker network create redash-net
docker run -d --name db --network redash-net -e POSTGRES_DB=redash -e POSTGRES_USER=redash -e 'POSTGRES_PASSWORD=YOUR_POSTGRES_PW' -v redash-db:/var/lib/postgresql/data postgres:16
docker run -d --name redis --network redash-net redis:7-alpine
docker run -d --name redash --network redash-net -p 5000:5000 -e 'REDASH_COOKIE_SECRET=YOUR_LONG_RANDOM_SECRET' -e 'REDASH_SECRET_KEY=YOUR_OTHER_RANDOM_SECRET' -e 'REDASH_DATABASE_URL=postgresql://redash:YOUR_POSTGRES_PW@db:5432/redash' -e REDASH_REDIS_URL=redis://redis:6379/0 readystack/redash:v26.3.0-CE-trixie-r1

The three containers share the redash-net network; db is the PostgreSQL container the backup and restore steps name. The database password appears twice, in POSTGRES_PASSWORD and inside REDASH_DATABASE_URL: in the URL, percent-encode characters such as @ : / % # and spaces. Keep each -e value in single quotes. Generate REDASH_COOKIE_SECRET and REDASH_SECRET_KEY once and keep them. The first start creates the schema; /ping answers when Redash is up, then open /setup to create your organisation and administrator. The archive ships no Compose file.

⁠The full ReadyStack Agent-ready Archive

The complete --network=none build kit for this image — plus admin/DB/API handbooks, the build's validation records, and its build provenance records — is at readystack.dev/buy.html⁠. A clean-room rebuild from this release's archive on an egress-blocked host reproduced its linux/amd64 digest sha256:3eac4c94725c0fdf6130ed1cbdb5eb19a7b6e542ae72cbd45c86d983cca2ee15 on 2026-09-25.

— ReadyStack · readystack.dev

Tag summary

Content type

Image

Digest

sha256:3bbcf4a22…

Size

336 Bytes

Last updated

about 3 hours ago

docker pull readystack/redash:sha256-3eac4c94725c0fdf6130ed1cbdb5eb19a7b6e542ae72cbd45c86d983cca2ee15.sig