Overview
Metabase is an open-source business intelligence platform — dashboards, a SQL editor, and scheduled report subscriptions. This template deploys the free open-source edition backed by a highly available PostgreSQL cluster by default. The bundled PostgreSQL is Metabase’s own app database (users, dashboards, saved connections); the databases you analyze are data sources you connect in the app after install — they are never installed or touched by this template. The admin account is created automatically on first boot, and the workload only starts receiving traffic once setup is complete, so there is never a publicly reachable setup page.Architecture
- Metabase — A single-replica standard workload serving the UI and API on port
3000. Stateless by design: all application state (questions, dashboards, users, saved connections) lives in the PostgreSQL app database, so Metabase itself has no volume set. - PostgreSQL (HA, default) — The postgres-highly-available template as a subchart: 3× Patroni PostgreSQL, 3× etcd, and a HAProxy leader-routing endpoint Metabase connects through.
- PostgreSQL (dev/lightweight, optional) — The single-instance postgres template instead, for lighter non-HA deployments.
What Gets Created
- Standard Metabase Workload — A single stateless replica serving the UI and API on port
3000. - Database Workloads — HA mode: a stateful Patroni PostgreSQL workload, a stateful etcd workload, and a standard HAProxy leader-routing workload. Single mode: one stateful PostgreSQL workload.
- Volume Sets — The database subchart’s persistent volumes (10 GiB per replica by default). Metabase itself has none.
- Secrets — Admin bootstrap credentials, the start script that creates the admin account on first boot, and the database credentials from the subchart.
- Identity & Policy — A least-privilege policy granting the Metabase identity
revealon exactly the secrets it uses, including your pre-created encryption-key secret. - Cron Backup Workload (optional) — When database backups are enabled.
This template does not create a GVC. You must deploy it into an existing GVC.
Prerequisites
Metabase encrypts the connection details of every data source you save with a key it reads from an opaque secret that you create before installing. The key is never passed through values.1
Generate an encryption key
Generate a random string of at least 16 characters, for example:
2
Create an opaque secret
Create an opaque secret in your org with encoding
plain whose payload is the generated key. Set its name in encryptionKey.secretName.3
Back up the key
Store a copy of the key somewhere safe, outside Control Plane.
UI
Browse, install, and manage templates visually
CLI
Manage templates from your terminal
Terraform
Declare templates in your Terraform configurations
Pulumi
Declare templates in your Pulumi programs
Choosing a Database Mode
Exactly one of the two database modes must be enabled — the chart enforces this at render and fails the install with a clear message otherwise.
A fresh HA-mode install takes roughly 10–15 minutes to fully converge; single mode is ready in about 2 minutes.
Configuration
The defaultvalues.yaml for this template:
Metabase Instance
image— The Metabase open-source container image.resources— CPU and memory for the Metabase container. The template caps the JVM at 75% of the container memory limit (JAVA_OPTS: -XX:MaxRAMPercentage=75.0), so raisingresources.memoryalso raises the Java heap. The 2 GiB default is sized for the JVM — lowering it is not recommended.encryptionKey.secretName— Name of your pre-created opaque secret holding the key that encrypts saved data-source credentials. See Prerequisites.admin.*— The admin account, created automatically on first boot against the local setup API. There is no unauthenticated setup page at any point: the workload only becomes ready — and only starts receiving traffic — once setup is complete, and if setup fails it never becomes ready at all (fail-closed). Changeadmin.passwordbefore installing — it must pass Metabase’s complexity check (letters + digits, 8+ characters), and none of theadmin.*values may contain double quotes or backslashes (enforced at render). The account is created exactly once, on first boot — changing these values later does not modify the existing account.siteName— The instance name shown in the UI and in emails Metabase sends.
Access
publicAccess.enabled— Serve the UI and API on the canonical*.cpln.appHTTPS endpoint (default). Everything behind the endpoint is gated by Metabase’s own login. Set tofalsefor an internal-only instance (external requests are blocked at the edge; in-GVC callers still reach it perinternalAccess).internalAccess.type— Internal firewall scope of the Metabase workload:
App Database
Enable exactly one ofpostgresHA (production, default) or postgres (dev/lightweight) — see Choosing a Database Mode. In both modes, change the database password before installing (postgresHA.postgres.password / postgres.config.password). Metabase is wired to the active database automatically — the HAProxy leader endpoint in HA mode, or the single instance directly in dev mode.
Connecting
Adding Data Sources
The databases you analyze are added inside Metabase after install (Admin → Databases) — the template never installs or touches them. To analyze a database running on Control Plane, use its internal endpoint as the host, e.g.{workload}.{gvc}.cpln.local:5432. Any database Metabase can reach — inside or outside Control Plane — works as a data source. Saved connection credentials are encrypted at rest with your encryption key.
Backing Up
Database backups are optional and disabled by default. They cover the app database — the questions, dashboards, users, and saved connections that make up your Metabase instance. Enable them withpostgresHA.backup.enabled or postgres.backup.enabled (matching your database mode), and complete the storage setup for your provider before installing. The values below are shown under backup.* — set them within the enabled database block.
- AWS S3
- Google Cloud Storage
- S3-compatible (MinIO, R2, Wasabi)
1
Create a bucket
Create an S3 bucket. Set
backup.aws.bucket and backup.aws.region to match.2
Set up a Cloud Account
If you do not have one, create a Cloud Account for your AWS account. Set
backup.aws.cloudAccountName to its name.3
Create a bucket-scoped IAM policy
Create an AWS IAM policy with the JSON below (replace
YOUR_BUCKET), then set backup.aws.policyName to the policy’s name:backup.mode selects logical (scheduled pg_dump via a cron workload) or wal-g (continuous WAL archiving). The single-instance mode takes scheduled logical dumps.
Important Notes
- Back up the encryption-key secret — losing or changing it means re-entering every saved database connection; rotation is only possible offline via Metabase’s
rotate-encryption-keycommand. - Change
admin.passwordand the database password (postgresHA.postgres.password/postgres.config.password) before installing. An admin password that fails Metabase’s complexity check (letters + digits, 8+ characters) keeps the workload unready by design. - Metabase is single-replica in this template — the default HA PostgreSQL backend removes the database as a failure point.
- Upgrades restart the single replica — expect a few minutes of UI downtime per Helm upgrade; the HA app database keeps running and no data is lost.
- Uninstall deletes the app-database volume sets — all questions, dashboards, and users. Enable backups if the data matters.
- This template ships the open-source image only — Pro/Enterprise features (SSO, sandboxing, config-file init) are not available.
External References
Metabase Documentation
Official Metabase documentation
Environment Variables
Metabase environment variables reference
Encrypting Database Details
How the encryption key protects saved connection credentials
Metabase in Production
Upstream guidance on running Metabase in production
Metabase Template
View the source files, default values, and chart definition