Securing a self-hosted Metabase deployment

Secure Metabase identity, database connections, metadata, dashboards, and operating access.

On this page

Define the analytics boundary

Metabase is a reporting interface, not the data-access policy itself. Secure the web application, its metadata database, identity path, database credentials, network routes, and shared collections together. A dashboard folder does not protect a user who can query an unrestricted database connection.

Use scoped data connections

Inventory every connection, owner, database role, schema, network path, and intended audience. Prefer read-only, purpose-scoped roles and a reporting target when queries could affect transactional systems. Test expensive filters and exports before inviting a broad group.

Review identity and collections

Map sign-in, administrator recovery, offboarding, collection access, data permissions, and publication roles. Test a restricted account through the normal browser path. Give shared dashboards an owner, metric definition, source, and review date so obsolete results do not become unofficial truth.

Protect metadata and changes

Back up the metadata store and restore it in isolation. Verify a user, permission, and known dashboard after restoration. Keep secrets outside screenshots and page content. Test upgrades against sign-in, a restricted view, representative questions, and each important source connection.

Security record

Keep evidence with the analytics service.

AreaCheckEvidence
DatabaseLeast privilegeRestricted query test.
CollectionsApproved sharingViewer account test.
MetadataRecoverable configurationIsolated restore.
ChangesSafe releaseVersion and acceptance record.

Questions to settle

Can Metabase use a production administrator credential?

Avoid it. A scoped reporting role reduces query and exposure risk.

What is backed up?

State the metadata boundary separately from source data, identity, and external services.

What proves access is correct?

A normal user can answer intended questions and cannot retrieve excluded data.

Secure operating cycle

List data sources, roles, collections, owners, and network paths.

Handover checks

Keep results current.

Role test

Restricted access works through the user interface.

Connection register

Every source has an owner and scoped credential.

Restore test

Metadata restoration has been exercised.

Sources and further reading

Talk to our team.

Tell us what you're working on, whether it's a deployment, an audit, a security test or a cyber range. You'll speak with an engineer who can help you scope it.

  • 30-minute call: free, with no obligation.
  • NDA on request: we can sign before you share details.
  • Clear next steps: a scope and plan after the call.