New to KubeDB? Please start here.

Druid Grafana Dashboard

KubeDB exposes Druid metrics through a JMX Exporter running as a Java agent inside each Druid container, and its own view of each resource (status, phase, version) through Panopticon. Once Prometheus is scraping both, you can visualize them in Grafana using pre-built KubeDB dashboards. This tutorial walks through the full setup: deploying the monitoring stack, enabling monitoring on a Druid instance, and importing the Grafana dashboards.

Before You Begin

  • You need a Kubernetes cluster with kubectl configured. If you do not already have a cluster, you can create one by using kind.

  • KubeDB must be installed in your cluster with kubedb-metrics enabled. Follow the setup guide here and make sure to include the flag below during installation:

    --set kubedb-metrics.enabled=true
    

    kubedb-metrics creates MetricsConfiguration objects for each database type, which Panopticon (see Configuration) uses to expose metrics to Prometheus.

  • Druid requires a deep storage backend and ZooKeeper. The example below uses S3-compatible deep storage with a pre-created secret.

  • To keep monitoring resources isolated, we use a separate monitoring namespace and deploy the database in the demo namespace.

    $ kubectl create ns monitoring
    namespace/monitoring created
    
    $ kubectl create ns demo
    namespace/demo created
    
  • Before proceeding, complete the Configuration steps to deploy kube-prometheus-stack and Panopticon.

Note: YAML files used in this tutorial are stored in docs/examples/druid/monitoring folder in GitHub repository kubedb/docs.

Setup

Get External Dependencies Ready

Deep Storage

One of the external dependency of Druid is deep storage where the segments are stored. It is a storage mechanism that Apache Druid does not provide. Amazon S3, Google Cloud Storage, or Azure Blob Storage, S3-compatible storage (like Minio), or HDFS are generally convenient options for deep storage.

In this tutorial, we will run a minio-server as deep storage in our local kind cluster using minio-operator and create a bucket named druid in it, which the deployed druid database will use.


$ helm repo add minio https://operator.min.io/
$ helm repo update minio
$ helm upgrade --install --namespace "minio-operator" --create-namespace "minio-operator" minio/operator --set operator.replicaCount=1

$ helm upgrade --install --namespace "demo" --create-namespace druid-minio minio/tenant \
--set tenant.pools[0].servers=1 \
--set tenant.pools[0].volumesPerServer=1 \
--set tenant.pools[0].size=1Gi \
--set tenant.certificate.requestAutoCert=false \
--set tenant.buckets[0].name="druid" \
--set tenant.pools[0].name="default"

Now we need to create a Secret named deep-storage-config. It contains the necessary connection information using which the druid database will connect to the deep storage.

apiVersion: v1
kind: Secret
metadata:
  name: deep-storage-config
  namespace: demo
stringData:
  druid.storage.type: "s3"
  druid.storage.bucket: "druid"
  druid.storage.baseKey: "druid/segments"
  druid.s3.accessKey: "minio"
  druid.s3.secretKey: "minio123"
  druid.s3.protocol: "http"
  druid.s3.enablePathStyleAccess: "true"
  druid.s3.endpoint.signingRegion: "us-east-1"
  druid.s3.endpoint.url: "http://myminio-hl.demo.svc.cluster.local:9000/"

Let’s create the deep-storage-config Secret shown above:

$ kubectl create -f https://github.com/kubedb/docs/raw/v2026.7.10/docs/examples/druid/quickstart/deep-storage-config.yaml
secret/deep-storage-config created

Below is the Druid object with monitoring configured to use Prometheus Operator.

apiVersion: kubedb.com/v1alpha2
kind: Druid
metadata:
  name: druid-grafana-demo
  namespace: demo
spec:
  version: 36.0.0
  deepStorage:
    type: s3
    configSecret:
      name: deep-storage-config
  topology:
    routers:
      replicas: 1
  deletionPolicy: WipeOut
  monitor:
    agent: prometheus.io/operator
    prometheus:
      serviceMonitor:
        labels:
          release: prometheus
        interval: 10s

Here,

  • monitor.agent: prometheus.io/operator tells KubeDB to create a ServiceMonitor for this instance.
  • monitor.prometheus.serviceMonitor.labels must match the serviceMonitorSelector label of your Prometheus (release: prometheus).
  • monitor.prometheus.serviceMonitor.interval sets the scrape interval to 10 seconds.

Create the Druid instance:

$ kubectl create -f https://github.com/kubedb/docs/raw/v2026.7.10/docs/examples/druid/monitoring/druid-grafana-demo.yaml
druid.kubedb.com/druid-grafana-demo created

Wait for it to be Ready:

$ kubectl get druid -n demo druid-grafana-demo
NAME                 VERSION   STATUS   AGE
druid-grafana-demo   36.0.0    Ready    5m

KubeDB creates a stats service named {druid-name}-stats for monitoring:

$ kubectl get svc -n demo --selector="app.kubernetes.io/instance=druid-grafana-demo"
NAME                       TYPE        CLUSTER-IP     EXTERNAL-IP   PORT(S)     AGE
druid-grafana-demo         ClusterIP   10.96.10.1     <none>        8888/TCP    5m
druid-grafana-demo-stats   ClusterIP   10.96.10.2     <none>        9101/TCP    5m

KubeDB also creates a ServiceMonitor in the demo namespace:

$ kubectl get servicemonitor -n demo
NAME                       AGE
druid-grafana-demo-stats   5m

Verify it carries the correct label:

$ kubectl get servicemonitor -n demo druid-grafana-demo-stats -o jsonpath='{.metadata.labels}'
{"release":"prometheus", ...}

Step 2: Verify Prometheus is Scraping

Port-forward the Prometheus pod:

$ kubectl port-forward -n monitoring \
  prometheus-prometheus-kube-prometheus-prometheus-0 9090
Forwarding from 127.0.0.1:9090 -> 9090
Forwarding from [::1]:9090 -> 9090

Open http://localhost:9090/targets in your browser. Look for an entry whose service label matches druid-grafana-demo-stats. Its state should be UP.

Prometheus Target

If the target is missing, check that the ServiceMonitor label (release: prometheus) matches the Prometheus serviceMonitorSelector.

Step 3: Access Grafana

Port-forward the Grafana service:

$ kubectl port-forward -n monitoring svc/prometheus-grafana 3000:80
Forwarding from 127.0.0.1:3000 -> 3000
Forwarding from [::1]:3000 -> 3000

Open http://localhost:3000. The username is admin. Retrieve the auto-generated password from the secret:

$ kubectl get secret -n monitoring prometheus-grafana \
  -o jsonpath='{.data.admin-password}' | base64 -d
FieldValue
Usernameadmin
Passwordoutput of the command above

Grafana Login

After a successful login you will see the Grafana home page:

Grafana Home

Step 4: Configure Prometheus as a Data Source

If you installed Grafana via kube-prometheus-stack, Prometheus is already configured as the default data source — skip to Step 5.

If you’re using a different Grafana instance than the one installed in the Configuration prerequisite (linked in “Before You Begin” above), add Prometheus as a data source manually:

  1. Go to ConnectionsData sourcesAdd new data source.

  2. Select Prometheus.

  3. Set the URL to your Prometheus service:

    http://prometheus-operated.monitoring.svc:9090
    
  4. Click Save & test. You should see Data source is working.

Step 5: Import Dashboard — Option A: Automatic (chart)

Rather than downloading and uploading each JSON file by hand (Option B below), KubeDB ships a chart that creates all matching dashboards for you as GrafanaDashboard custom resources. A separate controller, grafana-operator, watches these resources and pushes the actual dashboard JSON into your Grafana instance — both pieces are required.

1. Install grafana-operator (skip if it’s already running in your cluster):

$ helm repo add appscode https://charts.appscode.com/stable/
$ helm repo update

$ helm upgrade --install grafana-operator appscode/grafana-operator \
    --version v2026.6.12 \
    --namespace kubeops --create-namespace

2. Register your Grafana instance as an AppBinding (skip if you’ve already done this in another guide on this cluster). grafana-operator needs to know where to push dashboards and how to authenticate — it reads this from an AppBinding object, not from the chart install command itself. Since Grafana here came bundled with kube-prometheus-stack, reuse its existing admin credentials:

$ kubectl port-forward -n monitoring svc/prometheus-grafana 3000:80 &

$ curl -s -X POST -H "Content-Type: application/json" \
    -u admin:<grafana_password> \
    http://localhost:3000/api/auth/keys \
    -d '{"name":"kubedb-dashboards","role":"Admin"}'
# Note the returned "key"

$ kill %1

$ kubectl create secret generic grafana-admin-token -n monitoring \
    --from-literal=token='<key-from-above>'

$ cat <<EOF | kubectl apply -f -
apiVersion: appcatalog.appscode.com/v1alpha1
kind: AppBinding
metadata:
  name: grafana
  namespace: monitoring
spec:
  type: monitoring.appscode.com/grafana
  clientConfig:
    url: http://prometheus-grafana.monitoring.svc:80
  secret:
    name: grafana-admin-token
EOF

3. Install the dashboards:

The chart packages dashboard JSON for every database it supports, so install it from a copy trimmed down to just Druid’s dashboards (this also keeps grafana-operator from creating dashboards for databases you don’t run):

$ helm pull appscode/kubedb-grafana-dashboards --version v2026.7.10 --untar

$ cd kubedb-grafana-dashboards/dashboards
$ ls | grep -v '^druid$' | xargs rm -rf   # keep only dashboards/druid
$ cd ../..

$ helm package kubedb-grafana-dashboards
Successfully packaged chart and saved it to: kubedb-grafana-dashboards-v2026.7.10.tgz

$ helm upgrade -i kubedb-grafana-dashboards-druid ./kubedb-grafana-dashboards-v2026.7.10.tgz \
    -n kubeops --create-namespace \
    --set grafana.name=grafana \
    --set grafana.namespace=monitoring

Use a release name unique to this database (kubedb-grafana-dashboards-druid), not the plain kubedb-grafana-dashboards name — if you also follow another DB’s Grafana Dashboard guide on this same cluster, each helm upgrade -i under a shared release name would prune the previous DB’s dashboards (Helm removes anything not in the new release’s manifest). A per-DB release name lets them coexist.

grafana.name/grafana.namespace point the chart’s GrafanaDashboard resources at the AppBinding created in step 2 (omitting them falls back to whichever AppBinding in your cluster is labeled as the cluster-default Grafana, if any — explicit is safer on a shared cluster). No need to touch featureGates — with every other database’s dashboards/ folder removed, their gates simply match zero files and render nothing, regardless of being true by default.

This creates every dashboard the chart ships for Druid — KubeDB / Druid / Summary, KubeDB / Druid / Pod, KubeDB / Druid / Database — which grafana-operator then pushes into your Grafana instance automatically. No manual JSON download or upload needed.

Verify they landed:

$ kubectl get grafanadashboards.openviz.dev -n kubeops | grep -i druid
NAME                             TITLE                        SYNCED    AGE
grafana-kubedb-druid-summary     KubeDB / Druid / Summary     Current   30s
grafana-kubedb-druid-pod         KubeDB / Druid / Pod         Current   30s
grafana-kubedb-druid-database    KubeDB / Druid / Database    Current   30s

SYNCED: Current confirms grafana-operator successfully pushed each dashboard into Grafana. Open Grafana — the dashboard are already there under Dashboards, fully wired to your Prometheus data source, ready to explore in Step 6 below.

If the SYNCED column is missing entirely from your output (not just showing a non-Current value), grafana-operator most likely never processed the resource at all. Check that the operator pod is actually running (kubectl get pods -n kubeops -l app.kubernetes.io/name=grafana-operator), inspect its logs for AppBinding/auth errors (kubectl logs -n kubeops deploy/grafana-operator), and check kubectl get grafanadashboards.openviz.dev -n kubeops <name> -o yaml for status.conditions — the CR existing only means kubectl accepted it, not that it reached Grafana.

After importing them, they will appear under Dashboards in the left sidebar as well:

Dashboard NameDescription
KubeDB / Druid / SummaryCluster-wide status, node/resource sizing, and CPU usage across all pods
KubeDB / Druid / PodPer-pod status, ZooKeeper connectivity, and JVM memory/GC metrics
KubeDB / Druid / DatabaseCluster status, datasource/segment counts, task success, and JVM memory

Step 5: Import Dashboard — Option B: Manual (JSON upload)

If you’d rather not run grafana-operator, or want fine-grained control over exactly which dashboards get imported, upload the same dashboard JSON files by hand instead.

The KubeDB Druid dashboards are distributed as JSON files. Each JSON file is a complete dashboard definition — panels, queries, variables, and layout — that Grafana loads in one shot. Without importing, you would have to build every panel and write every PromQL query by hand. Importing lets you skip that entirely.

Three dashboards are available. Download all three JSON files from the appscode/grafana-dashboards repository (druid/ folder):

FileDashboard
druid_summary_dashboard.jsonKubeDB / Druid / Summary
druid_pods_dashboard.jsonKubeDB / Druid / Pod
druid_databases_dashboard.jsonKubeDB / Druid / Database

Import steps (repeat for each of the three files):

  1. In Grafana, click the + icon in the left sidebar.
  2. Select Import from the menu.
  3. Click Upload JSON file and select one of the downloaded .json files.
  4. In the Prometheus dropdown that appears, select your Prometheus data source.
  5. Click Import.

The import page looks like this — click Upload dashboard JSON file to select the file:

Grafana Import Dashboard

After importing all three files, they will appear under Dashboards in the left sidebar.

Step 6: Explore the Dashboard

After opening a dashboard, use the dropdown filters at the top to focus on a specific instance. Note that the Summary dashboard labels its filters Namespace and Druid, while the Pod and Database dashboards use lowercase namespace and app — they select the same thing.

VariableApplies toWhat to select
Namespace / namespaceAll dashboardsNamespace where your Druid is deployed (e.g., demo)
Druid / appAll dashboardsName of your Druid instance (e.g., druid-grafana-demo)
podPod dashboardA specific pod, e.g. a coordinator, broker, or historical

KubeDB / Druid / Summary — start here for a cluster-level overview:

  • General Info — database status, version, secure-transport flag, termination policy, total node count, and aggregate CPU/memory/storage requests and limits
  • CPU Info — a CPU usage graph broken down per pod, plus a CPU Quota table showing usage vs. requests (and % of request) for each pod

KubeDB Druid Summary Dashboard

KubeDB / Druid / Pod — drill into a specific Druid node (selected via the pod filter):

  • Druid Overview — node status (UP/DOWN) and ZooKeeper connection state for the selected pod
  • JVM Overview — JVM memory used, JVM memory pool, JVM bufferpool count, and JVM GC CPU time for the selected pod

KubeDB Druid Pod Dashboard

KubeDB / Druid / Database — cluster-wide segment and task metrics:

  • Druid Overview — Druid status, ZooKeeper connection state, total datasources, unloaded segments (count and size), successful tasks, and total segment size
  • JVM Overview — JVM memory used and JVM memory pool, aggregated across pods

KubeDB Druid Database Dashboard

Cleaning up

# Remove the Druid instance
kubectl delete druid -n demo druid-grafana-demo

# Remove the deep storage secret
kubectl delete secret deep-storage-config -n demo

# Remove namespaces
kubectl delete ns demo

# Uninstall the Grafana dashboards chart, if you used Option A
helm uninstall kubedb-grafana-dashboards-druid -n kubeops

# Uninstall grafana-operator (optional — skip if other DB guides on this cluster still use it)
helm uninstall grafana-operator -n kubeops

# Uninstall monitoring stack (optional)
helm uninstall prometheus -n monitoring
helm uninstall panopticon -n kubeops
kubectl delete ns monitoring kubeops

Next Steps