Apache Druid
Self-managed or Imply Cloud.
Access mode: Read-only
Trino connector. Queryable via Flume’s Lakehouse. This system can be accessed both through its native protocol (for metadata introspection) and via Trino federation (for data profiling and cross-system analytical queries).
Required information
| Field | Details |
|---|---|
| Router / Broker URL | Druid Router or Broker endpoint. Imply Cloud: provided endpoint URL. |
| Port | Default 8888 (Router) or 8082 (Broker). Imply Cloud: HTTPS on 443. |
| Datasource(s) | Druid datasources (equivalent to tables) to access. |
| Authentication | Basic auth, LDAP, or Imply Cloud API token. No auth by default on OSS Druid. |
| Access level | Read-only: Druid SQL query permissions on target datasources. |
Network considerations
Self-managed: VPN or direct access. The Router (port 8888) is the recommended entry point. It routes to the appropriate Broker.
Imply Cloud: HTTPS over 443. IP allowlisting in Imply console.
Internal services: Druid has many internal ports (Coordinator, Overlord, Historical, MiddleManager). Flume only needs access to the Router or Broker for queries.
Trino access: Flume’s Lakehouse queries Druid via the Trino Druid connector through the Broker’s SQL endpoint.
Credential and auth management
OSS Druid: Often deployed without authentication. If auth is enabled, basic auth (username + password) via the Druid Basic Security extension.
Imply Cloud: API token or SSO-based authentication.
LDAP integration: Druid supports LDAP via its Kerberos/LDAP auth extensions. Provide LDAP bind credentials.
Druid has no GRANT model. Access control is coarse: typically all-or-nothing read access per authenticated user. Fine-grained ACLs available in Imply Enterprise.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Network reachability | curl http://<router>:8888/status | Returns Druid version JSON |
| Authentication | POST /druid/v2/sql with query SELECT 1 | Returns result |
| Datasource listing | GET /druid/v2/datasources | Lists datasources |
| Query test | POST /druid/v2/sql with SELECT * FROM <datasource> LIMIT 1 | Returns a row |
| Metadata | SELECT TABLE_NAME FROM INFORMATION_SCHEMA.TABLES | Lists queryable tables |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.