DEV Community

OnaEiuspkz
OnaEiuspkz

Posted on

3,199 Apache Druid instances: an analytics engine with an administrative side

Apache Druid is a real time analytics database designed for event data. A ZoomEye query for the application fingerprint records 3,199 matches.
How the number was obtained
The query was app="Apache Druid", run against the ZoomEye index on 29 September 2026 at 02:48 UTC. The unit is a fingerprint match on a reachable service.
The components that answer on a network
A Druid cluster includes a coordinator that manages data segments, an overlord that manages ingestion tasks, a broker that serves queries, and historical and middle manager processes. Each exposes an HTTP interface, and the console provides a combined view across them.
Several of these interfaces accept task definitions. A caller who can submit a task can define the input source, which in older releases included the ability to read from arbitrary locations. That makes an exposed ingestion endpoint a more consequential finding than an exposed query endpoint.
Query surfaces leak in a quieter way. A permissive native query interface allows enumeration of datasource names, dimensions, and sample rows, which maps the data estate without triggering a login failure.
The count describes presence, not configuration
A fingerprint match confirms an identifiable service. It does not report whether authentication was enabled or which API path answered.
What to check
Keep coordinator, overlord, and console interfaces on a private network, and require authentication on the broker if it is reachable at all. Review ingestion permissions and restrict task submission to a small set of identities. Enable audit logging for task creation and configuration changes, and monitor for new datasources that appear without a corresponding deployment.
References

Top comments (0)