Amazon Redshift
Provisioned clusters and Redshift Serverless.
Access mode: Read-only or read-write
Trino connector. Queryable via Flume’s Lakehouse. This system can be accessed both through its native protocol (for metadata introspection) and via Trino federation (for data profiling and cross-system analytical queries).
Required information
| Field | Details |
|---|---|
| Cluster endpoint | Provisioned: <cluster>.<id>.<region>.redshift.amazonaws.com:5439. Serverless: <workgroup>.<id>.<region>.redshift-serverless.amazonaws.com:5439. |
| Port | Default 5439. |
| Database name | Specific database within the cluster. |
| Schema(s) | All schemas. Default is public. |
| Credentials | DB user + password, or IAM auth via GetClusterCredentials API. |
| Access level | Read-only: GRANT USAGE ON SCHEMA + GRANT SELECT ON ALL TABLES. Procs: GRANT EXECUTE ON PROCEDURE. |
Network considerations
Provisioned clusters: Typically in a VPC. If private, need VPC peering or Redshift-managed VPC endpoint.
Public access: Cluster must have “Publicly Accessible” enabled + security group allows inbound on 5439 from Flume IPs.
Serverless: Same VPC considerations. Use workgroup endpoint.
Enhanced VPC Routing: If enabled, COPY/UNLOAD routes through VPC. Does not affect query connections but relevant for architecture awareness.
Credential and auth management
Preferred: IAM auth. Flume calls GetClusterCredentials with IAM role to get temporary DB credentials. Requires IAM policy with redshift:GetClusterCredentials.
Acceptable: DB auth. Username + password. Passwords expire per cluster settings; confirm rotation policy.
Wire protocol: PostgreSQL-compatible. sslmode=require standard.
Connection pooling: Redshift has a 500-connection limit by default. Flume uses connection pooling to stay well under.
Stored procedure and logic access
Redshift stored procedures use PL/pgSQL. Invoked with CALL. Require EXECUTE ON PROCEDURE in target schema. Introspection via SVV_REDSHIFT_PROCEDURES and pg_proc_info. SECURITY DEFINER procedures run as owner. Confirm the owner has the necessary privileges.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Network reachability | telnet <endpoint> 5439 | Connected |
| Authentication | SELECT 1; | Returns 1 |
| Identity | SELECT current_user, session_user; | Expected service account |
| Schema access | SELECT * FROM SVV_TABLES WHERE table_schema = '<schema>' | Lists tables |
| Procedure listing | SELECT * FROM SVV_REDSHIFT_PROCEDURES | Lists procedures |
| Execute test | CALL <schema>.<proc>(test_params); | Returns expected result |
| Permission audit | SELECT * FROM SVV_RELATION_PRIVILEGES WHERE identity_name = '<user>' | Grants match spec |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.