Cassandra / ScyllaDB
On-premises, DataStax Astra, ScyllaDB Cloud.
Access mode: Read-only (typically)
Trino connector. Queryable via Flume’s Lakehouse. This system can be accessed both through its native protocol (for metadata introspection) and via Trino federation (for data profiling and cross-system analytical queries).
Required information
| Field | Details |
|---|---|
| Contact points | Comma-separated list of node IPs/FQDNs. Astra: connect via Secure Connect Bundle. |
| Port | Default 9042 (native CQL). TLS: 9142. |
| Datacenter | Local datacenter name for DCAwareRoundRobinPolicy. |
| Keyspace(s) | Cassandra keyspaces to access. |
| Credentials | Username + password, or Astra token. |
| Access level | Read-only: SELECT on keyspaces/tables. |
Network considerations
On-premises: VPN required. All nodes in the cluster should be reachable (driver discovers topology and connects to multiple nodes).
Astra: Uses Secure Connect Bundle (zip) which encapsulates TLS certs and connection metadata. No IP allowlisting needed.
ScyllaDB Cloud: Standard cloud networking. Provide connection details from dashboard.
Important: Cassandra drivers connect to multiple nodes. Firewall rules must allow Flume to reach all nodes, not just the seed nodes.
Credential and auth management
Astra: Application token. Generated in Astra console. Scoped to org/DB/keyspace roles. Auto-rotation available.
Standard auth: Internal Cassandra authenticator with username + password.
LDAP auth: If using DataStax Enterprise LDAP integration.
TLS: Client-to-node encryption should be enabled. Provide CA cert if using internal CA.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Network reachability | cqlsh <host> <port> or Astra: connect with Secure Bundle | Connected to cluster |
| Authentication | SELECT now() FROM system.local; | Returns timestamp |
| Keyspace access | DESCRIBE KEYSPACES; | Lists expected keyspaces |
| Table access | DESCRIBE TABLES; (within keyspace) | Lists tables |
| Read test | SELECT * FROM <keyspace>.<table> LIMIT 1; | Returns a row |
| Topology check | SELECT * FROM system.peers; | All nodes reachable |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.