Skip to content
Get startedRequest a demo
Databases, lakes, and warehouses

Databricks

Unity Catalog or Hive Metastore, on AWS, Azure, or GCP.

Access mode: Read-only or read-write

Trino connector. Queryable via Flume’s Lakehouse. This system can be accessed both through its native protocol (for metadata introspection) and via Trino federation (for data profiling and cross-system analytical queries).

Required information

FieldDetails
Workspace URLhttps://<workspace>.cloud.databricks.com or regional equivalent.
SQL Warehouse / ClusterCompute endpoint. Prefer SQL Warehouse (serverless or pro) for cost isolation. Provide the HTTP path.
Catalog(s)Unity Catalog: list catalogs. Legacy Hive: typically hive_metastore.
Schema(s)Within each catalog.
AuthenticationOAuth M2M service principal (preferred), PAT, or Azure AD token.
Access levelRead-only: USE CATALOG, USE SCHEMA, SELECT on tables. Functions: EXECUTE FUNCTION.

Network considerations

Default: SaaS, connections over HTTPS (443).

Private Link: If workspace uses AWS PrivateLink / Azure Private Link, need network peering or transit gateway.

IP access lists: If enabled, add Flume egress IPs. Check workspace Settings → Security → IP Access Lists.

Credential and auth management

Preferred: OAuth M2M (service principal). Create Databricks service principal, generate OAuth secret, grant to catalogs/schemas. Short-lived tokens, automatic rotation.

Acceptable: PAT. Simpler but has fixed expiry (max 1 year). No auto-rotation. OK for POC/dev.

Azure AD token: For Azure-hosted workspaces, use managed identity. Provide service principal app ID + secret.

Token refresh: Handled by Flume’s ODBC/SDK layer.

Stored procedure and logic access

Databricks UDFs (Python, SQL, Scala) accessible via SELECT. For Unity Catalog, EXECUTE permission required. Legacy Hive metastore: permissions managed at cluster level. UDF introspection via SHOW FUNCTIONS IN <catalog>.<schema>.

Validation checks

CheckMethodExpected result
Network reachabilityHTTPS GET to workspace URL200 OK
AuthenticationSELECT current_user()Returns service principal ID
Catalog accessSHOW SCHEMAS IN <catalog>Lists schemas
Table accessSELECT * FROM <catalog>.<schema>.<table> LIMIT 1Returns a row
Function listingSHOW FUNCTIONS IN <catalog>.<schema>Lists UDFs
Permission auditSHOW GRANTS ON SCHEMA <catalog>.<schema>Grants match spec

Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.