Skip to content
Get startedRequest a demo
Databases, lakes, and warehouses

Microsoft SQL Server

On-premises, Azure SQL Database, Azure SQL Managed Instance, AWS RDS for SQL Server.

Access mode: Read-only or read-write

Trino connector. Queryable via Flume’s Lakehouse. This system can be accessed both through its native protocol (for metadata introspection) and via Trino federation (for data profiling and cross-system analytical queries).

Required information

FieldDetails
Host / IPFQDN or IP. Azure SQL: <server>.database.windows.net. Named instances: host\instance or host,port.
PortDefault 1433. Named instances may use dynamic ports. Confirm the assigned port or ensure SQL Browser (UDP 1434) is accessible.
Database name(s)All databases requiring access. Separate service accounts per database acceptable.
Authentication typeSQL Auth, Windows/AD Auth, Azure AD (Entra ID) service principal, or managed identity.
Service account credentialsSQL Auth: username + password. Windows Auth: domain\username. Azure AD: tenant ID, client ID, client secret.
EncryptionEncrypt=True standard. Self-signed certs require TrustServerCertificate=True or provide CA cert.
Access levelRead-only minimum: db_datareader. Stored procs: EXECUTE on target schemas. Read-write: db_datawriter + DDL as scoped.

Network considerations

On-premises: VPN or SSH tunnel required. If behind corporate firewall, need site-to-site VPN endpoint or bastion host.

Azure SQL: Server firewall must allow Flume egress IPs, or configure VNet rule / Private Endpoint. Private Endpoint requires VPC/VNet peering.

AWS RDS: Security group inbound on 1433 from Flume CIDR. Private subnet requires VPC peering or PrivateLink.

Named instances: SQL Browser service (UDP 1434) must be reachable, or pin instance to a static port.

Always Encrypted / TDE: Does not affect connectivity but may affect column-level read access. Confirm whether Flume needs access to encryption keys.

Credential and auth management

Preferred: Azure AD service principal (for Azure SQL). Flume operates as a service principal. Provide app registration tenant ID, client ID, and client secret or certificate. Token refresh automatic.

Preferred: Windows/AD Auth (for on-prem). Requires Kerberos config. We need: SPN, KDC address, and keytab file. Complex but no password rotation needed.

Acceptable: SQL Auth. Simplest but many enterprises prohibit it. Password rotation policy must be documented.

Session management: Document LOCK_TIMEOUT and QUERY_TIMEOUT defaults. Long-running stored procs may need elevated limits. Connection pooling handled by Flume.

MFA: If enforced on the tenant, service accounts must be exempted or use certificate-based auth.

Stored procedure and logic access

Require EXECUTE permission on all in-scope stored procedures plus VIEW DEFINITION to introspect signatures and source (via sys.sql_modules or sp_helptext). If procs call linked servers, those linked server connections must also authorize Flume’s service account. For CLR procedures, confirm the assembly is trusted.

Validation checks

CheckMethodExpected result
Network reachabilitytelnet <host> <port> or Test-NetConnectionTCP connection established
AuthenticationSELECT 1Returns 1, no auth errors
Identity confirmationSELECT SUSER_SNAME(), CURRENT_USERReturns expected service account
Schema visibilitySELECT * FROM INFORMATION_SCHEMA.TABLESLists all expected tables
Stored proc listingSELECT * FROM INFORMATION_SCHEMA.ROUTINES WHERE ROUTINE_TYPE = 'PROCEDURE'Lists expected procedures
Stored proc introspectionEXEC sp_helptext '<proc_name>'Returns procedure source text
Stored proc executionEXEC <read_only_proc> @test_param=1Returns expected result set
Permissions auditSELECT * FROM fn_my_permissions(NULL, 'DATABASE')Granted permissions match spec

Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.