Microsoft SQL Server
On-premises, Azure SQL Database, Azure SQL Managed Instance, AWS RDS for SQL Server.
Access mode: Read-only or read-write
Trino connector. Queryable via Flume’s Lakehouse. This system can be accessed both through its native protocol (for metadata introspection) and via Trino federation (for data profiling and cross-system analytical queries).
Required information
| Field | Details |
|---|---|
| Host / IP | FQDN or IP. Azure SQL: <server>.database.windows.net. Named instances: host\instance or host,port. |
| Port | Default 1433. Named instances may use dynamic ports. Confirm the assigned port or ensure SQL Browser (UDP 1434) is accessible. |
| Database name(s) | All databases requiring access. Separate service accounts per database acceptable. |
| Authentication type | SQL Auth, Windows/AD Auth, Azure AD (Entra ID) service principal, or managed identity. |
| Service account credentials | SQL Auth: username + password. Windows Auth: domain\username. Azure AD: tenant ID, client ID, client secret. |
| Encryption | Encrypt=True standard. Self-signed certs require TrustServerCertificate=True or provide CA cert. |
| Access level | Read-only minimum: db_datareader. Stored procs: EXECUTE on target schemas. Read-write: db_datawriter + DDL as scoped. |
Network considerations
On-premises: VPN or SSH tunnel required. If behind corporate firewall, need site-to-site VPN endpoint or bastion host.
Azure SQL: Server firewall must allow Flume egress IPs, or configure VNet rule / Private Endpoint. Private Endpoint requires VPC/VNet peering.
AWS RDS: Security group inbound on 1433 from Flume CIDR. Private subnet requires VPC peering or PrivateLink.
Named instances: SQL Browser service (UDP 1434) must be reachable, or pin instance to a static port.
Always Encrypted / TDE: Does not affect connectivity but may affect column-level read access. Confirm whether Flume needs access to encryption keys.
Credential and auth management
Preferred: Azure AD service principal (for Azure SQL). Flume operates as a service principal. Provide app registration tenant ID, client ID, and client secret or certificate. Token refresh automatic.
Preferred: Windows/AD Auth (for on-prem). Requires Kerberos config. We need: SPN, KDC address, and keytab file. Complex but no password rotation needed.
Acceptable: SQL Auth. Simplest but many enterprises prohibit it. Password rotation policy must be documented.
Session management: Document LOCK_TIMEOUT and QUERY_TIMEOUT defaults. Long-running stored procs may need elevated limits. Connection pooling handled by Flume.
MFA: If enforced on the tenant, service accounts must be exempted or use certificate-based auth.
Stored procedure and logic access
Require EXECUTE permission on all in-scope stored procedures plus VIEW DEFINITION to introspect signatures and source (via sys.sql_modules or sp_helptext). If procs call linked servers, those linked server connections must also authorize Flume’s service account. For CLR procedures, confirm the assembly is trusted.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Network reachability | telnet <host> <port> or Test-NetConnection | TCP connection established |
| Authentication | SELECT 1 | Returns 1, no auth errors |
| Identity confirmation | SELECT SUSER_SNAME(), CURRENT_USER | Returns expected service account |
| Schema visibility | SELECT * FROM INFORMATION_SCHEMA.TABLES | Lists all expected tables |
| Stored proc listing | SELECT * FROM INFORMATION_SCHEMA.ROUTINES WHERE ROUTINE_TYPE = 'PROCEDURE' | Lists expected procedures |
| Stored proc introspection | EXEC sp_helptext '<proc_name>' | Returns procedure source text |
| Stored proc execution | EXEC <read_only_proc> @test_param=1 | Returns expected result set |
| Permissions audit | SELECT * FROM fn_my_permissions(NULL, 'DATABASE') | Granted permissions match spec |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.