Skip to content
Get startedRequest a demo
Databases, lakes, and warehouses

Snowflake

All cloud providers (AWS, Azure, GCP)

Access mode: Read-only or read-write

Trino connector. Queryable via Flume’s Lakehouse. This system can be accessed both through its native protocol (for metadata introspection) and via Trino federation (for data profiling and cross-system analytical queries).

Required information

FieldDetails
Account identifierFull URL: <org>-<account>.snowflakecomputing.com or legacy <account>.<region> format.
WarehouseCompute warehouse to use. Dedicated XS warehouse recommended to isolate Flume’s workload.
Database(s)All databases. Snowflake hierarchy: database → schema → object.
Schema(s)Within each database.
RoleDedicated Snowflake role (e.g., FLUME_READ_ROLE) with grants to target objects.
AuthenticationKey-pair (preferred), username/password, or OAuth. Key-pair: Flume generates keypair, provides public key for assignment.
Access levelRead-only: USAGE on warehouse/database/schema + SELECT on tables/views. Procs: USAGE on procedures.

Network considerations

Default: SaaS, so no VPN or peering is required. Connections over HTTPS (443).

Network Policies: If account uses network policies, Flume’s egress IPs must be allowed. Verify: SHOW NETWORK POLICIES;

PrivateLink (AWS) / Private Link (Azure): If configured for private connectivity, provide endpoint details. Flume must connect via the private endpoint DNS.

No firewall rules needed unless Network Policies or PrivateLink are in play.

Credential and auth management

Preferred: Key-pair auth. Flume generates RSA 2048+ keypair, provides public key. Client runs ALTER USER flume_svc SET RSA_PUBLIC_KEY='...'. No password to rotate.

Acceptable: OAuth. Snowflake external OAuth (Azure AD, Okta). Provide security integration details and token endpoint.

Acceptable: Username/password. Simplest but requires rotation policy.

MFA: Does not apply to key-pair auth. If enforced on account, service accounts using password auth must be exempted.

Session policies: Default 4-hour timeout. For large extracts, ensure SESSION_TIMEOUT is adequate or Flume implements reconnect logic.

Stored procedure and logic access

Snowflake stored procedures (JavaScript, SQL, Python, Scala) are invoked with CALL. Flume needs USAGE on the procedure. For introspection: SHOW PROCEDURES and GET_DDL('PROCEDURE', ...) require OWNERSHIP or appropriate grants. Caller’s rights procedures: Flume’s role needs the underlying table permissions. Owner’s rights: Only the owning role’s permissions apply.

Validation checks

CheckMethodExpected result
Network reachabilityHTTPS request to <account>.snowflakecomputing.com:443TLS handshake / 200 OK
AuthenticationSELECT CURRENT_USER(), CURRENT_ROLE();Returns service account and role
Warehouse accessUSE WAREHOUSE <wh>; SELECT 1;Query executes, warehouse spins up
Schema visibilitySHOW TABLES IN <db>.<schema>;Lists expected tables
Procedure listingSHOW PROCEDURES IN <db>.<schema>;Lists stored procedures
Procedure introspectionSELECT GET_DDL('PROCEDURE', '<db>.<schema>.<proc>(ARG_TYPES)');Returns procedure source
Execute testCALL <db>.<schema>.<proc>(test_params);Returns expected result
Permission auditSHOW GRANTS TO ROLE <role>;Grants match specification

Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.