Snowflake
All cloud providers (AWS, Azure, GCP)
Access mode: Read-only or read-write
Trino connector. Queryable via Flume’s Lakehouse. This system can be accessed both through its native protocol (for metadata introspection) and via Trino federation (for data profiling and cross-system analytical queries).
Required information
| Field | Details |
|---|---|
| Account identifier | Full URL: <org>-<account>.snowflakecomputing.com or legacy <account>.<region> format. |
| Warehouse | Compute warehouse to use. Dedicated XS warehouse recommended to isolate Flume’s workload. |
| Database(s) | All databases. Snowflake hierarchy: database → schema → object. |
| Schema(s) | Within each database. |
| Role | Dedicated Snowflake role (e.g., FLUME_READ_ROLE) with grants to target objects. |
| Authentication | Key-pair (preferred), username/password, or OAuth. Key-pair: Flume generates keypair, provides public key for assignment. |
| Access level | Read-only: USAGE on warehouse/database/schema + SELECT on tables/views. Procs: USAGE on procedures. |
Network considerations
Default: SaaS, so no VPN or peering is required. Connections over HTTPS (443).
Network Policies: If account uses network policies, Flume’s egress IPs must be allowed. Verify: SHOW NETWORK POLICIES;
PrivateLink (AWS) / Private Link (Azure): If configured for private connectivity, provide endpoint details. Flume must connect via the private endpoint DNS.
No firewall rules needed unless Network Policies or PrivateLink are in play.
Credential and auth management
Preferred: Key-pair auth. Flume generates RSA 2048+ keypair, provides public key. Client runs ALTER USER flume_svc SET RSA_PUBLIC_KEY='...'. No password to rotate.
Acceptable: OAuth. Snowflake external OAuth (Azure AD, Okta). Provide security integration details and token endpoint.
Acceptable: Username/password. Simplest but requires rotation policy.
MFA: Does not apply to key-pair auth. If enforced on account, service accounts using password auth must be exempted.
Session policies: Default 4-hour timeout. For large extracts, ensure SESSION_TIMEOUT is adequate or Flume implements reconnect logic.
Stored procedure and logic access
Snowflake stored procedures (JavaScript, SQL, Python, Scala) are invoked with CALL. Flume needs USAGE on the procedure. For introspection: SHOW PROCEDURES and GET_DDL('PROCEDURE', ...) require OWNERSHIP or appropriate grants. Caller’s rights procedures: Flume’s role needs the underlying table permissions. Owner’s rights: Only the owning role’s permissions apply.
Validation checks
| Check | Method | Expected result |
|---|---|---|
| Network reachability | HTTPS request to <account>.snowflakecomputing.com:443 | TLS handshake / 200 OK |
| Authentication | SELECT CURRENT_USER(), CURRENT_ROLE(); | Returns service account and role |
| Warehouse access | USE WAREHOUSE <wh>; SELECT 1; | Query executes, warehouse spins up |
| Schema visibility | SHOW TABLES IN <db>.<schema>; | Lists expected tables |
| Procedure listing | SHOW PROCEDURES IN <db>.<schema>; | Lists stored procedures |
| Procedure introspection | SELECT GET_DDL('PROCEDURE', '<db>.<schema>.<proc>(ARG_TYPES)'); | Returns procedure source |
| Execute test | CALL <db>.<schema>.<proc>(test_params); | Returns expected result |
| Permission audit | SHOW GRANTS TO ROLE <role>; | Grants match specification |
Every connection starts from the pre-engagement checklist and goes through the universal validation protocol before production sign-off.