Open Table format | Catalog type | Catalog authentication type | Storage type | Storage authentication type |
|---|---|---|---|---|
Apache Iceberg | AWS Glue Catalog* | None | Amazon S3* |
|
Hive Metastore | None | Amazon S3 | AWS Permanent IAM Credentials authentication | |
Hive Metastore | None | Microsoft Azure Data Lake Storage Gen2 | Azure Service Principal authentication | |
REST Catalog* | OAuth 2.0 Credentials | Amazon S3* |
| |
REST Catalog | OAuth 2.0 Credentials | Microsoft Azure Data Lake Storage Gen2 |
| |
Nessie Catalog* | OAuth 2.0 Credentials | MinIO* | MinIO Permanent IAM Credentials authentication | |
Delta Lake | AWS Glue Catalog | None | Amazon S3 | AWS Permanent IAM Credentials authentication |
*Open Table formats with catalog and storage types that apply to both mappings and mappings in advanced mode. The other catalog and storage types apply only to mappings in advanced mode. | ||||
Property | Description |
|---|---|
Connection Name | Name of the connection. Each connection name must be unique within the organization. Connection names can contain alphanumeric characters, spaces, and the following special characters: _ . + -, Maximum length is 255 characters. |
Description | Description of the connection. Maximum length is 4000 characters. |
Use Secret Vault | Stores sensitive credentials for this connection in the secrets manager that is configured for your organization. This property appears only if secrets manager is set up for your organization. This property is not supported by Data Ingestion and Replication and the Data Access Management services. When you enable the secret vault in the connection, you can select the credentials that the Secure Agent retrieves from the secrets manager. If you don't enable this option, the credentials are stored in the repository or on a local Secure Agent, depending on how your organization is configured. Note: If you’re using this connection to apply data access policies through pushdown or proxy services, you cannot use the Secret Vault configuration option. For information about how to configure and use a secrets manager, see Secrets manager configuration. |
Runtime Environment | The name of the runtime environment where you want to run tasks. Select a Secure Agent, Hosted Agent, or serverless runtime environment. You cannot run a database ingestion task on a Hosted Agent or in a serverless runtime environment. |
Open Table Format | The Open Table format that you want to use to read from or write data to a catalog. Select Apache Iceberg from the list. Note: Data Ingestion and Replication can't use Delta Lake. |
Property | Description |
|---|---|
Athena JDBC URL | Enter the JDBC URL in the following format: jdbc:athena://Region=<AWS_Region>;OutputLocation=<S3_Location> For example, jdbc:athena://Region=us-west1;OutputLocation=s3://working/dir. |
Catalog Authentication Type | The authentication method to connect to the catalog. Select one of the following options:
|
Property | Description |
|---|---|
Hive Metastore URI | The Hive thrift server URL to connect to Hive Metastore. |
Hive JDBC URL | The JDBC URL to connect to Hive4 server. |
Hive User Name | The user name of your Hive account to connect to Hive Metastore. |
Hive Password | The password of your Hive account to connect to Hive Metastore. |
Catalog Authentication Type | The authentication method to connect to the catalog. Select one of the following options:
|
Property | Description |
|---|---|
REST Catalog Type | The type of REST catalog that you want to connect to. Select Polaris Catalog. |
Catalog Endpoint URL | The endpoint URL of the REST catalog. For example, http://35.98.240.22:8181. |
Catalog Authentication Type | The authentication method to connect to the catalog. Select one of the following options:
|
Access Token URL | The URL provided by the OAuth 2.0 authorization server to obtain an access token. For example, http://35.98.240.22:8181/api/catalog/v1/oauth/tokens. |
Client ID | The client ID of OAuth 2.0 authorization server that is registered with the catalog. |
Client Secret | The client secret of OAuth 2.0 authorization server that is registered with the catalog. |
Scope | The scope parameters that define the permissions an access token grants to the catalog. For example, PRINCIPAL_ROLE:ALL. |
Property | Description |
|---|---|
Nessie URI | The base URI of the Nessie REST API endpoint. For example, http://3.8.140.58:18120/api/v2. |
Catalog Authentication Type | The authentication method to connect to the catalog. Select one of the following options:
|
Access Token URL | The URL provided by the OAuth 2.0 authorization server to obtain an access token. For example, https://in.okta.com/oauth2/default/v1/token. |
Client ID | The client ID of OAuth 2.0 authorization server that is registered with the catalog. |
Client Secret | The client secret of OAuth 2.0 authorization server that is registered with the catalog. |
Scope | The scope parameters that define the permissions an access token grants to the catalog. For example, nessieopentablepyn.access. |
Property | Description |
|---|---|
Access Key | The key to access the AWS Glue Catalog. |
Secret Key | The secret key to access the AWS Glue Catalog. The secret key is associated with the access key and uniquely identifies the account. |
Property | Description |
|---|---|
IAM Role ARN | The ARN of the IAM role assumed by the EC2 role to generate the temporary session credentials. |
External ID | A unique, user-defined string value that the IAM role requires the EC2 role to provide when calling the sts:AssumeRole API. |
Property | Description |
|---|---|
Azure Account Name | The name of the Microsoft Azure Data Lake Storage Gen2 account to stage the files. |
Azure Client ID | The client ID of your application. Enter the application ID or client ID for your application registered in the Azure Active Directory. |
Azure Client Secret | The client secret for your application. |
Azure Tenant ID | The directory ID or tenant ID for your application. |
Property | Description |
|---|---|
Endpoint URL | The HTTP or HTTPS URL of the MinIO storage endpoint. For example, http://3.8.140.58:9000. |
Access Key | Access key ID that uniquely identifies the IAM user credentials to access MinIO. |
Secret Key | Secret access key that authenticates the access key ID to securely access MinIO. |
Property | Description |
|---|---|
Warehouse Location | The path to the warehouse in MinIO where the Nessie catalog stores the Iceberg tables. For example, s3://warehouse/. |
Additional Properties | Additional properties to configure the MinIO storage. The default properties are client.region=us-east-1 and s3.path-style-access=true. Do not edit or delete the s3.path-style-access=true property. You can edit the client.region property and set the value to the MinIO region for your catalog. Enter new properties as key=value pairs separated by semicolons. |