How it works
Coalesce operates a dedicated network in AWS and in Azure for private connectivity. For each service you want to reach, Coalesce creates a private endpoint in that network that points at your service, and you approve the connection from your side. Traffic between Coalesce Quality and the private endpoint travels through an encrypted tunnel, so your warehouse never has to accept connections from the public internet. You stay in control of the connection throughout: the endpoint can only be used once you approve it, and it can be removed at any time (see Removing a private connection). On Azure, your service does not need to be in the same region as the Coalesce endpoint: a private endpoint can connect to a Private Link Service in any public Azure region.Setting up Snowflake on Azure
Snowflake supports Azure Private Link on Business Critical edition or
higher. Both functions below require the
ACCOUNTADMIN role.1
Share your Private Link configuration
Run the following in your Snowflake account and send the output to your
Coalesce contact:The output tells us which Private Link Service to connect to and which
hostnames (account URL and OCSP) must resolve privately.
2
Coalesce creates the private endpoint
Coalesce creates a private endpoint towards your Snowflake account and
sends you the endpoint’s resource ID and an access token for the
Coalesce Azure subscription.
3
Authorize the endpoint
Authorize the endpoint in Snowflake, using the values from the previous
step:See Snowflake’s guide to
Azure Private Link and Snowflake
and the
SYSTEM$AUTHORIZE_PRIVATELINK
reference for details.4
Connect the integration
Once Coalesce confirms the endpoint is live, create or update your
Snowflake integration using your
Private Link account URL (the one ending in
.privatelink.snowflakecomputing.com) as the host.Setting up another Azure Private Link Service
1
Share your service details
Send your Coalesce contact:
- The alias or resource ID of your Azure Private Link Service
- Each hostname Coalesce Quality should use to reach the service, and the port for each
2
Approve the connection
Coalesce creates a private endpoint towards your Private Link Service,
and the connection appears on your service as Pending. In the Azure
portal, open Private Link → Private link services, select your
service, select the pending connection and choose Approve. See
Microsoft’s guide to
managing private endpoint connections.
3
Connect the integration
Once Coalesce confirms the endpoint is live, configure the integration
using the hostnames you shared.
Setting up Amazon Redshift
Coalesce connects through a Redshift-managed VPC endpoint, which AWS supports under these conditions:- A provisioned cluster uses the RA3 or RG node type and has cluster relocation or Multi-AZ turned on. Redshift Serverless workgroups are supported as they are.
- The cluster or workgroup listens on a port in the range 5431–5455 or 8191–8215. The default, 5439, is in range.
1
Share your cluster details
Send your Coalesce contact the AWS account ID that owns the cluster, the
AWS region, and the cluster identifier (provisioned) or workgroup name
(Serverless).
2
Grant endpoint access
Coalesce gives you the AWS account ID to grant access to.Provisioned cluster. In the Redshift console, grant the account access
from the cluster’s properties, or use the AWS CLI:Redshift Serverless. In the workgroup’s Data access tab, under
Granted accounts, choose Grant access and enter the account ID.
With the AWS CLI, attach a resource policy to the workgroup with
aws redshift-serverless put-resource-policy. See AWS’s guide to
connecting from a Redshift VPC endpoint in another account.3
Connect the integration
Coalesce creates the endpoint and tells you the hostname to use. Create or
update your Redshift integration with it.
Removing a private connection
Ask your Coalesce contact to remove the endpoint. For Azure Private Link Services and Redshift, you can also cut the connection off from your side:- Azure Private Link Service: select the connection on your service and choose Reject or Remove.
- Redshift provisioned cluster: run
aws redshift revoke-endpoint-access, or revoke the account in the console. - Redshift Serverless: in the workgroup’s Data access tab, select the account under Granted accounts and choose Revoke access.