Skip to main content
By default, Coalesce Quality connects to your data warehouse over the public internet from a fixed set of egress IP addresses. If your security policy does not allow a warehouse to be reachable from the internet, Coalesce Quality can connect to it over a private endpoint instead. Private connectivity is set up together with the Coalesce team. It is not self-service: contact your Coalesce representative or support to start.

How it works

Coalesce operates a dedicated network in AWS and in Azure for private connectivity. For each service you want to reach, Coalesce creates a private endpoint in that network that points at your service, and you approve the connection from your side. Traffic between Coalesce Quality and the private endpoint travels through an encrypted tunnel, so your warehouse never has to accept connections from the public internet. You stay in control of the connection throughout: the endpoint can only be used once you approve it, and it can be removed at any time (see Removing a private connection). On Azure, your service does not need to be in the same region as the Coalesce endpoint: a private endpoint can connect to a Private Link Service in any public Azure region.

Setting up Snowflake on Azure

Snowflake supports Azure Private Link on Business Critical edition or higher. Both functions below require the ACCOUNTADMIN role.
1

Share your Private Link configuration

Run the following in your Snowflake account and send the output to your Coalesce contact:
The output tells us which Private Link Service to connect to and which hostnames (account URL and OCSP) must resolve privately.
2

Coalesce creates the private endpoint

Coalesce creates a private endpoint towards your Snowflake account and sends you the endpoint’s resource ID and an access token for the Coalesce Azure subscription.
3

Authorize the endpoint

Authorize the endpoint in Snowflake, using the values from the previous step:
See Snowflake’s guide to Azure Private Link and Snowflake and the SYSTEM$AUTHORIZE_PRIVATELINK reference for details.
4

Connect the integration

Once Coalesce confirms the endpoint is live, create or update your Snowflake integration using your Private Link account URL (the one ending in .privatelink.snowflakecomputing.com) as the host.
1

Share your service details

Send your Coalesce contact:
  • The alias or resource ID of your Azure Private Link Service
  • Each hostname Coalesce Quality should use to reach the service, and the port for each
2

Approve the connection

Coalesce creates a private endpoint towards your Private Link Service, and the connection appears on your service as Pending. In the Azure portal, open Private Link → Private link services, select your service, select the pending connection and choose Approve. See Microsoft’s guide to managing private endpoint connections.
3

Connect the integration

Once Coalesce confirms the endpoint is live, configure the integration using the hostnames you shared.

Setting up Amazon Redshift

Coalesce connects through a Redshift-managed VPC endpoint, which AWS supports under these conditions:
  • A provisioned cluster uses the RA3 or RG node type and has cluster relocation or Multi-AZ turned on. Redshift Serverless workgroups are supported as they are.
  • The cluster or workgroup listens on a port in the range 5431–5455 or 8191–8215. The default, 5439, is in range.
1

Share your cluster details

Send your Coalesce contact the AWS account ID that owns the cluster, the AWS region, and the cluster identifier (provisioned) or workgroup name (Serverless).
2

Grant endpoint access

Coalesce gives you the AWS account ID to grant access to.Provisioned cluster. In the Redshift console, grant the account access from the cluster’s properties, or use the AWS CLI:
Redshift Serverless. In the workgroup’s Data access tab, under Granted accounts, choose Grant access and enter the account ID. With the AWS CLI, attach a resource policy to the workgroup with aws redshift-serverless put-resource-policy. See AWS’s guide to connecting from a Redshift VPC endpoint in another account.
3

Connect the integration

Coalesce creates the endpoint and tells you the hostname to use. Create or update your Redshift integration with it.

Removing a private connection

Ask your Coalesce contact to remove the endpoint. For Azure Private Link Services and Redshift, you can also cut the connection off from your side:
  • Azure Private Link Service: select the connection on your service and choose Reject or Remove.
  • Redshift provisioned cluster: run aws redshift revoke-endpoint-access, or revoke the account in the console.
  • Redshift Serverless: in the workgroup’s Data access tab, select the account under Granted accounts and choose Revoke access.
Removing the endpoint does not change your warehouse or any of its settings.