> ## Documentation Index
> Fetch the complete documentation index at: https://docs.synq.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Private Connectivity

> Connect Coalesce Quality to your data warehouse over AWS PrivateLink or Azure Private Link instead of the public internet

By default, Coalesce Quality connects to your data warehouse over the public
internet from a fixed set of [egress IP addresses](/security/ip). If your
security policy does not allow a warehouse to be reachable from the internet,
Coalesce Quality can connect to it over a private endpoint instead.

Private connectivity is set up together with the Coalesce team. It is not
self-service: contact your Coalesce representative or
[support](/support/support) to start.

### How it works

Coalesce operates a dedicated network in AWS and in Azure for private
connectivity. For each service you want to reach, Coalesce creates a private
endpoint in that network that points at your service, and you approve the
connection from your side. Traffic between Coalesce Quality and the private
endpoint travels through an encrypted tunnel, so your warehouse never has to
accept connections from the public internet.

You stay in control of the connection throughout: the endpoint can only be
used once you approve it, and it can be removed at any time (see
[Removing a private connection](#removing-a-private-connection)).

On Azure, your service does not need to be in the same region as the Coalesce
endpoint: a private endpoint can connect to a Private Link Service in any
public Azure region.

### Setting up Snowflake on Azure

<Note>
  Snowflake supports Azure Private Link on Business Critical edition or
  higher. Both functions below require the `ACCOUNTADMIN` role.
</Note>

<Steps>
  <Step title="Share your Private Link configuration">
    Run the following in your Snowflake account and send the output to your
    Coalesce contact:

    ```sql theme={null}
    SELECT SYSTEM$GET_PRIVATELINK_CONFIG();
    ```

    The output tells us which Private Link Service to connect to and which
    hostnames (account URL and OCSP) must resolve privately.
  </Step>

  <Step title="Coalesce creates the private endpoint">
    Coalesce creates a private endpoint towards your Snowflake account and
    sends you the endpoint's resource ID and an access token for the
    Coalesce Azure subscription.
  </Step>

  <Step title="Authorize the endpoint">
    Authorize the endpoint in Snowflake, using the values from the previous
    step:

    ```sql theme={null}
    SELECT SYSTEM$AUTHORIZE_PRIVATELINK(
      '<private-endpoint-resource-id>',
      '<access-token>'
    );
    ```

    See Snowflake's guide to
    [Azure Private Link and Snowflake](https://docs.snowflake.com/en/user-guide/privatelink-azure)
    and the
    [`SYSTEM$AUTHORIZE_PRIVATELINK`](https://docs.snowflake.com/en/sql-reference/functions/system_authorize_privatelink)
    reference for details.
  </Step>

  <Step title="Connect the integration">
    Once Coalesce confirms the endpoint is live, create or update your
    [Snowflake integration](/dw-integrations/snowflake) using your
    Private Link account URL (the one ending in
    `.privatelink.snowflakecomputing.com`) as the host.
  </Step>
</Steps>

### Setting up another Azure Private Link Service

<Steps>
  <Step title="Share your service details">
    Send your Coalesce contact:

    * The alias or resource ID of your Azure Private Link Service
    * Each hostname Coalesce Quality should use to reach the service, and the port for each
  </Step>

  <Step title="Approve the connection">
    Coalesce creates a private endpoint towards your Private Link Service,
    and the connection appears on your service as **Pending**. In the Azure
    portal, open **Private Link → Private link services**, select your
    service, select the pending connection and choose **Approve**. See
    Microsoft's guide to
    [managing private endpoint connections](https://learn.microsoft.com/en-us/azure/private-link/manage-private-endpoint#private-endpoint-connections).
  </Step>

  <Step title="Connect the integration">
    Once Coalesce confirms the endpoint is live, configure the integration
    using the hostnames you shared.
  </Step>
</Steps>

### Setting up Amazon Redshift

Coalesce connects through a
[Redshift-managed VPC endpoint](https://docs.aws.amazon.com/redshift/latest/mgmt/managing-cluster-cross-vpc.html),
which AWS supports under these conditions:

* A provisioned cluster uses the RA3 or RG node type and has cluster relocation or Multi-AZ turned on. Redshift Serverless workgroups are supported as they are.
* The cluster or workgroup listens on a port in the range 5431–5455 or 8191–8215. The default, 5439, is in range.

<Steps>
  <Step title="Share your cluster details">
    Send your Coalesce contact the AWS account ID that owns the cluster, the
    AWS region, and the cluster identifier (provisioned) or workgroup name
    (Serverless).
  </Step>

  <Step title="Grant endpoint access">
    Coalesce gives you the AWS account ID to grant access to.

    **Provisioned cluster.** In the Redshift console, grant the account access
    from the cluster's properties, or use the AWS CLI:

    ```bash theme={null}
    aws redshift authorize-endpoint-access \
      --cluster-identifier <your-cluster> \
      --account <coalesce-aws-account-id>
    ```

    **Redshift Serverless.** In the workgroup's **Data access** tab, under
    **Granted accounts**, choose **Grant access** and enter the account ID.
    With the AWS CLI, attach a resource policy to the workgroup with
    `aws redshift-serverless put-resource-policy`. See AWS's guide to
    [connecting from a Redshift VPC endpoint in another account](https://docs.aws.amazon.com/redshift/latest/mgmt/serverless-connecting.html#serverless-cross-vpc).
  </Step>

  <Step title="Connect the integration">
    Coalesce creates the endpoint and tells you the hostname to use. Create or
    update your [Redshift integration](/dw-integrations/redshift) with it.
  </Step>
</Steps>

### Removing a private connection

Ask your Coalesce contact to remove the endpoint. For Azure Private Link
Services and Redshift, you can also cut the connection off from your side:

* **Azure Private Link Service:** select the connection on your service and choose **Reject** or **Remove**.
* **Redshift provisioned cluster:** run `aws redshift revoke-endpoint-access`, or revoke the account in the console.
* **Redshift Serverless:** in the workgroup's **Data access** tab, select the account under **Granted accounts** and choose **Revoke access**.

Removing the endpoint does not change your warehouse or any of its settings.
