All skills
aws avatar

/connecting-to-data-source

@b33847d

Create and troubleshoot AWS Glue connections to JDBC databases (Oracle, SQL Server, PostgreSQL, MySQL, RDS), Redshift, Snowflake, and BigQuery. Gathers connection hints from user, discovers existing connections and RDS/Redshift candidates, registers credentials in Secrets Manager or IAM DB auth, configures VPC, and tests. Triggers on: connect to database, set up Glue connection, register data source, connect to Snowflake/BigQuery/RDS, connection timeout, test connection, troubleshoot connection. Do NOT use for moving data (use ingesting-into-data-lake), creating tables (use creating-data-lake-table), queries (use querying-data-lake), catalog exploration (use exploring-data-catalog), or SaaS (Salesforce, ServiceNow, SAP, MongoDB, Kafka).

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/connecting-to-data-source

This session only. Nothing lands on disk.

referencessnowflake-setup.md

≈672 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Snowflake Connection Setup

AWS Glue native Snowflake connection (type SNOWFLAKE, not JDBC). Required for Glue for Spark ETL jobs reading from or writing to Snowflake.

Contents

Connection Type

Use ConnectionType: SNOWFLAKE. Do NOT use a JDBC connection configured with the Snowflake JDBC URL -- that path is for Glue crawlers only and cannot be used by Glue for Spark ETL jobs. The two credential types are stored separately in the Data Catalog.

Authentication Modes

Mode When to use Secret contents
User + password Quick start, non-production username, password
Key-pair (RSA) Production, long-lived workloads username, private_key (PEM, base64)
OAuth 2.0 Enterprise SSO, credential-free for end users client_id, client_secret, refresh_token, token URL

OAuth 2.0 for Glue Snowflake connections was released April 2026. For current Snowflake OAuth setup steps, cite Snowflake's OAuth docs rather than repeating them.

Connection JSON Template

Password-based:

{
  "Name": "snowflake-analytics",
  "ConnectionType": "SNOWFLAKE",
  "ConnectionProperties": {
    "HOST": "<account>.<region>.snowflakecomputing.com",
    "WAREHOUSE": "<warehouse-name>",
    "ROLE": "<role-name>",
    "DATABASE": "<default-database>",
    "SECRET_ID": "<secrets-manager-arn>"
  }
}

The secret must contain snowflakeUser and snowflakePassword keys per Glue's Snowflake connection convention.

Account identifier formats vary -- see Snowflake account identifier docs for the correct form for your region/cloud.

Private sources add PhysicalConnectionRequirements as in jdbc-setup.md.

PrivateLink

Snowflake accounts configured for AWS PrivateLink have a different hostname pattern. Glue jobs use the privatelink hostname directly. Configure the Glue connection's security group to allow outbound to the privatelink endpoint. See Snowflake PrivateLink docs.

Further Reading

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill includes some security considerations such as dynamic script generation for troubleshooting and a surface for indirect prompt injection. While these warrant review, they are used within the skill's intended functionality to register and test data source connections. See detailed analysis for context.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at b33847d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
Other metadata
metadata
{
  "version": "1",
  "argument-hint": "'[source-type|connection-name|hostname]'"
}

README badge

README badge for aws/agent-toolkit-for-aws/connecting-to-data-source