Snowflake Prerequisites

Before you configure the Micro-Integration for Snowflake, perform these setup steps in Snowflake. You need a Snowflake account with the ACCOUNTADMIN role or equivalent privileges to complete these steps.

  1. Create the target database and schema, if they don't already exist:

    CREATE DATABASE IF NOT EXISTS <database>;
    CREATE SCHEMA IF NOT EXISTS <database>.<schema>;
  2. Create the target table, or let the Micro-Integration create it for you. The Micro-Integration always writes to a table with the following fixed schema:

    CREATE TABLE <database>.<schema>.<table> (
        RECORD_CONTENT  VARIANT,
        RECORD_METADATA VARIANT
    );

    RECORD_CONTENT contains the output of the mapping stage. Structured payloads (maps, collections, arrays) are serialized to JSON; string and binary payloads are written as-is. RECORD_METADATA contains any message headers that are explicitly mapped. Headers are not automatically populated. For more information, see Binding Configuration for provisioning options and Message Headers for header mapping.

    Instead of creating the table manually, you can set provisioning-mode.tables to CREATE on the workflow's producer binding so the Micro-Integration creates the table automatically using the schema above. The default, NONE, requires the table to already exist.

  3. Create a dedicated Snowflake user for the Micro-Integration, rather than reusing a personal or shared account. A dedicated user isolates the Micro-Integration's access so you can audit, rotate, or revoke its credentials independently:

    CREATE USER <mi_user>
      DEFAULT_ROLE = <mi_role>
      MUST_CHANGE_PASSWORD = FALSE;
  4. Create a role for the Micro-Integration and grant it the privileges it needs to write to the target table. Grant CREATE TABLE only if you're using provisioning-mode.tables: CREATE; otherwise, pre-create the table and grant INSERT on it directly:

    CREATE ROLE <mi_role>;
    GRANT USAGE ON WAREHOUSE <warehouse> TO ROLE <mi_role>;
    GRANT USAGE ON DATABASE <database> TO ROLE <mi_role>;
    GRANT USAGE ON SCHEMA <database>.<schema> TO ROLE <mi_role>;
    GRANT INSERT ON TABLE <database>.<schema>.<table> TO ROLE <mi_role>;
    GRANT CREATE TABLE ON SCHEMA <database>.<schema> TO ROLE <mi_role>; -- only if using provisioning-mode.tables: CREATE
    
    GRANT ROLE <mi_role> TO USER <mi_user>;
    ALTER USER <mi_user> SET DEFAULT_WAREHOUSE = <warehouse>;

    The Micro-Integration has no warehouse property, so it relies on the user or role having a default warehouse assigned in Snowflake, as shown above. It only ever writes to the target table and never queries it, so the privileges shown above are all it needs.

    Use a role scoped to only these privileges in production. ACCOUNTADMIN and other broad system roles are useful for initial testing, but shouldn't be used for a running Micro-Integration.

  5. Set up key-pair authentication. The Micro-Integration requires Snowflake key-pair authentication; username and password authentication is not supported. Generate an RSA key pair using OpenSSL:

    openssl genrsa 2048 | openssl pkcs8 -topk8 -inform PEM -out rsa_key.p8 -nocrypt

    To encrypt the private key with a passphrase instead, omit -nocrypt:

    openssl genrsa 2048 | openssl pkcs8 -topk8 -inform PEM -v2 aes-256-cbc -out rsa_key.p8

    Then generate the matching public key:

    openssl rsa -in rsa_key.p8 -pubout -out rsa_key.pub

    The private key doesn't have to be in PKCS#8 format. The Micro-Integration also accepts traditional PEM-encoded RSA keys, whether encrypted or unencrypted. PKCS#8, produced by the commands above, is Snowflake's recommended format, not a requirement.

    Assign the public key to the Snowflake user, using only the key body (not the -----BEGIN/END PUBLIC KEY----- lines) as a single unbroken string:

    ALTER USER <mi_user> SET RSA_PUBLIC_KEY='<contents of rsa_key.pub>';

    Configure the path to rsa_key.p8 and, if you encrypted it, its passphrase using the private-key-path and private-key-password connection properties. Provide the contents of rsa_key.p8 and, if you encrypted it, its passphrase, as the Private Key and Private Key Password connection parameters.

  6. Retrieve the values you'll need to configure the connection:

    • Your account URL, in the format <locator>.<region>.snowflakecomputing.com:443. You can find your account locator and region by running SELECT CURRENT_ACCOUNT(), CURRENT_REGION();, or from the account selector in the Snowflake web interface.

    • The database, schema, and table names you created in step 1 (or that the Micro-Integration will auto-create, if you're using provisioning-mode.tables: CREATE).

  7. Verify your setup by connecting to Snowflake as <mi_user> (for example, using SnowSQL or the Snowflake web interface) and confirming you can reach the target objects before you continue to configuration:

    USE ROLE <mi_role>;
    USE WAREHOUSE <warehouse>;
    INSERT INTO <database>.<schema>.<table> (RECORD_CONTENT, RECORD_METADATA) VALUES (PARSE_JSON('{}'), PARSE_JSON('{}'));
    SELECT * FROM <database>.<schema>.<table>;

    If this succeeds, remove the test row before configuring the Micro-Integration: TRUNCATE TABLE <database>.<schema>.<table>;