Add an AWS Glue Native Datastore with a New Connection
This page walks you through adding an AWS Glue Native source datastore while creating its connection: every field the form asks for, section by section, followed by the steps to test and finish.
Once the datastore is created, run a Sync to discover the tables in the selected database. Tables that AWS Glue Native declines to read, such as views and partition-projection tables, are skipped while the rest of the database syncs normally.
Already have a connection?
To add an AWS Glue Native datastore on a connection that already exists, go to Add with an Existing Connection.
Before you start, review the AWS Glue Native Permissions and the Authentication page. Access to the Glue Data Catalog is not enough on its own: the identity also needs to read the S3 objects the catalog points at.
Warning
AWS Glue Native cannot be used as an enrichment datastore. After you add it as a source, link a separate enrichment datastore as its destination to store anomalies and metadata: either during creation or afterwards.
Field reference
After you choose New Connection, the form shows three sections. Connection Properties holds everything that belongs to the connection, including the Secrets Management and Authentication groups inside it. Location holds the database to monitor, and General holds the datastore's own settings.
Connection Properties
These fields define the Glue Data Catalog Qualytics connects to. They belong to the connection, so they can be reused by other datastores later. Secrets Management and Authentication, described next, sit inside this section.
| Field | Required | Type | Description |
|---|---|---|---|
| Connection Name | Text | A label for the saved connection (e.g., acme_glue_us_east_1), so other datastores can reuse it later. |
|
| Region | Text | The AWS region of the Glue Data Catalog, for example us-east-1. |
|
| Catalog ID | Text | The 12-digit ID of the AWS account that owns the Glue Data Catalog, for cross-account access. Leave it empty to use the catalog in the account the credentials belong to. |
No Catalog field
Connectors such as Athena ask for a Catalog name. Each AWS account has one Glue Data Catalog per region, so Region and, when needed, Catalog ID already identify it.
Authentication
Shown inside Connection Properties. The Type selector offers two options, Access Key and Assumed Role, and each one shows its own credential fields, so pick the tab that matches your choice. See AWS Glue Native Authentication for how each option works.
| Field | Required | Type | Description |
|---|---|---|---|
| Type | Option | Set to Access Key, which is the default. | |
| Access Key | Text | The Access Key ID of the IAM user Qualytics connects as. | |
| Secret Key | Text | The Secret Access Key for that Access Key ID. Stored encrypted and never displayed back. |
| Field | Required | Type | Description |
|---|---|---|---|
| Type | Option | Set to Assumed Role to have Qualytics assume an IAM role instead of using a stored key pair. | |
| Role ARN | Text | The ARN of the role Qualytics assumes (e.g., arn:aws:iam::123456789012:role/MyRole). |
|
| External ID | Text | The External ID your role's trust policy requires, if any. |
AWS and local deployments only
Assumed Role is offered on AWS and local deployments only. Elsewhere the Type selector is not shown and the form goes straight to the Access Key fields.
Secrets Management
Also inside Connection Properties, and optional. Use it only if you want Qualytics to pull credentials from a secrets manager instead of typing them into the form. Turn on HashiCorp Vault to show the fields below. Despite the label, any secrets manager that exposes a compatible REST API works; see Secrets Management.
| Field | Required | Type | Description |
|---|---|---|---|
| Login URL | Text | The Vault endpoint Qualytics uses to authenticate (e.g., https://vault.example.com/v1/auth/approle/login). |
|
| Credentials Payload | Text | A JSON body containing the credentials Vault expects (e.g., {"role_id":"...","secret_id":"..."}). |
|
| Token JSONPath | Text | The JSONPath that extracts the client token from Vault's response. Defaults to $.auth.client_token. |
|
| Secret URL | Text | The Vault path where the secret is stored (e.g., https://vault.example.com/v1/secret/data/glue). |
|
| Token Header Name | Text | The HTTP header name used to send the token. Defaults to X-Vault-Token. |
|
| Data JSONPath | Text | The JSONPath that extracts the secret payload from Vault's response. Defaults to $.data. |
Location
Pick the Glue database Qualytics should read from. Unlike Connection Properties, this section belongs to the datastore rather than to the connection, so it is filled in on both flows.
| Field | Required | Type | Description |
|---|---|---|---|
| Database | Option | One or more Glue databases to monitor. The dropdown is filled in once Qualytics connects to the catalog. Each database you pick becomes its own Qualytics datastore. |
General
The datastore's own settings.
| Field | Required | Type | Description |
|---|---|---|---|
| Name | Text | The datastore name in Qualytics. Comes suggested from the connection name and the database, so you can leave it blank to accept that suggestion. | |
| Group | Option | Organizes your datastores under a shared group in the navigation tree. Select an existing group, or turn on Add New Group to create one. | |
| Teams | Option | Select one or more teams to associate with this source datastore. | |
| Initiate Sync | Checkbox | Ask Qualytics to run the first Sync on each datastore once it is created. |
Selecting more than one database
When you pick several databases in Location, each one becomes its own datastore and Name is replaced by Name Template, a naming pattern applied to all of them. Use {{schema}} as the placeholder for the database name: glue_{{schema}} becomes glue_sales, glue_finance, and so on. Left empty, each datastore is named from the connection name and its database.
Steps
Step 1: Navigate to the Datastores page.
Step 2: Click the Add button at the top-right corner and choose Source from its menu.
Step 3: The Datastore step opens, the first of two.
Step 4: Select New Connection next to the Search field.
Step 5: Select AWS Glue Native from the connector grid. Use the search field to filter connectors by name.
Step 6: Fill in the fields of Connection Properties, the Authentication fields for the Type you choose, Location, and General, as described in the Field reference.
Step 7: Click Test connection. A success message confirms that the connection has been verified.
Info
The Finish and Next buttons stay disabled until the connection test passes on the current values. If you change a connection field after a successful test, test again. The test reads the catalog, not the data files, so it can pass before the S3 permissions are in place. If the test fails, see Troubleshooting.
Step 8: Click Finish to create the datastore.
Tip
To link an enrichment destination so Qualytics can store anomalies and metadata from the first operation, click Next instead of Finish. See Link Enrichment on Datastore Creation.
Step 9: A success dialog confirms that your datastore has been added. Click Go to your datastore to open its page.