Skip to content

Add an AWS Glue Native Datastore with a New Connection

This page walks you through adding an AWS Glue Native source datastore while creating its connection: every field the form asks for, section by section, followed by the steps to test and finish.

Once the datastore is created, run a Sync to discover the tables in the selected database. Tables that AWS Glue Native declines to read, such as views and partition-projection tables, are skipped while the rest of the database syncs normally.

Already have a connection?

To add an AWS Glue Native datastore on a connection that already exists, go to Add with an Existing Connection.

Before you start, review the AWS Glue Native Permissions and the Authentication page. Access to the Glue Data Catalog is not enough on its own: the identity also needs to read the S3 objects the catalog points at.

Warning

AWS Glue Native cannot be used as an enrichment datastore. After you add it as a source, link a separate enrichment datastore as its destination to store anomalies and metadata: either during creation or afterwards.

Field reference

After you choose New Connection, the form shows three sections. Connection Properties holds everything that belongs to the connection, including the Secrets Management and Authentication groups inside it. Location holds the database to monitor, and General holds the datastore's own settings.

Connection Properties

These fields define the Glue Data Catalog Qualytics connects to. They belong to the connection, so they can be reused by other datastores later. Secrets Management and Authentication, described next, sit inside this section.

Field Required Type Description
Connection Name Text A label for the saved connection (e.g., acme_glue_us_east_1), so other datastores can reuse it later.
Region Text The AWS region of the Glue Data Catalog, for example us-east-1.
Catalog ID Text The 12-digit ID of the AWS account that owns the Glue Data Catalog, for cross-account access. Leave it empty to use the catalog in the account the credentials belong to.

No Catalog field

Connectors such as Athena ask for a Catalog name. Each AWS account has one Glue Data Catalog per region, so Region and, when needed, Catalog ID already identify it.

Authentication

Shown inside Connection Properties. The Type selector offers two options, Access Key and Assumed Role, and each one shows its own credential fields, so pick the tab that matches your choice. See AWS Glue Native Authentication for how each option works.

Field Required Type Description
Type Option Set to Access Key, which is the default.
Access Key Text The Access Key ID of the IAM user Qualytics connects as.
Secret Key Text The Secret Access Key for that Access Key ID. Stored encrypted and never displayed back.
Field Required Type Description
Type Option Set to Assumed Role to have Qualytics assume an IAM role instead of using a stored key pair.
Role ARN Text The ARN of the role Qualytics assumes (e.g., arn:aws:iam::123456789012:role/MyRole).
External ID Text The External ID your role's trust policy requires, if any.

AWS and local deployments only

Assumed Role is offered on AWS and local deployments only. Elsewhere the Type selector is not shown and the form goes straight to the Access Key fields.

Secrets Management

Also inside Connection Properties, and optional. Use it only if you want Qualytics to pull credentials from a secrets manager instead of typing them into the form. Turn on HashiCorp Vault to show the fields below. Despite the label, any secrets manager that exposes a compatible REST API works; see Secrets Management.

Field Required Type Description
Login URL Text The Vault endpoint Qualytics uses to authenticate (e.g., https://vault.example.com/v1/auth/approle/login).
Credentials Payload Text A JSON body containing the credentials Vault expects (e.g., {"role_id":"...","secret_id":"..."}).
Token JSONPath Text The JSONPath that extracts the client token from Vault's response. Defaults to $.auth.client_token.
Secret URL Text The Vault path where the secret is stored (e.g., https://vault.example.com/v1/secret/data/glue).
Token Header Name Text The HTTP header name used to send the token. Defaults to X-Vault-Token.
Data JSONPath Text The JSONPath that extracts the secret payload from Vault's response. Defaults to $.data.

Location

Pick the Glue database Qualytics should read from. Unlike Connection Properties, this section belongs to the datastore rather than to the connection, so it is filled in on both flows.

Field Required Type Description
Database Option One or more Glue databases to monitor. The dropdown is filled in once Qualytics connects to the catalog. Each database you pick becomes its own Qualytics datastore.

General

The datastore's own settings.

Field Required Type Description
Name Text The datastore name in Qualytics. Comes suggested from the connection name and the database, so you can leave it blank to accept that suggestion.
Group Option Organizes your datastores under a shared group in the navigation tree. Select an existing group, or turn on Add New Group to create one.
Teams Option Select one or more teams to associate with this source datastore.
Initiate Sync Checkbox Ask Qualytics to run the first Sync on each datastore once it is created.

Selecting more than one database

When you pick several databases in Location, each one becomes its own datastore and Name is replaced by Name Template, a naming pattern applied to all of them. Use {{schema}} as the placeholder for the database name: glue_{{schema}} becomes glue_sales, glue_finance, and so on. Left empty, each datastore is named from the connection name and its database.

Steps

Step 1: Navigate to the Datastores page.

Step 2: Click the Add button at the top-right corner and choose Source from its menu.

Step 3: The Datastore step opens, the first of two.

Step 4: Select New Connection next to the Search field.

Step 5: Select AWS Glue Native from the connector grid. Use the search field to filter connectors by name.

Step 6: Fill in the fields of Connection Properties, the Authentication fields for the Type you choose, Location, and General, as described in the Field reference.

Step 7: Click Test connection. A success message confirms that the connection has been verified.

Info

The Finish and Next buttons stay disabled until the connection test passes on the current values. If you change a connection field after a successful test, test again. The test reads the catalog, not the data files, so it can pass before the S3 permissions are in place. If the test fails, see Troubleshooting.

Step 8: Click Finish to create the datastore.

Tip

To link an enrichment destination so Qualytics can store anomalies and metadata from the first operation, click Next instead of Finish. See Link Enrichment on Datastore Creation.

Step 9: A success dialog confirms that your datastore has been added. Click Go to your datastore to open its page.