Openflow security¶
This section describes how Openflow authenticates to Snowflake and to external systems, and how you manage secrets used by connectors and runtimes.
For a high-level summary of authentication, authorization, encryption, secrets, private connectivity, and Tri-Secret Secure support, see Security in About Openflow. For Snowflake Managed Token details (the default runtime-to-Snowflake authentication method), see Snowflake Managed Token authentication.
Topics¶
- Use Workload Identity Federation with Openflow: Authenticate from Openflow runtimes to AWS, Azure, and Google Cloud without long-lived cloud credentials.
- Use external secret providers with Openflow: Expose secrets from AWS Secrets Manager, Azure Key Vault, or Google Cloud Secret Manager as Openflow parameters.
- Data Connectivity Proxy: Route connector traffic through a Data Connectivity Proxy for private or controlled network paths.