← Overview

Connectors

Connect every source, without exposing a credential

graal connects to your databases, files, APIs and Hadoop estate from your own infrastructure. The credential is an encrypted secret that the connection references: it is never written into code, into logs, or into anything you export.

Interface illustration

Key capabilities

Declared once, used everywhere

Relational databases

PostgreSQL, Oracle, SQL Server, MySQL and MariaDB, for reads and writes. Drivers ship in the runtime images: nothing to install on anyone’s laptop.

Files and object storage

CSV, Parquet, JSON, Excel and Avro, on any S3-compatible storage or on an SFTP server.

REST APIs

The connector handles pagination and secret-based authentication. A run only calls the hosts you have allowed.

Hadoop and Hive

HDFS and the Hive metastore, Kerberos included: the keytab is a project secret. Your Hive tables move to Iceberg at your own pace.

SAS files

.sas7bdat tables are read directly in a pipeline, with no SAS license.

Change data capture

Inserts, updates and deletes in your databases are tracked continuously (CDC) and written into your Iceberg tables.

How it works

From source to dataset

  1. Step 01

    Declare

    You pick the source type, the host and the secret to use. The secret is encrypted at rest and shared at project level.

  2. Step 02

    Test

    graal opens the connection from your cluster, detects the schema and shows a preview of the first rows.

  3. Step 03

    Use

    The same connection serves pipelines, jobs, notebooks and SQL, under the project’s permissions.

A credential never travels in clear

When a pipeline reads a database, the code it produces does not contain the password: it contains a reference to the secret. graal resolves that reference when the run starts, inside the execution container, and the value is written neither into the container definition nor into its logs. The code you export stays shareable, reviewable and versionable.

Traffic starts from your side

Connections open from your cluster to your sources. No intermediary service relays your data, and each run only reaches the destinations allowed for it: a database, a bucket, an API host. The rest of the network is closed to it.

Standards and integrations

Standard protocols, nothing proprietary

  • JDBC
  • PostgreSQL
  • Oracle
  • SQL Server
  • MySQL
  • MariaDB
  • S3
  • SFTP
  • REST
  • HDFS
  • Hive
  • Kerberos
  • CSV
  • Parquet
  • JSON
  • Avro
  • SAS7BDAT

Governance

Secrets that stay where they belong

  • Secrets encrypted at rest (AES-GCM), never shown in clear again after creation
  • A connection belongs to a project and follows its permissions
  • Every creation, change and use of a connection is recorded in the audit trail

Frequently asked questions

Do we need to open outbound traffic?

No. graal connects from your infrastructure to your sources. For an external API, you explicitly allow its host, and only that flow opens.

Does the password appear in generated code?

No. A pipeline’s code holds a reference to the secret, resolved when the run starts. Exported code can therefore be shared safely.

Can we keep our Hadoop cluster?

Yes. graal reads HDFS and Hive, Kerberos included, and you move to Iceberg table by table, with no deadline.

Are our SAS programs covered?

.sas7bdat tables are read directly. SAS programs run as jobs, described on the Orchestration page.

Connect your first source

A database, a bucket, a data preview: it is the first step of the demonstration.