snowflake Snowflake Blog ·

Snowflake Data Connectivity Proxy for Private Data Now Generally Available

blogdatasnowflakegaarchitect
feature announcement

Snowflake has introduced the Data Connectivity Proxy (DCP) for Openflow, a new feature designed to securely connect Snowflake to private data sources across hybrid environments. DCP uses a lightweight, outbound-only agent that establishes an encrypted tunnel to Snowflake on port 443, eliminating the need for complex inbound firewall configurations, VPNs, or PrivateLink for each topology. This simplifies data integration for enterprises with strict security requirements, such as those in finance, healthcare, and manufacturing. The Data Connectivity Proxy is now generally available for Standard, Enterprise, and Business-Critical Snowflake editions on AWS, Azure, and Google Cloud.

  • Snowflake Openflow introduces Data Connectivity Proxy (DCP)
  • Addressing complex network challenges for private data access
  • Secure, outbound-only agent for private data tunneling
  • Enhanced security, reachability, and simplicity for data integration
Features (1)
  • Snowflake Openflow introduces Data Connectivity Proxy (DCP)

    Snowflake has announced the Data Connectivity Proxy (DCP) for Openflow, a fully managed data integration service that allows access to previously unreachable private data sources. It offers a consistent, Snowflake-provided agent model to reduce the need for topology-specific VPNs, PrivateLink, and third-party agents.

Notes (3)
  • Addressing complex network challenges for private data access

    Historically, integrating private data into managed pipelines required custom ETL infrastructure or lengthy projects to open inbound ports, which often violated regulatory requirements. Existing solutions like CSP-native private connections or VPNs address only parts of the problem and demand significant network engineering overhead.

  • Secure, outbound-only agent for private data tunneling

    DCP functions as a lightweight agent running within the private data environment, creating an outbound-only TLS connection to Snowflake on port 443. This design eliminates inbound firewall rules, with all traffic protected by mutual TLS (mTLS) and source credentials remaining within Snowflake.

  • Enhanced security, reachability, and simplicity for data integration

    DCP offers robust security by accepting no inbound connections and using explicit, auditable identities with mTLS. It covers various private sources including on-premises databases (Oracle, SQL Server), private Kafka brokers, and cross-cloud data, while simplifying deployment as a Docker image without Kubernetes.

Read the original announcement →

https://www.snowflake.com/content/snowflake-site/global/ja/blog/data-connectivity-proxy-openflow

Related releases