C3 AI Documentation Home

Grant an Application Direct Access to a JDBC Datastore

The raw SQL actions on the Jdbc Type, such as Jdbc#queryTuples and Jdbc#exec, are restricted to cluster administrators. Direct access lets a cluster administrator allowlist a specific application to run those actions against a specific named datastore, without granting the application cluster-admin privileges. Every direct-access query re-checks the allowlist before it runs, and an application cannot allowlist itself.

Allowlist an application (cluster administrator)

Map the application id (<cluster>-<env>-<app>) to the datastore names in Jdbc.DirectAccess.Config. The value is a list, so an application can be allowlisted for more than one datastore:

JavaScript
Jdbc.DirectAccess.Config.inst()
   .setConfigMapValue("allowedDatastoreByAppId", "myCluster-myEnv-myApp", ["MyDatastore"], ConfigOverride.CLUSTER);

To revoke access, remove the entry with removeConfigMapKey("allowedDatastoreByAppId", "myCluster-myEnv-myApp", ConfigOverride.CLUSTER).

Run a direct-access query (allowlisted application)

Obtain a Jdbc.DirectAccess handle from a named datastore connection and run raw SQL:

JavaScript
var directAccess = Jdbc.connectToDatastore("MyDatastore").directAccess();
var rows = directAccess.queryTuples("SELECT ID, NAME FROM MY_TABLE", false);

Obtaining the handle throws an authorization error if the application is not allowlisted for the datastore.

See also

See Connect an Application to an External Database.

Was this page helpful?