Shared security · Burst Load + CDC

Grant the pipeline what it needs. Keep the trust boundary small.

Agents initiate control traffic, resolve Burst Load and CDC secrets locally, and keep row data outside the control plane. Direct-log capture can isolate elevated file or device access in a small broker.

The job to be done

Move committed data with a path your team can explain.

A capability matters when it removes an operational decision, not when it adds another checkbox. SQL Flow connects source-aware capture, durable progress, target apply, and validation so the page you are reading leads to a usable operating path.

Agents resolve database and object-store secrets locally, open the source with the permissions required for the selected tables, and write through the target-native loading path. The control plane coordinates work without receiving plaintext credentials or row payloads. SQL Flow handles local database and object-store secrets; source access scoped to selected data; target-native loading credentials; no row detour through the control plane.

Why this path matters

Keep source and target credentials inside the migration environment.

Agents resolve database and object-store secrets locally, open the source with the permissions required for the selected tables, and write through the target-native loading path. The control plane coordinates work without receiving plaintext credentials or row payloads. SQL Flow handles local database and object-store secrets; source access scoped to selected data; target-native loading credentials; no row detour through the control plane.

What changes for you

Enrollment establishes stable identity, operators approve agents, and revocation persists. HTTPS, scoped keys, rate limits, sanitized faults, and audit protect mutations. SQL Flow handles explicit approval and durable revocation; per-agent credentials and ownership checks; full and read-only API scopes; webhook validation and denied-action audit.

The outcome

Bring hosting, identity, secret store, zones, and log constraints. We will map every credential.

The payoff

See what the capability changes.

Outbound

Agent control traffic

The control plane never dials a database.

Local

Secret resolution

Credentials and relay keys remain on agents.

Read only

Privileged broker

Expose allowlisted bytes without SQL or exec.

Where the work happens

The details that make the result usable.

Read each capability as part of the operating path. The important question is not whether a feature exists, but what work it removes and what evidence it leaves behind.

Burst Load data access

Keep source and target credentials inside the migration environment.

Agents resolve database and object-store secrets locally, open the source with the permissions required for the selected tables, and write through the target-native loading path. The control plane coordinates work without receiving plaintext credentials or row payloads.

SQL Flow handles local database and object-store secrets; source access scoped to selected data; target-native loading credentials; no row detour through the control plane.

  • Local database and object-store secrets
  • Source access scoped to selected data
  • Target-native loading credentials
  • No row detour through the control plane

Agent and control plane

Authenticate control without joining the row path.

Enrollment establishes stable identity, operators approve agents, and revocation persists. HTTPS, scoped keys, rate limits, sanitized faults, and audit protect mutations.

SQL Flow handles explicit approval and durable revocation; per-agent credentials and ownership checks; full and read-only API scopes; webhook validation and denied-action audit.

  • Explicit approval and durable revocation
  • Per-agent credentials and ownership checks
  • Full and read-only API scopes
  • Webhook validation and denied-action audit

Database-side privilege

Separate log access from decode and apply.

For DirectLog, a broker serves allowlisted reads when source files or devices need brokering. Canonical paths, final-handle validation, caps, HMAC, and audit constrain privilege.

SQL Flow handles open, read range, length, and close only; no write, listing, SQL, or command execution; agent-local keys and certificates; TLS for off-host links.

  • Open, read range, length, and close only
  • No write, listing, SQL, or command execution
  • Agent-local keys and certificates
  • TLS for off-host links

Before you choose

Check the path against your environment.

Use the page-specific details below as a short discovery checklist. They are the conditions and work areas that shape the capability, not generic product promises.

  • Local database and object-store secrets
  • Source access scoped to selected data
  • Target-native loading credentials
  • No row detour through the control plane
  • Explicit approval and durable revocation
  • Per-agent credentials and ownership checks

The path to confidence

See the work. Make the call. Prove the result.

The page keeps the product detail close to the decision it supports. Your team can see what the software handles automatically, what it changes for the target, and what the result leaves ready to operate.

  1. Keep source and target credentials inside the migration environment.

    Agents resolve database and object-store secrets locally, open the source with the permissions required for the selected tables, and write through the target-native loading path. The control plane coordinates work without receiving plaintext credentials or row payloads. SQL Flow handles local database and object-store secrets; source access scoped to selected data; target-native loading credentials; no row detour through the control plane.

  2. Authenticate control without joining the row path.

    Enrollment establishes stable identity, operators approve agents, and revocation persists. HTTPS, scoped keys, rate limits, sanitized faults, and audit protect mutations. SQL Flow handles explicit approval and durable revocation; per-agent credentials and ownership checks; full and read-only API scopes; webhook validation and denied-action audit.

  3. Separate log access from decode and apply.

    For DirectLog, a broker serves allowlisted reads when source files or devices need brokering. Canonical paths, final-handle validation, caps, HMAC, and audit constrain privilege. SQL Flow handles open, read range, length, and close only; no write, listing, SQL, or command execution; agent-local keys and certificates; TLS for off-host links.

Keep the plan connected

Take the next useful step.

A capability becomes easier to operate when the next decision follows from the constraint you just uncovered. Explore the related work that completes this part of the path.

Your working set

What this page leaves you with

  • Agent control traffic
  • Secret resolution
  • Keep source and target credentials inside the migration environment.
  • Authenticate control without joining the row path.
  • Review exact privilege before deployment.

Take the next step

Review exact privilege before deployment.

Bring hosting, identity, secret store, zones, and log constraints. We will map every credential.

Talk through my use case