Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This page describes how to set up Lakehouse Federation to run federated queries on Snowflake data that is not managed by Azure Databricks. To learn more about Lakehouse Federation, see What is Lakehouse Federation?
To connect to your Snowflake database using Lakehouse Federation, you must create the following in your Azure Databricks Unity Catalog metastore:
- A connection to your Snowflake database.
- A foreign catalog that mirrors your Snowflake database in Unity Catalog so that you can use Unity Catalog query syntax and data governance tools to manage Azure Databricks user access to the database.
This page covers how to run federated queries on Snowflake data using an OAuth access token. For other authentication methods, see the following pages:
You can run federated queries on Snowflake using query federation or catalog federation.
In query federation, JDBC pushes the Unity Catalog query down to the external database. This is ideal for on-demand reporting or proof-of-concept work on your ETL pipelines.
In catalog federation, the Unity Catalog query runs directly against file storage. This approach is helpful for incremental migration without code adaptation or as a longer-term hybrid model for organizations that must maintain some data in Snowflake alongside their data registered in Unity Catalog. See Enable Snowflake catalog federation.
Before you begin
Workspace requirements:
- Workspace enabled for Unity Catalog.
Compute requirements:
- Network connectivity from your compute resource to the target database systems. See Networking recommendations for Lakehouse Federation.
- Azure Databricks compute must use Databricks Runtime 13.3 LTS or above and Standard or Dedicated access mode.
- SQL warehouses must be pro or serverless and must use 2023.40 or above.
Permissions required:
- To create a connection, you must be a metastore admin or a user with the CREATE CONNECTIONprivilege on the Unity Catalog metastore attached to the workspace.
- To create a foreign catalog, you must have the CREATE CATALOGpermission on the metastore and be either the owner of the connection or have theCREATE FOREIGN CATALOGprivilege on the connection.
Additional permission requirements are specified in each task-based section that follows.
Request an OAuth access token
Follow How To: Generate and use an OAuth token using Snowflake OAuth for custom clients in the Snowflake Knowledge Base.
Create a connection
A connection specifies a path and credentials for accessing an external database system. To create a connection, you can use Catalog Explorer or the CREATE CONNECTION SQL command in an Azure Databricks notebook or the Databricks SQL query editor.
Note
You can also use the Databricks REST API or the Databricks CLI to create a connection. See POST /api/2.1/unity-catalog/connections and Unity Catalog commands.
Permissions required: Metastore admin or user with the CREATE CONNECTION privilege.
- In your Azure Databricks workspace, click - Catalog. 
- At the top of the Catalog pane, click the  Add icon and select Create a connection from the menu. Add icon and select Create a connection from the menu.- Alternatively, from the Quick access page, click the External Data > External Locations button, go to the Connections tab, and click Create connection. 
- On the Connection basics page of the Set up connection wizard, enter a user-friendly Connection name. 
- For Connection type, select Snowflake. 
- For Auth type, select - OAuth Access Tokenfrom the drop-down menu.
- (Optional) Add a comment. 
- Click Next. 
- Enter the following authentication and connection details on the Authentication page. - Host: For example, snowflake-demo.east-us-2.azure.snowflakecomputing.com.
- Port: The default value is 443.
- User: Use your personal Snowflake username.
- Access token: Access token from Request an OAuth access token.
- (Optional) Expires in secs: The expiration time (in seconds) for the access token from Request an OAuth access token (expires_in).
 
- Host: For example, 
- Click Next. 
- On the Connection details page, enter the name of your Snowflake warehouse. 
- If you want to use proxy for connecting to Snowflake, check the Use proxy box and fill in the required details. 
- Click Create connection. 
- On the Catalog basics page, enter a name for the foreign catalog. 
- For Database, enter a database name in Snowflake. A foreign catalog mirrors a database in an external data system so that you can query and manage access to data in that database using Azure Databricks and Unity Catalog. 
- (Optional) Click Test connection to confirm that it works. 
- Click Create catalog. 
- On the Access page, select the workspaces in which users can access the catalog you created. You can select All workspaces have access, or click Assign to workspaces, select the workspaces, and then click Assign. 
- Change the Owner who will be able to manage access to all objects in the catalog. Start typing a principal in the text box, and then click the principal in the returned results. 
- Grant Privileges on the catalog. Click Grant: - Specify the Principals who will have access to objects in the catalog. Start typing a principal in the text box, and then click the principal in the returned results.
- Select the Privilege presets to grant to each principal. All account users are granted BROWSEby default.- Select Data Reader from the drop-down menu to grant readprivileges on objects in the catalog.
- Select Data Editor from the drop-down menu to grant readandmodifyprivileges on objects in the catalog.
- Manually select the privileges to grant.
 
- Select Data Reader from the drop-down menu to grant 
- Click Grant.
 
- Click Next. 
- On the Metadata page, specify tags key-value pairs. For more information, see Apply tags to Unity Catalog securable objects. 
- (Optional) Add a comment. 
- Click Save. 
Case-sensitive database identifiers
The database field of the foreign catalog maps to a Snowflake database identifier. If the Snowflake database identifier is not case-sensitive, the casing you use in the foreign catalog <database-name> is preserved. However, if the Snowflake database identifier is case-sensitive, you must wrap the foreign catalog <database-name> in double quotes to preserve the case.
For example:
- databaseis converted to- DATABASE
- "database"is converted to- database
- "database"""is converted to- database"- To escape a double quote, use another double quote. 
- "database""results in an error because the double quote is not escaped correctly.
For more information, see Identifier requirements in the Snowflake documentation.
Supported pushdowns
The following pushdowns are supported:
- Filters
- Projections
- Limit
- Joins
- Aggregates (Average, Corr, CovPopulation, CovSample, Count, Max, Min, StddevPop, StddevSamp, Sum, VariancePop, VarianceSamp)
- Functions (String functions, Mathematical functions, Data, Time and Timestamp functions, and other miscellaneous functions, such as Alias, Cast, SortOrder)
- Windows functions (DenseRank, Rank, RowNumber)
- Sorting
Data type mappings
When you read from Snowflake to Spark, data types map as follows:
| Snowflake type | Spark type | 
|---|---|
| decimal, number, numeric | DecimalType | 
| bigint, byteint, int, integer, smallint, tinyint | IntegerType | 
| float, float4, float8 | FloatType | 
| double, double precision, real | DoubleType | 
| char, character, string, text, time, varchar | StringType | 
| binary | BinaryType | 
| boolean | BooleanType | 
| date | DateType | 
| datetime, timestamp, timestamp_ltz, timestamp_ntz, timestamp_tz | TimestampType | 
Limitations
- The Snowflake OAuth endpoint must be accessible from Databricks control plane IPs. See Outbound IPs from Azure Databricks control plane. Snowflake supports configuring network policies at the security integration level, which allows for a separate network policy that enables direct connectivity from the Databricks control plane to the OAuth endpoint for authorization.
- Use Proxy, Proxy host, Proxy port, and Snowflake role configuration options are not supported. Specify Snowflake role as part of the OAuth scope.
Additional resources
See the following articles in the Snowflake documentation: