Skip to main content

Connection Profiles

Connection Profiles store the credentials and endpoint for one external platform, so source and sink nodes authenticate without credentials being entered on each node.

Overview​

A connection profile answers how Fleak authenticates against an external platform, and where that platform lives — a broker address, a workspace host, a region. It does not name the individual topic, queue, table, or folder you read from or write to. That is a Data Asset.

Together the three layers divide as follows:

LayerAnswersExample
Connection ProfileWhich platform, and what credentialsAn AWS access key pair plus us-east-1
Data AssetWhich location on that platformThe queue https://sqs.us-east-1.amazonaws.com/123456789012/orders
NodeHow the workflow reads or writes itBatch size, flush interval, encoding

One profile backs many assets, and one asset backs many workflows. Rotating a credential is a single edit on the profile rather than a change to every node that uses it.

note

Connection profiles replace what earlier versions of Fleak called Integrations. The settings page is now Settings → Connection Profiles.

Managing Connection Profiles​

Accessing Connection Profiles​

Click your username in the top left of the Fleak dashboard, select Settings, then Connection Profiles in the settings sidebar.

Creating a Connection Profile​

Click Create Connection Profile, choose the platform, then fill in the fields for that platform. Each platform's fields are listed in Supported Platforms below. Every profile also takes a name, which is what you select by when configuring a data asset or a node.

You can also create a profile without leaving the workflow builder, while configuring a node or a data asset. Most platforms support both routes. XSIAM profiles are the exception: they can only be created here on the settings page.

Ownership and Sharing​

A profile has a single owner, the person who created it. Sharing it with your organization makes it selectable by other members; leaving it unshared keeps it private to you.

Secrets are masked server-side for anyone who is not the owner. A non-owner sees a profile's secret fields as •••••••• and cannot read the stored value back, whether through the UI or the API. Non-secret configuration — a region, a host URL, a Datadog site — stays visible, so a shared profile is still usable and auditable without exposing the credential.

Editing and Re-deploying​

Saving an edit to a profile does not change running deployments. Fleak warns you on save:

Changes won't apply until you re-deploy. Saving updates this connection profile, but running deployments keep using the previous settings until you re-deploy them.

Re-deploy each affected workflow for a credential rotation or endpoint change to take effect.

Deleting​

A profile that data assets or workflows still reference cannot be deleted until those references are removed.

Supported Platforms​

The platforms below back the connectors that are generally available. Fleak's settings page lists further platforms that are in preview or marked coming soon; those are not documented here.

PlatformUsed by
AWS S3S3 Sink
AWS SQSSQS Sink, SQS Source, S3 Event Notifications Source
Apache KafkaKafka Sink, Kafka Source
DatabricksDatabricks Sink
Databricks ZerobusDatabricks Zerobus Sink
DatadogDatadog Logs Sink
XSIAMXSIAM Sink
API KeySplunk HEC Sink, XSIAM Sink

AWS S3​

FieldDescriptionRequired
RegionThe AWS region of the bucket, e.g. us-east-1.Yes
AWS Access Key IDThe access key ID of the IAM user Fleak authenticates as.Yes
AWS Secret Access KeyThe matching secret access key. Stored encrypted and masked from non-owners.Yes

Required IAM permissions:

  • Profile validation uses AWS STS and needs no S3 permission at all.
  • s3:ListBucket on the bucket ARN — required by S3 Folder source nodes to list objects.
  • s3:GetObject on the object or prefix ARN — required by S3 Folder source nodes to read objects.
  • s3:PutObject on the destination object or prefix ARN — required by S3 Folder sink nodes.
  • s3:AbortMultipartUpload on the destination ARN — used by the default batch/multipart sink only to clean up a failed upload so incomplete parts do not remain billable. This is not s3:DeleteObject.
  • s3:ListAllMyBuckets on * — optional, used only for automatic bucket discovery. You can type a bucket name manually if this is denied.
  • For buckets or objects with default SSE-KMS encryption, grant kms:Decrypt for reads, kms:GenerateDataKey for writes, and both for multipart writes, on the KMS key ARN. Fleak has no KMS field in this form.

AWS SQS​

FieldDescriptionRequired
RegionThe AWS region of the queue, e.g. us-west-2.Yes
AWS Access Key IDThe access key ID of the IAM user Fleak authenticates as.Yes
AWS Secret Access KeyThe matching secret access key.Yes

Apache Kafka​

FieldDescriptionRequired
Broker/Bootstrap AddressComma-separated bootstrap servers, e.g. broker1:9092,broker2:9092.Yes
Authentication TypePLAINTEXT, SSL, SASL_PLAINTEXT, or SASL_SSL. Defaults to SASL_SSL.Yes
SASL MechanismPLAIN, SCRAM-SHA-256, or SCRAM-SHA-512. Shown only for the SASL protocols. Defaults to PLAIN.Yes, for SASL
UsernameSASL username.No
PasswordSASL password.No
Additional Connection PropertiesFree-form Kafka client properties for anything the fields above do not cover, e.g. ssl.* or client.id. Found under Show advanced options.No

The authentication type and SASL mechanism are written into the profile's Kafka client properties on save. Because the profile owns the security configuration, a node whose connection comes from a profile cannot override security.protocol, sasl.mechanism, sasl.jaas.config, or the SSL password properties on itself.

Databricks​

FieldDescriptionRequired
Host URLYour workspace URL, e.g. https://dbc-xxxx.cloud.databricks.com.Yes
Client IDThe service principal's application ID.Yes
Client SecretThe service principal's OAuth secret.Yes

Use OAuth M2M (machine-to-machine) credentials from a Databricks service principal, not a personal access token. M2M tokens refresh automatically, which is what keeps a 24/7 pipeline authenticated.

Databricks Zerobus​

FieldDescriptionRequired
Host URLYour workspace URL, e.g. https://dbc-xxxx.cloud.databricks.com.Yes
Ingest EndpointThe Zerobus ingest endpoint, e.g. https://<workspace_id>.zerobus.<region>.cloud.databricks.com.Yes
Client IDThe service principal's application ID.Yes
Client SecretThe service principal's OAuth secret.Yes

Zerobus is a separate profile type from Databricks: it carries its own ingest endpoint and is used only by the Databricks Zerobus Sink.

Datadog​

FieldDescriptionRequired
SiteYour Datadog region domain — the host in your Datadog URL, e.g. us3.datadoghq.com. Enter the domain only, without https:// or a path. US1 accounts use datadoghq.com.Yes
API KeyA Datadog API key from Organization Settings → API Keys. This is the API key, not an Application key.Yes

The site determines the intake endpoint, so it decides both where and how logs are delivered.

XSIAM​

FieldDescriptionRequired
API KeyThe XSIAM API key, sent as the Authorization header.Yes

API Key​

A bare credential with no endpoint of its own — the data asset carries the endpoint. Used for the Splunk HEC token and as the inline option when creating an XSIAM dataset.

FieldDescriptionRequired
API KeyThe token value, sent verbatim.Yes
note

API Key profiles are created inline, while configuring a node or data asset. They are not listed as standalone profiles on the Connection Profiles settings page.