Use the following steps to securely connect your Galaxy cluster to your AWS RDS instances using AWS PrivateLink. These steps also apply to the same databases deployed on an AWS EC2 instance.
You must work with a Starburst technical resource to complete your PrivateLink configuration. Contact your account team for more information.
You must configure a separate AWS PrivateLink connection for each catalog you want to connect to Starburst Galaxy.
Configure the following resources in the AWS console:
Go to the VPC console.
Navigate to PrivateLink and Lattice > Resource gateways.
Create a new resource gateway for the VPC where your RDS instance resides. For assistance, see the AWS documentation.
Go to the VPC console.
Navigate to PrivateLink and Lattice > Resource configurations.
Create a new resource configuration. In the Configuration type section, select Resource group.
In the Resource gateway section, select the resource gateway you created in the previous step.
Copy the ARN of your resource configuration for later use.
Go to the Resource Access Manager console.
Create a new resource share for your group resource configuration.
Grant access to the Starburst principal ARN: 179619298502.
For each data source you want to connect to Galaxy, complete the following steps:
Return to your group resource configuration.
Create a new resource configuration.
In the Configuration type section, select Resource.
In the Type drop-down menu, select Child.
Specify either the DNS name or IP address of your data source.
Configure the appropriate port range.
Submit a support ticket through Galaxy:
Click the support icon in Galaxy.
Select Chat with technical support.
Select Submit a Support Ticket.
Include the ARN of your group resource configuration in the request.
Starburst Support aims to confirm the creation of a resource endpoint within 24-48 hours. You can then manage child resource configurations in your AWS account. Galaxy automatically reflects any changes.
Is the information on this page helpful?
Yes
No