Configuration file format for synq-scout, the Coalesce Quality triage agent run on-premise: your data and the chosen LLM (e.g. an internal LiteLLM proxy, Google Vertex, or AWS Bedrock) stay within your environment, and only the triage resolution — not the underlying data or investigation — is sent back to Coalesce Quality. Defines the agent's data warehouse connections and LLM endpoint.
No Additional PropertiesSYNQConfig holds Coalesce Quality connection settings.
No Additional PropertiesOAuth client ID for authenticating with Coalesce Quality.
OAuth client secret for authenticating with Coalesce Quality.
gRPC endpoint for the Coalesce Quality API (e.g. "developer.synq.io:443").
gRPC endpoint for the Coalesce Quality ingest API. Defaults to Endpoint if empty.
OAuth token URL. Derived from Endpoint if empty.
Each additional property must conform to the following schema
Type: objectConnection is a single database connection entry in a connections map.
No Additional PropertiesDisplay name for this connection. Defaults to the connection ID (map key).
When true, the connection is skipped during execution.
Maximum number of parallel queries. Range: 1-256. Defaults to 8.
Value must be greater or equal to 1 and lesser or equal to 256
PostgresConf contains PostgreSQL connection parameters.
No Additional PropertiesValue must be greater or equal to 1 and lesser or equal to 65535
Disable SSL certificate verification.
SnowflakeConf contains Snowflake connection parameters.
No Additional PropertiesSnowflake account identifier.
Virtual warehouse to use for queries.
Role to assume after connecting.
PEM-encoded private key content for key-pair authentication.
Path to a PEM-encoded private key file.
Passphrase to decrypt the private key.
Databases to include. If empty, all accessible databases are scraped.
No Additional ItemsUse GET_DDL() to retrieve DDL for tables and views.
Database containing the ACCOUNT_USAGE schema. Defaults to SNOWFLAKE.
Set to "externalbrowser" to use SSO browser-based authentication.
BigQueryConf contains BigQuery connection parameters.
No Additional PropertiesGCP project ID.
Region for BigQuery resources.
Inline JSON content of the service account key.
Path to the service account key JSON file.
Explicit list of dataset names to scrape. When set, only these datasets are queried
and project-level bigquery.datasets.list permission is not required.
RedshiftConf contains Amazon Redshift connection parameters.
No Additional PropertiesValue must be greater or equal to 1 and lesser or equal to 65535
Estimate table freshness from Redshift query logs instead of metadata.
MySQLConf contains MySQL connection parameters.
No Additional PropertiesValue must be greater or equal to 1 and lesser or equal to 65535
Disable SSL certificate verification.
Additional DSN parameters passed to the driver.
Each additional property must conform to the following schema
Type: stringClickhouseConf contains ClickHouse connection parameters.
No Additional PropertiesValue must be greater or equal to 1 and lesser or equal to 65535
Name this ClickHouse is published under, and the top element of every path
and breadcrumb its tables appear in — "prod", "staging", "eu-analytics".
ClickHouse has no container above a database, so something has to name the
service itself. Left empty, that is the host above, which is correct but
unreadable for a ClickHouse Cloud endpoint; a name given here replaces it.
Two connections to the same service must give the same name, and the name is
the identity of everything scraped through it: changing it republishes those
tables under new paths, and the old ones stop being produced. Pick one per
service and keep it.
"prod"
"staging"
Database the connection opens with, so an unqualified table name in a query
resolves against it. It does not restrict what is scraped: metadata comes
from system tables and covers every database the user can see, whatever this
says. Empty opens on "default".
Disable SSL certificate verification.
ClickHouse server settings applied to every connection, written as they
would be in a DSN query string (e.g. maxexecutiontime: "300"). Values are
typed the way ClickHouse types them in a connection string: "true" and
"false" become 1 and 0, whole numbers become integers, anything else is
passed through as text. A name given here replaces the value the scrape
would otherwise use.
Each additional property must conform to the following schema
Type: stringHow ClickHouse system tables are read. Omit to keep reading across a
cluster named "default", which every ClickHouse Cloud service provides.
How system tables are read. Optional — defaults to "allreplicas".
- "allreplicas": read through clusterAllReplicas(<name>, ...) so metadata
covers every replica. Requires GRANT REMOTE ON ..
- "singlenode": read on the connected node only. The one setting that
works on an install whose remoteservers defines no cluster, and it
needs no REMOTE grant — but on an install that does have replicas it
reports the metadata of a single node, so choose it deliberately.
"all_replicas"
"single_node"
Cluster to read through, as named under remoteservers in the ClickHouse
configuration. SELECT DISTINCT cluster FROM system.clusters lists what a
server has. Empty means "default". Ignored when mode is "singlenode".
TrinoConf contains Trino / Starburst connection parameters.
No Additional PropertiesValue must be greater or equal to 1 and lesser or equal to 65535
Use a plain HTTP connection instead of HTTPS.
Catalogs to include. Required for most Trino deployments.
No Additional ItemsDatabricksConf contains Databricks connection parameters.
No Additional PropertiesDatabricks workspace URL.
Personal access token for authentication.
OAuth client ID (M2M authentication).
OAuth client secret (M2M authentication).
SQL warehouse ID to use for queries.
MSSQLConf contains Microsoft SQL Server / Azure SQL Database connection parameters.
No Additional PropertiesValue must be greater or equal to 1 and lesser or equal to 65535
Trust the server certificate without validation.
Encryption mode (e.g. "true", "false", "strict").
Federated authentication method (e.g. "ActiveDirectoryDefault").
Pre-acquired access token for Azure AD authentication.
Azure AD application client ID for service principal auth.
OracleConf contains Oracle Database connection parameters.
No Additional PropertiesValue must be greater or equal to 1 and lesser or equal to 65535
Oracle service name.
Enable SSL/TLS for the connection.
Verify the server's SSL certificate.
Path to Oracle Wallet directory for authentication.
Enable Oracle Diagnostics Pack features (AWR, ASH).
DuckDBConf contains DuckDB / MotherDuck connection parameters.
No Additional PropertiesFile path, ':memory:' for in-memory, or MotherDuck database name.
MotherDuck organization/account name (for cloud mode).
MotherDuck authentication token (required for cloud MotherDuck).
AthenaConf contains Amazon Athena connection parameters.
No Additional PropertiesAWS region hosting the Athena service and Glue Data Catalog.
Athena workgroup. Defaults to "primary" when empty. Must have a
ResultConfiguration.OutputLocation configured.
Glue Data Catalog name. Defaults to "AwsDataCatalog" when empty.
Static AWS credentials. Pair accesskeyid with secretaccesskey.
Optional STS session token, when accesskeyid+secretaccesskey are
short-lived STS credentials.
Named AWS shared-config profile (from ~/.aws/credentials or
~/.aws/config). Used only when static credentials are absent.
IAM role ARN to assume via STS. Wraps whichever base credentials
resolved above (or the host's default chain when no other auth is set).
External ID required by the role's trust policy. Pair with role_arn.
Optional STS session name. Defaults to "synq-athena".
Scope filter for include/exclude filtering by Glue catalog, Glue
database, and table. Mapping: ScopeRule.database = Glue catalog,
ScopeRule.schema = Glue database, ScopeRule.table = Glue table/view.
Include rules. If non-empty, only matching objects are accepted.
No Additional ItemsScopeRuleConf is a single include/exclude rule.
No Additional PropertiesDatabase-level pattern (catalog for Athena/Trino/Databricks, project for BigQuery).
Schema-level pattern (Glue database for Athena, dataset for BigQuery).
Table or view name pattern.
Exclude rules. Matching objects are rejected, even if they match an include rule.
No Additional ItemsScopeRuleConf is a single include/exclude rule.
Same definition as connections_additionalProperties_athena_scope_include_itemsUse SHOW CREATE TABLE to retrieve full table DDL (CTAS bodies, Iceberg
TBLPROPERTIES, Hive external LOCATION/SerDe). One Athena query per
table — billed at the 10MB scan minimum each.
Use SHOW CREATE VIEW to retrieve full view DDL instead of the
rewritten body from informationschema.views.viewdefinition.
For Iceberg tables, fan out one Athena query per table to read row
count, total file size, snapshot commit timestamp, and partition
columns from the table's $files / $snapshots / $partitions metadata
tables. Hive externals are unaffected.
FabricConf contains the connection settings for a Microsoft Fabric Warehouse or Lakehouse SQL analytics endpoint.
No Additional PropertiesHostname of the workspace's SQL analytics endpoint. Copy it from the
Fabric portal: open your Warehouse or Lakehouse, then Settings → SQL
connection string.
"my-workspace.datawarehouse.fabric.microsoft.com"
Default database for queries that don't name one explicitly. Optional —
defaults to "master". Because metadata and metric queries are always
fully qualified, this only affects ad-hoc SQL that omits the database.
"my_warehouse"
How to authenticate to Fabric. Optional — defaults to a service principal
(clientid + clientsecret). Values are matched case-insensitively, and
the equivalent dbt-fabric and Microsoft ODBC spellings are also accepted:
- "serviceprincipal" (default): Entra ID service principal. Set
clientid, clientsecret and, if needed, tenantid.
- "azurecli": reuse the machine's az login session. On-prem agent only.
- "default": try Azure's default credential chain (environment, managed
identity, CLI, ...). On-prem agent only.
- "managedidentity": use an Azure managed identity; set client_id to
select a user-assigned identity. On-prem agent only.
"service_principal"
"azure_cli"
"default"
"managed_identity"
Application (client) ID of the Entra ID service principal. When authtype
is "managedidentity", this instead selects a user-assigned identity.
"00000000-0000-0000-0000-000000000000"
Client secret for the service principal. Supply it through an environment
variable (e.g. ${FABRICCLIENTSECRET}) rather than committing it in plain
text.
"${FABRIC_CLIENT_SECRET}"
Entra ID tenant (directory) ID. Optional — inferred from the endpoint
hostname when omitted. Set it only when the service principal lives in a
different tenant than the workspace.
"00000000-0000-0000-0000-000000000000"
A pre-acquired Entra ID OAuth access token for the SQL scope
(https://database.windows.net/.default). Optional — when set it overrides
every other authentication method. Mainly for hosted deployments that mint
their own token.
"${FABRIC_ACCESS_TOKEN}"
Optional include/exclude filter that limits which databases, schemas and
tables are scanned. When omitted, the whole workspace is scanned.
YAMLLLMConfig contains LLM provider settings.
No Additional PropertiesOpenAI-compatible API configuration (also used for LiteLLM proxy).
No Additional PropertiesAPI key for the LLM provider.
Base URL for the API (e.g. LiteLLM proxy URL).
Model used for deep thinking/analysis tasks.
Model used for summarization tasks.
Number of parallel triage operations.
Number of parallel test suggestion operations.