PageSourceSearch

https://docs.starlake.ai/assets/js/e533fc66.2fef143b.js

js starlake.ai collected 2026-10-03 23:13:01 UTC 30,134 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkstarlake=self.webpackChunkstarlake||[]).push([[5774],{28363:e=>{e.exports=JSON.parse('{"version":{"pluginId":"qod","version":"current","label":"Next","banner":null,"badge":false,"noIndex":false,"className":"docs-version-current","isLast":true,"docsSidebars":{"docs":[{"type":"link","href":"/qod/introduction","label":"Introduction","docId":"introduction","unlisted":false},{"type":"category","label":"Getting Started","items":[{"type":"link","href":"/qod/getting-started/quickstart","label":"Quickstart","docId":"getting-started/quickstart","unlisted":false},{"type":"link","href":"/qod/getting-started/install","label":"Installation","docId":"getting-started/install","unlisted":false},{"type":"link","href":"/qod/getting-started/demo","label":"Demo bootstrap (LOAD_TPCH / LOAD_TPCDS)","docId":"getting-started/demo","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"category","label":"DuckDB how-tos","items":[{"type":"link","href":"/qod/duckdb/access-control","label":"Access control","docId":"duckdb/access-control","unlisted":false},{"type":"link","href":"/qod/duckdb/authentication","label":"Authentication","docId":"duckdb/authentication","unlisted":false},{"type":"link","href":"/qod/duckdb/sso","label":"Single sign-on","docId":"duckdb/sso","unlisted":false},{"type":"link","href":"/qod/duckdb/adbc","label":"ADBC","docId":"duckdb/adbc","unlisted":false},{"type":"link","href":"/qod/duckdb/flight-sql-server","label":"Flight SQL server","docId":"duckdb/flight-sql-server","unlisted":false},{"type":"link","href":"/qod/duckdb/multi-tenant","label":"Multi-tenant","docId":"duckdb/multi-tenant","unlisted":false}],"collapsed":true,"collapsible":true,"href":"/qod/duckdb"},{"type":"category","label":"Concepts","items":[{"type":"link","href":"/qod/concepts/architecture","label":"Architecture","docId":"concepts/architecture","unlisted":false},{"type":"link","href":"/qod/concepts/tenancy","label":"Tenancy model","docId":"concepts/tenancy","unlisted":false},{"type":"link","href":"/qod/concepts/routing","label":"Routing and statement classification","docId":"concepts/routing","unlisted":false},{"type":"link","href":"/qod/concepts/sessions-transactions","label":"Sessions and transactions","docId":"concepts/sessions-transactions","unlisted":false},{"type":"link","href":"/qod/concepts/catalogs","label":"Catalogs","docId":"concepts/catalogs","unlisted":false},{"type":"link","href":"/qod/concepts/state-storage","label":"State storage","docId":"concepts/state-storage","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"category","label":"Administration","items":[{"type":"link","href":"/qod/administration/","label":"Administration","docId":"administration/index","unlisted":false},{"type":"link","href":"/qod/administration/onboarding","label":"Onboard a tenant","docId":"administration/onboarding","unlisted":false},{"type":"link","href":"/qod/administration/access-control","label":"Grant and revoke access","docId":"administration/access-control","unlisted":false},{"type":"link","href":"/qod/administration/sql-administration","label":"Administer with SQL","docId":"administration/sql-administration","unlisted":false},{"type":"link","href":"/qod/administration/day-2-operations","label":"Run the platform","docId":"administration/day-2-operations","unlisted":false},{"type":"link","href":"/qod/administration/audit-log","label":"Audit log","docId":"administration/audit-log","unlisted":false},{"type":"link","href":"/qod/administration/usage-accounting","label":"Usage and accounting","docId":"administration/usage-accounting","unlisted":false},{"type":"link","href":"/qod/administration/lifecycle-config","label":"Lifecycle and config","docId":"administration/lifecycle-config","unlisted":false},{"type":"link","href":"/qod/administration/manage-by-manifest","label":"Manage by manifest","docId":"administration/manage-by-manifest","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"category","label":"Operating","items":[{"type":"category","label":"Deployment","items":[{"type":"link","href":"/qod/operating/deploy-local","label":"Local deployment","docId":"operating/deploy-local","unlisted":false},{"type":"link","href":"/qod/operating/deploy-single-server","label":"Single-server production deployment","docId":"operating/deploy-single-server","unlisted":false},{"type":"link","href":"/qod/operating/deploy-docker","label":"Docker deployment","docId":"operating/deploy-docker","unlisted":false},{"type":"link","href":"/qod/operating/deploy-fleet","label":"Fleet (bare servers)","docId":"operating/deploy-fleet","unlisted":false},{"type":"link","href":"/qod/operating/deploy-kubernetes","label":"Kubernetes deployment","docId":"operating/deploy-kubernetes","unlisted":false},{"type":"link","href":"/qod/operating/tls","label":"TLS","docId":"operating/tls","unlisted":false},{"type":"link","href":"/qod/operating/encryption","label":"Encryption at rest","docId":"operating/encryption","unlisted":false},{"type":"link","href":"/qod/operating/hardening","label":"Security hardening","docId":"operating/hardening","unlisted":false},{"type":"link","href":"/qod/operating/resilience","label":"Resilience and recovery","docId":"operating/resilience","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"category","label":"Provisioning","items":[{"type":"link","href":"/qod/operating/tenants-databases","label":"Tenants and databases","docId":"operating/tenants-databases","unlisted":false},{"type":"link","href":"/qod/operating/managed-storage","label":"Managed object storage","docId":"operating/managed-storage","unlisted":false},{"type":"link","href":"/qod/operating/pools-cohorts","label":"Pools and cohorts","docId":"operating/pools-cohorts","unlisted":false},{"type":"link","href":"/qod/operating/autoscaling","label":"Autoscaling pools","docId":"operating/autoscaling","unlisted":false},{"type":"link","href":"/qod/operating/federation","label":"Federation","docId":"operating/federation","unlisted":false},{"type":"link","href":"/qod/operating/iceberg","label":"External Iceberg catalogs","docId":"operating/iceberg","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"category","label":"Identity & access","items":[{"type":"link","href":"/qod/operating/authentication","label":"Authentication","docId":"operating/authentication","unlisted":false},{"type":"link","href":"/qod/operating/auth-providers","label":"Authentication providers","docId":"operating/auth-providers","unlisted":false},{"type":"link","href":"/qod/operating/oauth-server-setup","label":"OAuth / OIDC server setup (per provider)","docId":"operating/oauth-server-setup","unlisted":false},{"type":"link","href":"/qod/operating/rbac-model","label":"Access control model","docId":"operating/rbac-model","unlisted":false},{"type":"link","href":"/qod/operating/rbac-admin","label":"Administering access","docId":"operating/rbac-admin","unlisted":false},{"type":"link","href":"/qod/operating/scim-provisioning","label":"SCIM provisioning","docId":"operating/scim-provisioning","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"link","href":"/qod/operating/observability","label":"Observability","docId":"operating/observability","unlisted":false},{"type":"link","href":"/qod/operating/history-trends","label":"Statement history and trends","docId":"operating/history-trends","unlisted":false},{"type":"link","href":"/qod/operating/maintenance","label":"Managed DuckLake maintenance","docId":"operating/maintenance","unlisted":false},{"type":"link","href":"/qod/operating/branching","label":"Branching (agents propose, humans merge)","docId":"operating/branching","unlisted":false},{"type":"link","href":"/qod/operating/manifest","label":"Manifest backup and restore","docId":"operating/manifest","unlisted":false},{"type":"link","href":"/qod/operating/admin-ui","label":"Admin UI guide","docId":"operating/admin-ui","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"category","label":"Connecting","items":[{"type":"link","href":"/qod/connecting/clients","label":"Connecting clients","docId":"connecting/clients","unlisted":false},{"type":"link","href":"/qod/connecting/duckdb","label":"DuckDB (native Quack)","docId":"connecting/duckdb","unlisted":false},{"type":"link","href":"/qod/connecting/authenticating","label":"Authenticating","docId":"connecting/authenticating","unlisted":false},{"type":"link","href":"/qod/connecting/sql","label":"Supported SQL","docId":"connecting/sql","unlisted":false},{"type":"link","href":"/qod/connecting/mcp","label":"MCP server (AI agents)","docId":"connecting/mcp","unlisted":false},{"type":"link","href":"/qod/connecting/agent-skill","label":"Operator skill (AI agents)","docId":"connecting/agent-skill","unlisted":false},{"type":"link","href":"/qod/connecting/dbeaver","label":"DBeaver","docId":"connecting/dbeaver","unlisted":false},{"type":"link","href":"/qod/connecting/powerbi","label":"Power BI","docId":"connecting/powerbi","unlisted":false},{"type":"link","href":"/qod/connecting/tableau","label":"Tableau","docId":"connecting/tableau","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"category","label":"CLI","items":[{"type":"link","href":"/qod/cli/","label":"The qod CLI","docId":"cli/index","unlisted":false},{"type":"link","href":"/qod/cli/admin","label":"Administering with the CLI","docId":"cli/admin","unlisted":false},{"type":"link","href":"/qod/cli/sql","label":"Running SQL","docId":"cli/sql","unlisted":false},{"type":"link","href":"/qod/cli/reference","label":"Command reference","docId":"cli/reference","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"category","label":"Reference","items":[{"type":"link","href":"/qod/reference/configuration","label":"Configuration","docId":"reference/configuration","unlisted":false},{"type":"link","label":"REST API","href":"pathname:///api/"},{"type":"link","href":"/qod/reference/cli","label":"Manager jar","docId":"reference/cli","unlisted":false},{"type":"link","href":"/qod/reference/metrics","label":"Metrics","docId":"reference/metrics","unlisted":false}],"collapsed":true,"collapsible":true},{"type":"category","label":"Contributing","items":[{"type":"link","href":"/qod/contributing/dev-loop","label":"Development loop","docId":"contributing/dev-loop","unlisted":false},{"type":"link","href":"/qod/contributing/architecture-map","label":"Architecture map","docId":"contributing/architecture-map","unlisted":false},{"type":"link","href":"/qod/contributing/extending","label":"Extending the manager","docId":"contributing/extending","unlisted":false}],"collapsed":true,"collapsible":true}]},"docs":{"administration/access-control":{"id":"administration/access-control","title":"Grant and revoke access to DuckDB tables","de
1scription":"Grant a team read access to DuckDB tables, add row filters and column masks, and revoke access, from the admin UI, the qod CLI, or plain SQL.","sidebar":"docs"},"administration/audit-log":{"id":"administration/audit-log","title":"Audit log","description":"How Quack on Demand records a tenant-scoped audit trail of admin actions, auth events, denials and data-plane writes on DuckDB.","sidebar":"docs"},"administration/day-2-operations":{"id":"administration/day-2-operations","title":"Run the platform","description":"Operational playbooks for a running DuckDB fleet: watch the Nodes board, scale pools, drain before maintenance, inspect recent statements.","sidebar":"docs"},"administration/index":{"id":"administration/index","title":"Administration","description":"Superuser and tenant admin roles in Quack on Demand, and where each administrative task on your DuckDB gateway lives in the UI and CLI.","sidebar":"docs"},"administration/lifecycle-config":{"id":"administration/lifecycle-config","title":"Lifecycle and config","description":"Attach external catalogs, rotate secrets, back up and restore configuration, and decommission a DuckDB gateway cleanly, step by step.","sidebar":"docs"},"administration/manage-by-manifest":{"id":"administration/manage-by-manifest","title":"Manage by manifest","description":"Manage every tenant, pool, role, user and grant of your DuckDB gateway as one version-controlled YAML manifest: export, edit, re-import.","sidebar":"docs"},"administration/onboarding":{"id":"administration/onboarding","title":"Onboard a tenant","description":"Golden path for onboarding a tenant: sign in, create the database and pool, add users, hand a BI user a DuckDB connection string.","sidebar":"docs"},"administration/sql-administration":{"id":"administration/sql-administration","title":"Administer DuckDB access with SQL: roles, grants, row and column policies","description":"Manage users, roles, grants, row policies and column masks on DuckDB with plain SQL from any client: CREATE ROLE, GRANT, CREATE ROW POLICY.","sidebar":"docs"},"administration/usage-accounting":{"id":"administration/usage-accounting","title":"Usage and accounting","description":"Per-tenant, per-pool and per-user metering of DuckDB statements, a durable ledger for chargeback, billing exports and capacity planning.","sidebar":"docs"},"cli/admin":{"id":"cli/admin","title":"Administering with the CLI","description":"Provision a tenant end to end with the qod CLI: login, database, pool, users, roles, grants, and a query under row-level security on DuckDB.","sidebar":"docs"},"cli/index":{"id":"cli/index","title":"The qod CLI","description":"The qod command-line client for Quack on Demand: boot a DuckDB gateway, administer tenants and access control, and run Flight SQL queries.","sidebar":"docs"},"cli/reference":{"id":"cli/reference","title":"Command reference","description":"Every qod CLI command by noun and verb, with flags, profiles and JSON output for scripting a DuckDB gateway from CI or a shell.","sidebar":"docs"},"cli/sql":{"id":"cli/sql","title":"Running SQL","description":"Run one-shot or interactive SQL against a DuckDB gateway with qod sql, the Arrow Flight SQL client built into the command-line tool.","sidebar":"docs"},"concepts/architecture":{"id":"concepts/architecture","title":"Architecture of a multi-tenant DuckDB gateway","description":"How Quack on Demand puts an authenticated, access-controlled, horizontally scaled SQL surface in front of DuckDB: planes, object model, request flow.","sidebar":"docs"},"concepts/catalogs":{"id":"concepts/catalogs","title":"Catalogs","description":"The three database kinds behind a Quack on Demand database, how a DuckLake catalog separates metadata from Parquet data, and how external catalogs such as Iceberg attach alongside it.","sidebar":"docs"},"concepts/routing":{"id":"concepts/routing","title":"Routing and statement classification","description":"How each statement on the Flight SQL edge is classified read or write and routed to the least-loaded DuckDB node, with cache-aware placement.","sidebar":"docs"},"concepts/sessions-transactions":{"id":"concepts/sessions-transactions","title":"Sessions and transactions","description":"The session model of the DuckDB gateway: how transactions pin to a node, when a pin is invali
1dated, and how prepared statements behave.","sidebar":"docs"},"concepts/state-storage":{"id":"concepts/state-storage","title":"State storage","description":"Where Quack on Demand keeps control-plane state (tenants, pools, RBAC graph) in Postgres, separate from tenant data in DuckLake catalogs.","sidebar":"docs"},"concepts/tenancy":{"id":"concepts/tenancy","title":"Multi-tenant DuckDB: the tenancy model","description":"How Quack on Demand isolates tenants on shared DuckDB infrastructure: tenants, databases and pools, and what enforces the boundary between them.","sidebar":"docs"},"connecting/agent-skill":{"id":"connecting/agent-skill","title":"Operator skill (AI agents)","description":"Install the Quack on Demand agent skill so Claude Code, Copilot or Gemini CLI can operate your DuckDB gateway through the qod CLI.","sidebar":"docs"},"connecting/authenticating":{"id":"connecting/authenticating","title":"Authenticating a client to DuckDB over Flight SQL","description":"How a Flight SQL client authenticates to the DuckDB gateway: password or bearer token, how the tenant is resolved, and the TLS settings to use.","sidebar":"docs"},"connecting/clients":{"id":"connecting/clients","title":"Connecting clients to DuckDB: JDBC, ADBC, ODBC and native ATTACH","description":"Connect JDBC, ADBC, ODBC, Python and DuckDB itself to a governed DuckDB gateway: connection targets, credentials and per-client recipes.","sidebar":"docs"},"connecting/dbeaver":{"id":"connecting/dbeaver","title":"DBeaver to DuckDB over Flight SQL JDBC","description":"Connect DBeaver to a shared DuckDB through the Arrow Flight SQL JDBC driver: register the driver, build the URL, pass an OAuth token.","sidebar":"docs"},"connecting/duckdb":{"id":"connecting/duckdb","title":"DuckDB (native Quack protocol)","description":"ATTACH a governed DuckDB gateway from any DuckDB client with the quack extension, no driver required, and join remote tables with local ones.","sidebar":"docs"},"connecting/mcp":{"id":"connecting/mcp","title":"MCP server: AI agents querying DuckDB under RBAC","de
1scription":"Let Claude Code, Claude Desktop or Cursor query DuckDB through the embedded MCP server, with the same RBAC, row and column policies as any SQL client.","sidebar":"docs"},"connecting/powerbi":{"id":"connecting/powerbi","title":"Power BI to DuckDB with the ADBC connector","description":"Connect Power BI and Microsoft Fabric to DuckDB with the QoD connector on the in-box Flight SQL ADBC driver: Import, DirectQuery and query folding.","sidebar":"docs"},"connecting/sql":{"id":"connecting/sql","title":"Supported SQL: the DuckDB dialect through the gateway","description":"What SQL you can run through the DuckDB gateway: the DuckDB dialect, default schema rules, transactions, prepared statements and ACL rewrites.","sidebar":"docs"},"connecting/tableau":{"id":"connecting/tableau","title":"Tableau to DuckDB over Flight SQL JDBC","description":"Connect Tableau Desktop to a shared DuckDB through the generic JDBC connector and the Arrow Flight SQL JDBC driver, with no custom connector.","sidebar":"docs"},"contributing/architecture-map":{"id":"contributing/architecture-map","title":"Architecture map","description":"Codebase orientation for contributors to Quack on Demand: process model, request flow, and where each concern lives in the source tree.","sidebar":"docs"},"contributing/dev-loop":{"id":"contributing/dev-loop","title":"Development loop","description":"Day-to-day developer workflow for Quack on Demand: build, test, run locally and regenerate the documentation from the source tree.","sidebar":"docs"},"contributing/extending":{"id":"contributing/extending","title":"Extending the manager","description":"Extend Quack on Demand with a new runtime backend or a new authentication provider through the two seams designed for it.","sidebar":"docs"},"duckdb/access-control":{"id":"duckdb/access-control","title":"DuckDB access control: roles, grants, row and column security","description":"Add users, roles, grants, row-level security and column masking to DuckDB. Quack on Demand checks every statement against an ACL before it runs.","sidebar":"docs"},"duckdb/adbc":{"id":"duckdb/adbc","title":"Connect to DuckDB with ADBC from Python, Go and Power BI","description":"Query a shared DuckDB with ADBC over Arrow Flight SQL. Quack on Demand serves the standard Flight SQL ADBC driver for Python, Go and Power BI.","sidebar":"docs"},"duckdb/authentication":{"id":"duckdb/authentication","title":"DuckDB authentication: passwords, tokens and OAuth for SQL clients","description":"Give DuckDB a login. Quack on Demand authenticates every JDBC, ADBC, ODBC or native DuckDB connection with passwords, JWT bearer tokens or OAuth.","sidebar":"docs"},"duckdb/flight-sql-server":{"id":"duckdb/flight-sql-server","title":"A Flight SQL server for DuckDB: JDBC, ODBC and ADBC","description":"DuckDB has no server. Quack on Demand is an Arrow Flight SQL server for DuckDB and DuckLake, so DBeaver, Tableau and Power BI connect over JDBC, ODBC or ADBC.","sidebar":"docs"},"duckdb/index":{"id":"duckdb/index","title":"DuckDB as a service: what Quack on Demand adds","description":"DuckDB is an embedded engine with no users, no server and no grants. Quack on Demand adds authentication, SSO, access control, ADBC and Flight SQL.","sidebar":"docs"},"duckdb/multi-tenant":{"id":"duckdb/multi-tenant","title":"Multi-tenant DuckDB and DuckLake: tenants, databases and pools","description":"Run many teams or customers on one DuckDB deployment. Quack on Demand isolates tenants, databases (each its own DuckLake catalog) and pools of DuckDB nodes.","sidebar":"docs"},"duckdb/sso":{"id":"duckdb/sso","title":"DuckDB single sign-on with Keycloak, Google, Azure AD and Okta","description":"Single sign-on for DuckDB: Keycloak, Google, Azure AD or Cognito tokens for SQL clients, any OIDC IdP including Okta for the admin UI, plus SCIM sync.","sidebar":"docs"},"getting-started/demo":{"id":"getting-started/demo","title":"Demo bootstrap (LOAD_TPCH / LOAD_TPCDS)","description":"Turn a fresh install into a multi-tenant DuckDB demo with TPC-H, TPC-DS or SSB data, a full RBAC graph and a federated catalog in one command.","sidebar":"docs"},"getting-started/install":{"id":"getting-started/install","title":"Installation","description":"Install Quack on Demand as a Docker image or a single jar driven by the qod CLI, from uvx demo mode to a durable DuckDB gateway.","sidebar":"docs"},"getting-started/quickstart":{"id":"getting-started/quickstart","title":"Quickstart: a governed DuckDB gateway in one command","de
1scription":"Boot a multi-tenant DuckDB gateway, connect a client over Flight SQL or native ATTACH, and run your first query on TPC-H data.","sidebar":"docs"},"introduction":{"id":"introduction","title":"Quack on Demand: multi-tenant SQL gateway for DuckDB and DuckLake","description":"Quack on Demand puts an authenticated, access-controlled, autoscaled SQL endpoint in front of DuckDB and DuckLake, over Flight SQL or native ATTACH.","sidebar":"docs"},"operating/admin-ui":{"id":"operating/admin-ui","title":"Admin UI guide","description":"Tour of the Quack on Demand admin console: tenants, databases, pools, users, access control, and live node and statement telemetry.","sidebar":"docs"},"operating/auth-providers":{"id":"operating/auth-providers","title":"DuckDB authentication providers: Keycloak, Google, Azure AD, Cognito","description":"Enable and configure each authentication provider for DuckDB clients: built-in passwords, external JWT, Keycloak, Google, Azure AD, Cognito, UI SSO.","sidebar":"docs"},"operating/authentication":{"id":"operating/authentication","title":"Authentication: how DuckDB clients prove who they are","description":"How the Flight SQL edge authenticates every DuckDB client: the provider chain, credentials, roles and groups from tokens, and session caching.","sidebar":"docs"},"operating/autoscaling":{"id":"operating/autoscaling","title":"Autoscaling pools","description":"Declare an autoscale band and let the manager add and remove DuckDB read nodes with load, without anyone scaling the pool by hand.","sidebar":"docs"},"operating/branching":{"id":"operating/branching","title":"Branching (agents propose, humans merge)","description":"Zero-copy branches of a DuckLake database: agents and pipelines write on a branch, humans review the row-level diff and merge into main.","sidebar":"docs"},"operating/deploy-docker":{"id":"operating/deploy-docker","title":"Docker deployment","description":"Run the whole DuckDB gateway as a Docker Compose stack: manager, Postgres metastore and DuckDB nodes in one container on one host.","sidebar":"docs"},"operating/deploy-fleet":{"id":"operating/deploy-fleet","title":"Fleet deployment: nodes on your own servers, no Kubernetes","description":"Run DuckDB nodes across many Linux or macOS servers without Kubernetes: servers join with qod fleet join, the manager schedules one node per server from a shared fleet.","sidebar":"docs"},"operating/deploy-kubernetes":{"id":"operating/deploy-kubernetes","title":"Kubernetes deployment","description":"Deploy Quack on Demand on Kubernetes: the manager as a pod that spawns DuckDB node pods on demand, per pool, with highly available managers.","sidebar":"docs"},"operating/deploy-local":{"id":"operating/deploy-local","title":"Local deployment","description":"The default local runtime: DuckDB nodes as child processes of the manager on one machine, for development, evaluation and small deployments.","sidebar":"docs"},"operating/deploy-single-server":{"id":"operating/deploy-single-server","title":"Single-server production deployment","description":"Production deployment of a DuckDB gateway on one large server with an existing PostgreSQL and an S3-compatible object store such as MinIO.","sidebar":"docs"},"operating/encryption":{"id":"operating/encryption","title":"Encryption at rest for DuckDB and DuckLake databases","description":"Create a database with its DuckDB or DuckLake data encrypted on disk with one switch at create time, and how the mechanism differs by kind.","sidebar":"docs"},"operating/federation":{"id":"operating/federation","title":"Federation","description":"Attach Postgres, MySQL, S3 or Iceberg catalogs to a DuckDB gateway database and query them under the same access-control model as native tables.","sidebar":"docs"},"operating/hardening":{"id":"operating/hardening","title":"Security hardening","description":"Security hardening checklist for exposing a DuckDB gateway to untrusted users: defaults to change, secrets, network and the SQL surface.","sidebar":"docs"},"operating/history-trends":{"id":"operating/history-trends","title":"Statement history and trends","description":"Every Flight SQL statement recorded for recent search and rolled up into trend charts: latency, routing and volume per tenant and pool.","sidebar":"docs"},"operating/iceberg":{"id":"operating/iceberg","title":"External Iceberg catalogs","de
1scription":"An external Iceberg REST catalog attaches to a database as a typed federated source: you","sidebar":"docs"},"operating/maintenance":{"id":"operating/maintenance","title":"Managed DuckLake maintenance","description":"Managed DuckLake maintenance: compaction, snapshot expiry and file cleanup per database, on compute isolated from query serving.","sidebar":"docs"},"operating/managed-storage":{"id":"operating/managed-storage","title":"Managed object storage","description":"Managed object storage: configure one root bucket and let every DuckLake database get its own prefix and credentials automatically.","sidebar":"docs"},"operating/manifest":{"id":"operating/manifest","title":"Manifest backup and restore","description":"Export the entire control-plane configuration as one YAML manifest and import it to restore, clone an environment or apply a reviewed change.","sidebar":"docs"},"operating/oauth-server-setup":{"id":"operating/oauth-server-setup","title":"OAuth / OIDC for DuckDB clients: Keycloak, Google, Azure AD, Cognito","description":"Server-side reference for bearer-token authentication of JDBC, ADBC and ODBC clients to DuckDB with Keycloak, Google, Azure AD or AWS Cognito.","sidebar":"docs"},"operating/observability":{"id":"operating/observability","title":"Observability","description":"Metrics for a DuckDB gateway through Micrometer: Prometheus, AWS, Azure or GCP sinks, plus a ready-made Grafana operator dashboard.","sidebar":"docs"},"operating/pools-cohorts":{"id":"operating/pools-cohorts","title":"Pools and cohorts","description":"Create, size, scale and stop pools of DuckDB nodes, the node roles that drive routing, and cohort-based node placement on Kubernetes.","sidebar":"docs"},"operating/rbac-admin":{"id":"operating/rbac-admin","title":"Administering access","description":"Recipes for managing users, roles, groups, memberships and pool grants on a DuckDB gateway with the qod command-line tool.","sidebar":"docs"},"operating/rbac-model":{"id":"operating/rbac-model","title":"Access control model: RBAC, row and column security for DuckDB","description":"The role-based access control model enforced on every DuckDB statement: roles, groups, table verbs, row-level policies, column masking, two gates.","sidebar":"docs"},"operating/resilience":{"id":"operating/resilience","title":"Resilience and recovery","description":"What happens when a DuckDB node, the manager or Postgres fails: the topology, recovery behaviour, and the known gaps with their issue numbers.","sidebar":"docs"},"operating/scim-provisioning":{"id":"operating/scim-provisioning","title":"SCIM provisioning: sync DuckDB users and groups from Okta, Entra or Google","description":"SCIM 2.0 endpoints so Okta, Microsoft Entra or Google Workspace provision and deprovision DuckDB gateway users and groups automatically.","sidebar":"docs"},"operating/tenants-databases":{"id":"operating/tenants-databases","title":"Tenants and databases","description":"Provision tenants and their databases on a DuckDB gateway, the object hierarchy behind them, and per-database object store credentials.","sidebar":"docs"},"operating/tls":{"id":"operating/tls","title":"TLS","description":"TLS on the Flight SQL edge and the native Quack listener: the default self-signed certificate, a CA-signed replacement, and client settings.","sidebar":"docs"},"reference/cli":{"id":"reference/cli","title":"Manager jar","description":"The manager uber-jar of Quack on Demand: boot the manager, run the self-contained demo, and the manifest subcommands for scripting.","sidebar":"docs"},"reference/configuration":{"id":"reference/configuration","title":"Configuration reference","description":"Every configuration key of Quack on Demand with its QOD_ environment-variable override, its default, and the sensitive values to rotate.","sidebar":"docs"},"reference/metrics":{"id":"reference/metrics","title":"Metrics","description":"Every metric series emitted by the DuckDB gateway, with its labels, for the Prometheus endpoint and the AWS, Azure and GCP sinks.","sidebar":"docs"}}}}')}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.