Setup guide · Amazon Redshift

Connect Amazon Redshift to Dataki

Dataki connects to Amazon Redshift directly, as a SQL client does: the endpoint, port 5439, a database, a user and a password. It works the same for a provisioned cluster and a Serverless workgroup. Redshift keeps both private by default, so the work is on the AWS side: a user that can only read, public access, and one security group rule for Dataki's address.

  1. Your Redshift cluster or workgroup
  2. Direct connection over TLS
  3. Dataki
Setup
About 10 minutes.
Connects from
34.89.253.13, on port 5439 unless you changed it.
Encryption
Always TLS: Dataki never falls back to an unencrypted connection. On an endpoint AWS named, the certificate is verified.
What it reads
Tables, views (late-binding ones too) and Spectrum tables in every schema the user can use, or only the schemas you list.

01Before you start

  • A provisioned cluster or a Serverless workgroup, and its admin user, or any user allowed to create users and grant access.
  • Permission in the AWS console to edit the cluster's or workgroup's network settings and its VPC security group.

02Set it up

3 steps, about 10 minutes

  1. 01

    Create a read-only user

    Connect as the admin user, for instance in Query Editor v2, and create a user for Dataki. Pick a password of 8 to 64 characters with an upper-case letter, a lower-case letter and a digit, and without ', ", \, / or @. Then give it USAGE on each schema Dataki should read and SELECT on the tables in it.

    The last line is Redshift's scoped permission: it also covers tables created in the schema later, by anyone. Where it is not available to you, the line before it grants the tables that exist today, and you run it again after adding tables.

    Run as the admin user
    CREATE USER dataki PASSWORD 'Choose-a-long-password-1';
    GRANT USAGE ON SCHEMA analytics TO dataki;
    GRANT SELECT ON ALL TABLES IN SCHEMA analytics TO dataki;
    GRANT SELECT FOR TABLES IN SCHEMA analytics TO dataki;
    • Repeat the three GRANT lines for every schema you want to ask about.
    • Set the password as plain text, as above. A user whose password was set as a sha256|… hash cannot sign in from Dataki.
  2. 02

    Let Dataki in

    Redshift creates clusters and workgroups private, and new ones accept only TLS. For Dataki to reach yours it has to be publicly accessible, with an inbound rule for 34.89.253.13.

    • Network settings

      Provisioned cluster

      The cluster's Properties tab › Network and security settings.

      Serverless workgroup

      Workgroup configuration › your workgroup › Data access › Network and security › Edit.

    • Security group rule

      Provisioned cluster

      Open the VPC security group › Inbound rules › Edit inbound rules: TCP, port 5439, source 34.89.253.13/32.

      Serverless workgroup

      The same: TCP, port 5439, source 34.89.253.13/32.

    • Public access

      Provisioned cluster

      Actions › turn on Publicly accessible.

      Serverless workgroup

      Turn on Publicly accessible in the same panel.

    • Endpoint

      Provisioned cluster

      General information › Endpoint.

      Serverless workgroup

      The workgroup's General information › Endpoint.

    • The VPC needs a route to an internet gateway, which the default VPC has. When public access is on, Redshift gives the cluster or workgroup an Elastic IP of its own.
  3. 03

    Add the connection in Dataki

    Open app.dataki.ai/connect and, under Database Connections, choose Connect Redshift. Paste the endpoint as the console shows it, …amazonaws.com:5439/dev: Dataki takes the port and the database from it. Enter dataki and its password, then Test connection and Save Connection.

    Leave Schemas empty for every schema the user can read, or list the ones the model should see, separated by commas.

03Check it

Make sure it is right

Two checks, run while signed in as dataki. The connection test in Dataki runs the first one for you, and warns when it finds nothing.

Which tables will Dataki see?

Dataki shows the model the tables and views the user can read, in the schemas you allowed. A table missing here cannot be asked about.

As dataki
SELECT table_schema, table_name, table_type
FROM svv_tables
WHERE table_schema NOT IN ('information_schema', 'catalog_history')
  AND LEFT(table_schema, 3) <> 'pg_'
  AND has_schema_privilege(table_schema, 'USAGE')
  AND CASE WHEN table_type LIKE '%EXTERNAL%' THEN TRUE
      ELSE has_table_privilege(quote_ident(table_schema) || '.' || quote_ident(table_name), 'SELECT') END
ORDER BY table_schema, table_name;

Is the user really read-only?

This must fail with "permission denied". Dataki also runs every query in a read-only transaction and accepts only a single SELECT, but the user is what holds whatever else happens.

As dataki
CREATE TABLE analytics.dataki_write_check (id INT);

Once Amazon Redshift is connected, you can ask it questions from your AI assistant through Dataki's MCP server:

04Worth knowing

What you will run into

Redshift SQL, not PostgreSQL
Redshift started from PostgreSQL 8.0 and differs from it: no generate_series or NOW() over your tables, no arrays, LISTAGG rather than string_agg, and window sums need a ROWS frame. Dataki writes Redshift SQL for a Redshift connection, so connect Redshift as Redshift, not as PostgreSQL.
Big results are refused, not cut
A query may return up to 50,000 rows and run for up to two minutes. Past either, Dataki stops it and says so, rather than drawing a chart from part of the answer. Ask for totals, or for a shorter period.
Queries use your cluster
Every question runs on your warehouse: on a Serverless workgroup it is billed as compute time, on a provisioned cluster it takes a slot in a WLM queue. A separate queue for the dataki user keeps Dataki's queries away from your loads.
Connections Dataki cannot make
IAM authentication and temporary credentials, a cluster reachable only inside its VPC (through PrivateLink, a VPN or a bastion host), and SSH tunnels. By default Redshift also locks a user after five failed sign-ins in a row, until an admin unlocks it, so check the password before testing again.

05Other routes

If this route does not suit you

Try it on sample data first

AWS's getting started guide loads TICKIT, the ticket-sales sample its documentation uses, into a cluster in a few minutes. Grant dataki the schema it lands in, and ask Dataki which events sold the most tickets.

Free while we are in beta

Connect Amazon Redshift. Ask it something.

Once the data is where Dataki can read it, the first answer is a question away, and anything worth keeping becomes a dashboard with a link that stays live.

One data source
Free tier. Connect a second on any paid plan.
Read-only
Every query runs read-only. Dataki cannot change your data.
No card
There is nothing to cancel if you stop.