Setup guide · Amazon Redshift
Connect Amazon Redshift to Dataki
Dataki connects to Amazon Redshift directly, as a SQL client does: the endpoint, port 5439, a database, a user and a password. It works the same for a provisioned cluster and a Serverless workgroup. Redshift keeps both private by default, so the work is on the AWS side: a user that can only read, public access, and one security group rule for Dataki's address.
- Your Redshift cluster or workgroup
- Direct connection over TLS
- Dataki
- Setup
- About 10 minutes.
- Connects from
34.89.253.13, on port 5439 unless you changed it.- Encryption
- Always TLS: Dataki never falls back to an unencrypted connection. On an endpoint AWS named, the certificate is verified.
- What it reads
- Tables, views (late-binding ones too) and Spectrum tables in every schema the user can use, or only the schemas you list.
01Before you start
- A provisioned cluster or a Serverless workgroup, and its admin user, or any user allowed to create users and grant access.
- Permission in the AWS console to edit the cluster's or workgroup's network settings and its VPC security group.
02Set it up
3 steps, about 10 minutes
- 01
Create a read-only user
Connect as the admin user, for instance in Query Editor v2, and create a user for Dataki. Pick a password of 8 to 64 characters with an upper-case letter, a lower-case letter and a digit, and without
',",\,/or@. Then give itUSAGEon each schema Dataki should read andSELECTon the tables in it.The last line is Redshift's scoped permission: it also covers tables created in the schema later, by anyone. Where it is not available to you, the line before it grants the tables that exist today, and you run it again after adding tables.
Run as the admin user CREATE USER dataki PASSWORD 'Choose-a-long-password-1'; GRANT USAGE ON SCHEMA analytics TO dataki; GRANT SELECT ON ALL TABLES IN SCHEMA analytics TO dataki; GRANT SELECT FOR TABLES IN SCHEMA analytics TO dataki;- Repeat the three
GRANTlines for every schema you want to ask about. - Set the password as plain text, as above. A user whose password was set as a
sha256|…hash cannot sign in from Dataki.
- Repeat the three
- 02
Let Dataki in
Redshift creates clusters and workgroups private, and new ones accept only TLS. For Dataki to reach yours it has to be publicly accessible, with an inbound rule for
34.89.253.13.-
Network settings
Provisioned cluster
The cluster's
Propertiestab ›Network and security settings.Serverless workgroup
Workgroup configuration› your workgroup ›Data access›Network and security›Edit. -
Security group rule
Provisioned cluster
Open the VPC security group ›
Inbound rules›Edit inbound rules: TCP, port5439, source34.89.253.13/32.Serverless workgroup
The same: TCP, port
5439, source34.89.253.13/32. -
Public access
Provisioned cluster
Actions› turn onPublicly accessible.Serverless workgroup
Turn on
Publicly accessiblein the same panel. -
Endpoint
Provisioned cluster
General information›Endpoint.Serverless workgroup
The workgroup's
General information›Endpoint.
- The VPC needs a route to an internet gateway, which the default VPC has. When public access is on, Redshift gives the cluster or workgroup an Elastic IP of its own.
-
- 03
Add the connection in Dataki
Open app.dataki.ai/connect and, under
Database Connections, chooseConnect Redshift. Paste the endpoint as the console shows it,…amazonaws.com:5439/dev: Dataki takes the port and the database from it. Enterdatakiand its password, thenTest connectionandSave Connection.Leave
Schemasempty for every schema the user can read, or list the ones the model should see, separated by commas.
03Check it
Make sure it is right
Two checks, run while signed in as dataki. The connection test in Dataki runs the first one for you, and warns when it finds nothing.
Which tables will Dataki see?
Dataki shows the model the tables and views the user can read, in the schemas you allowed. A table missing here cannot be asked about.
SELECT table_schema, table_name, table_type
FROM svv_tables
WHERE table_schema NOT IN ('information_schema', 'catalog_history')
AND LEFT(table_schema, 3) <> 'pg_'
AND has_schema_privilege(table_schema, 'USAGE')
AND CASE WHEN table_type LIKE '%EXTERNAL%' THEN TRUE
ELSE has_table_privilege(quote_ident(table_schema) || '.' || quote_ident(table_name), 'SELECT') END
ORDER BY table_schema, table_name; Is the user really read-only?
This must fail with "permission denied". Dataki also runs every query in a read-only transaction and accepts only a single SELECT, but the user is what holds whatever else happens.
CREATE TABLE analytics.dataki_write_check (id INT); Once Amazon Redshift is connected, you can ask it questions from your AI assistant through Dataki's MCP server:
04Worth knowing
What you will run into
- Redshift SQL, not PostgreSQL
- Redshift started from PostgreSQL 8.0 and differs from it: no
generate_seriesorNOW()over your tables, no arrays,LISTAGGrather thanstring_agg, and window sums need aROWSframe. Dataki writes Redshift SQL for a Redshift connection, so connect Redshift as Redshift, not as PostgreSQL. - Big results are refused, not cut
- A query may return up to 50,000 rows and run for up to two minutes. Past either, Dataki stops it and says so, rather than drawing a chart from part of the answer. Ask for totals, or for a shorter period.
- Queries use your cluster
- Every question runs on your warehouse: on a Serverless workgroup it is billed as compute time, on a provisioned cluster it takes a slot in a WLM queue. A separate queue for the
datakiuser keeps Dataki's queries away from your loads. - Connections Dataki cannot make
- IAM authentication and temporary credentials, a cluster reachable only inside its VPC (through PrivateLink, a VPN or a bastion host), and SSH tunnels. By default Redshift also locks a user after five failed sign-ins in a row, until an admin unlocks it, so check the password before testing again.
05Other routes
If this route does not suit you
Try it on sample data first
AWS's getting started guide loads TICKIT, the ticket-sales sample its documentation uses, into a cluster in a few minutes. Grant dataki the schema it lands in, and ask Dataki which events sold the most tickets.
Checked against
- Amazon Redshift: CREATE USER
- Amazon Redshift: GRANT
- Amazon Redshift: scoped permissions
- Amazon Redshift: making a cluster or workgroup publicly accessible
- Amazon Redshift: SSL connections
- Amazon Redshift: behavior changes (TLS and public access defaults)
- Amazon Redshift: SVV_TABLES
- Amazon Redshift: user lockout after failed sign-ins
- Amazon Redshift: load the TICKIT sample
Last checked 26 September 2026.
Free while we are in beta
Connect Amazon Redshift. Ask it something.
Once the data is where Dataki can read it, the first answer is a question away, and anything worth keeping becomes a dashboard with a link that stays live.
- One data source
- Free tier. Connect a second on any paid plan.
- Read-only
- Every query runs read-only. Dataki cannot change your data.
- No card
- There is nothing to cancel if you stop.