From df1c62a4ccf9a4bf9b528e0bf1f0c10847281843 Mon Sep 17 00:00:00 2001 From: Daulat Karande Date: Mon, 28 Sep 2026 21:30:18 +0530 Subject: [PATCH 1/6] Support Snowflake WIF auth in dlsync JDBC connection. Pass token and workloadIdentityProvider through to JDBC 3.28.0 so CI can use Aembit OIDC instead of a stored password. Co-authored-by: Cursor --- CHANGELOG.md | 5 +++++ README.md | 6 +++++- build.gradle | 2 +- pom.xml | 2 +- src/main/java/com/snowflake/dlsync/ConfigManager.java | 2 +- 5 files changed, 13 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 931fd79..8da01b6 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,11 @@ This project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [Unreleased] +### Added +- Workload Identity Federation (WIF) JDBC auth: pass `token` and `workloadIdentityProvider` through to Snowflake JDBC +- Upgraded `snowflake-jdbc` from 3.25.1 to 3.28.0 (WIF authenticator support) + ## [3.2.0] - 2026-02-27 ### Added - Added PLAN command for deployment preview (dry-run without database modifications) diff --git a/README.md b/README.md index 9034832..558883b 100644 --- a/README.md +++ b/README.md @@ -347,6 +347,8 @@ connection: authenticator: # snowflake authenticator(optional) private_key_file: # snowflake p8 file (optional) private_key_pwd: # password for private key file (optional) + token: # OAuth or WIF token (optional) + workloadIdentityProvider: # OIDC, AWS, AZURE, or GCP when authenticator is WORKLOAD_IDENTITY (optional) ``` The `configTables` is used by create script module to add the data of the tables to the script file. The `scriptExclusion` is used to exclude the script files from being processed by this tool. @@ -362,11 +364,13 @@ db=database #your database schema=dl_sync #your dl_sync schema. It will use this schema to store neccessary tables for this tool user=user_name #user name of the database password=password #password for the connection (optional) -authenticator=externalbrowser #authenticator used for the connection (optional) +authenticator=externalbrowser #authenticator used for the connection (optional). Use WORKLOAD_IDENTITY for WIF warehouse=my_warehouse #warehouse to be used by the connection role=my_role #role used by this tool private_key_file=my_private_key_file.p8 # private key file used for the connection (optional) private_key_pwd=my_private_key_password # password for the private key file (optional) +token=oauth_or_wif_token # OAuth / WIF token (optional) +workloadIdentityProvider=OIDC # OIDC, AWS, AZURE, or GCP when authenticator=WORKLOAD_IDENTITY (optional) JAVA_TOOL_OPTIONS ="-Dnet.snowflake.jdbc.enableBouncyCastle=true" # This must be set if using encrypted key-pair authentication ``` diff --git a/build.gradle b/build.gradle index 6d2ca55..0cbad7e 100644 --- a/build.gradle +++ b/build.gradle @@ -16,7 +16,7 @@ repositories { dependencies { implementation 'org.apache.commons:commons-text:1.14.0' - implementation 'net.snowflake:snowflake-jdbc:3.25.1' + implementation 'net.snowflake:snowflake-jdbc:3.28.0' implementation 'ch.qos.logback:logback-core:1.5.25' implementation 'ch.qos.logback:logback-classic:1.5.25' implementation 'org.slf4j:slf4j-api:2.0.4' diff --git a/pom.xml b/pom.xml index c193297..253af79 100644 --- a/pom.xml +++ b/pom.xml @@ -22,7 +22,7 @@ net.snowflake snowflake-jdbc - 3.25.1 + 3.28.0 ch.qos.logback diff --git a/src/main/java/com/snowflake/dlsync/ConfigManager.java b/src/main/java/com/snowflake/dlsync/ConfigManager.java index d6ba243..a550bde 100644 --- a/src/main/java/com/snowflake/dlsync/ConfigManager.java +++ b/src/main/java/com/snowflake/dlsync/ConfigManager.java @@ -18,7 +18,7 @@ @Slf4j public class ConfigManager { private final static String CONFIG_FILE_NAME = "config.yaml"; - private final static String[] JDBC_KEY = {"url", "account", "user", "password", "authenticator", "role", "warehouse", "db", "schema", "private_key_file", "private_key_pwd"}; + private final static String[] JDBC_KEY = {"url", "account", "user", "password", "authenticator", "role", "warehouse", "db", "schema", "private_key_file", "private_key_pwd", "token", "workloadIdentityProvider"}; private final static String SCRIPT_ROOT_KEY = "SCRIPT_ROOT"; private String scriptRoot; private String profile; From 034af1a5ba38b8b4f73c43b56ddb1db9b4887aa1 Mon Sep 17 00:00:00 2001 From: sfc-gh-yhailu Date: Wed, 30 Sep 2026 16:01:09 -0700 Subject: [PATCH 2/6] updated release and changelog --- CHANGELOG.md | 2 +- gradle.properties | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 8da01b6..78470f3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,7 +2,7 @@ This project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). -## [Unreleased] +## [3.3.0] - 2026-09-30 ### Added - Workload Identity Federation (WIF) JDBC auth: pass `token` and `workloadIdentityProvider` through to Snowflake JDBC - Upgraded `snowflake-jdbc` from 3.25.1 to 3.28.0 (WIF authenticator support) diff --git a/gradle.properties b/gradle.properties index ff0ecd6..eb6c507 100644 --- a/gradle.properties +++ b/gradle.properties @@ -1 +1 @@ -releaseVersion=3.2.0 \ No newline at end of file +releaseVersion=3.3.0 \ No newline at end of file From e7f6c8bd676528aa30c958e9378c68bdfaa67115 Mon Sep 17 00:00:00 2001 From: sfc-gh-yhailu Date: Fri, 2 Oct 2026 12:00:26 -0700 Subject: [PATCH 3/6] Updated github action to latest version --- .github/workflows/release.yml | 10 ++++++---- .github/workflows/test.yml | 8 +++++--- CHANGELOG.md | 3 +++ 3 files changed, 14 insertions(+), 7 deletions(-) diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index aea652e..6bbf017 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -9,9 +9,9 @@ jobs: release: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v7 - name: Set up JDK 11 - uses: actions/setup-java@v4 + uses: actions/setup-java@v6 with: java-version: '11' distribution: 'temurin' @@ -20,7 +20,9 @@ jobs: export VERSION=$(grep "^releaseVersion=" gradle.properties | awk -F"=" '{ print $2 }') echo "VERSION=$VERSION" >> $GITHUB_ENV - name: Setup Gradle - uses: gradle/gradle-build-action@v2 + uses: gradle/actions/setup-gradle@v6 + with: + cache-provider: basic - name: Build with Gradle run: ./gradlew clean build - name: setup git config @@ -33,7 +35,7 @@ jobs: git tag -a v${{ env.VERSION }} -m "version ${{ env.VERSION }}" git push origin v${{ env.VERSION }} - name: Create GitHub Release - uses: softprops/action-gh-release@v1 + uses: softprops/action-gh-release@v3 with: tag_name: v${{ env.VERSION }} name: Release v${{ env.VERSION }} diff --git a/.github/workflows/test.yml b/.github/workflows/test.yml index cc6feb4..674c590 100644 --- a/.github/workflows/test.yml +++ b/.github/workflows/test.yml @@ -9,11 +9,13 @@ jobs: test: runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 - - uses: actions/setup-java@v4 + - uses: actions/checkout@v7 + - uses: actions/setup-java@v6 with: java-version: '11' distribution: 'temurin' - - uses: gradle/actions/setup-gradle@v4 + - uses: gradle/actions/setup-gradle@v6 + with: + cache-provider: basic - name: test with gradle run: ./gradlew test \ No newline at end of file diff --git a/CHANGELOG.md b/CHANGELOG.md index 78470f3..761aa14 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -6,6 +6,9 @@ This project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.htm ### Added - Workload Identity Federation (WIF) JDBC auth: pass `token` and `workloadIdentityProvider` through to Snowflake JDBC - Upgraded `snowflake-jdbc` from 3.25.1 to 3.28.0 (WIF authenticator support) +### Changed +- Updated GitHub Actions to supported versions: `actions/checkout` v7, `actions/setup-java` v6, `softprops/action-gh-release` v3 +- Replaced deprecated `gradle/gradle-build-action` with `gradle/actions/setup-gradle` v6 (using the open-source `basic` cache provider) ## [3.2.0] - 2026-02-27 ### Added From 2573672f87cd1559c4e4564bcd7c29d422334471 Mon Sep 17 00:00:00 2001 From: sfc-gh-yhailu Date: Mon, 5 Oct 2026 08:38:02 -0700 Subject: [PATCH 4/6] updated changelog --- CHANGELOG.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 761aa14..fb5d447 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,7 +8,7 @@ This project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.htm - Upgraded `snowflake-jdbc` from 3.25.1 to 3.28.0 (WIF authenticator support) ### Changed - Updated GitHub Actions to supported versions: `actions/checkout` v7, `actions/setup-java` v6, `softprops/action-gh-release` v3 -- Replaced deprecated `gradle/gradle-build-action` with `gradle/actions/setup-gradle` v6 (using the open-source `basic` cache provider) +- Replaced deprecated `gradle/gradle-build-action` with `gradle/actions/setup-gradle` v6 ## [3.2.0] - 2026-02-27 ### Added From 13a910aebe0f13513164b5534ff2720ebe2c764a Mon Sep 17 00:00:00 2001 From: sfc-gh-yhailu Date: Tue, 6 Oct 2026 11:50:49 -0700 Subject: [PATCH 5/6] updated codeowners --- .github/CODEOWNERS | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index 46f1a70..be4f32b 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1 +1 @@ -* @sfc-gh-yhailu \ No newline at end of file +* @sfc-gh-yhailu sfc-gh-skalaga \ No newline at end of file From 4335e623619f6fb4d282ab0175e9b292c03fb143 Mon Sep 17 00:00:00 2001 From: sfc-gh-yhailu Date: Tue, 6 Oct 2026 11:54:37 -0700 Subject: [PATCH 6/6] updated codeowners --- .github/CODEOWNERS | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/CODEOWNERS b/.github/CODEOWNERS index be4f32b..5703258 100644 --- a/.github/CODEOWNERS +++ b/.github/CODEOWNERS @@ -1 +1 @@ -* @sfc-gh-yhailu sfc-gh-skalaga \ No newline at end of file +* @sfc-gh-yhailu @sfc-gh-skalaga \ No newline at end of file