Skip to main content

Connect to a BYOC Warehouse

A BYOC warehouse runs in your cloud account and VPC. Your cloud network provides direct warehouse connectivity. Configure security groups, network ACLs, load balancers, routing, and any public exposure in your own cloud environment.

Use Connection information and examples to find the host, ports, credentials, and client examples for the warehouse.

Public Access Allowlist

This control is separate from the SaaS Public Link and PrivateLink features. BYOC does not expose a separate VeloDB-managed public endpoint for direct warehouse connections.

The Public Access Allowlist restricts the source IP addresses from which users can perform Console data-plane operations. These operations include running queries in SQL Editor, importing data through Import Data, viewing query activity in Query Audit, and using other Console features that require warehouse connectivity.

The allowlist does not affect control-plane operations, such as creating, deleting, or scaling resources. It also does not affect direct private connections or configure network controls in your cloud account.

byoc public access allowlist

Click Edit IP Allowlist to open the settings and choose one of three options:

byoc public access allowlist modal

OptionBehavior
AnywhereAllow Console data-plane operations from any source IP address.
NowhereBlock Console data-plane operations through this access path.
Specific LocationsRestrict access to listed IP addresses or CIDR blocks.

Selecting Nowhere blocks the public access path. If no private access path is configured, Console features that require warehouse connectivity cannot reach the warehouse. This setting does not disable Console data-plane operations across the organization or affect direct private connections. To request organization-wide disablement, contact VeloDB Support.