Skip to main content

What is a source ?​

Data sources are data stored in your organization, it's an endpoint and the central elements of QALITA Platform. They are referenced in the platform, and the original data is never stored in the platform.

Reference a Source​

Referencing a source is a way to tell Platform that you have data accessible at this endpoint, it can be a file path, or database credentials.

You can reference a source two ways :

  1. You can do it using the QALITA CLI source add command.
  2. Your can do it using the QALITA CLI UI

When you reference a source, QALITA CLI creates a configuration file sources-conf.yaml in the ~/.qalita/ directory, which contains the connection information for the source.

sources-conf.yaml
version: 1
sources:
- config:
path: ~/desktop/data/heart/
description: 11 clinical features for predicting heart disease events.
id: 1
name: Heart Failure Prediction Dataset
reference: true
sensitive: true
type: file
validate: valid
visibility: internal

In this example, the source is a local file, but it could also be a database, a remote file, a data stream, etc.

PropertyDescription
versionConfiguration version
sourcesList of sources
configSource configuration, properties vary depending on the source type.
idUnique source identifier, this ID is obtained from the platform after finalizing the source referencing with the qalita source push command.
nameSource name
typeSource type
referenceIf the source is a reference, it allows comparison with other sources.
sensitiveIf the source is sensitive, special permission is required to access it see permissions
validateIf the source is valid, it means the client has proper access to the source, and it can be referenced on the platform.
visibilitySource visibility, can be public, internal, or private. Allows restricting access to different user profiles on the platform.
access_modeHow the platform reaches the source: service (shared service-account credentials) or user (the credentials of one named person). See Access modality.

Access modality​

A source's credentials live on the Worker, never on the platform. Who those credentials belong to changes what the platform is allowed to do with the source, so every source declares an access modality.

ModalityMeaning
serviceThe Worker holds the credentials of a shared service account. Anyone entitled to see the source may read it. This is the default, and the behaviour QALITA has always had.
userThe Worker holds the credentials of one named person — typically their own Active Directory account, carrying their own rights on the database.

Why it matters​

If your database grants rights per user — each person connecting with their own account and seeing a different subset of the data — then a source registered with one person's credentials carries that person's rights. Letting a colleague read it through the platform would hand them access the database never granted them, and the permission chain your DBA set up would be broken at the application layer.

So a source declared user is subject to three rules the platform enforces for you:

  • its visibility is necessarily private, and cannot be changed;
  • it is readable only by the person it is bound to — sharing it through the usual source associations does not grant access;
  • it is served only by the Worker that holds those credentials. If that Worker is offline, the platform says so rather than falling back to another one.

Choosing the modality​

You choose it when referencing the source. The platform then binds the source to the Worker used and to you.

Tightening a source from service to user is allowed at any time — it only ever removes access. The reverse is refused: to move a source back to a service account you must reference it again through a Worker configured with service-account credentials, because that is the only way to prove the credentials actually changed.

warning

A user or a Worker that owns a user-mode source cannot be deleted while that source exists. Reassign or delete the person's nominative sources first. This is deliberate: silently unbinding such a source would leave data reachable with credentials nobody is accountable for.

When a source is not visible​

A source may be absent from a listing for three reasons: it is private and not shared with you, it is nominative and belongs to someone else, or it is marked sensitive and you lack the corresponding habilitation. Where the platform can say which, it does — Studio shows the reason and what to do about it.

Source Types​

Sources can be of any type, as long as there are packs to process them. QALITA Platform imposes no limitations on source types.