Private connectivity for Snowflake Native Apps¶
A Snowflake Native App uses the private connectivity configured on the account where the app is installed. There is no separate private connectivity setup for the app.
This topic describes which existing configuration applies, and which limitations are specific to an app.
Cloud platform support¶
AWS PrivateLink and Azure Private Link are generally available for Snowflake Native Apps with and without containers. Google Cloud Private Service Connect is not yet supported.
For the full matrix, including Virtual Private Snowflake and government regions, see Support for private connectivity, VPS, and government regions.
Ingress¶
Configure inbound private connectivity on the account where the app is installed:
For more information, see To the Snowflake Service. To open the app in Snowsight, also configure To Snowsight.
Streamlit¶
If the app includes Streamlit, also configure Private connectivity for Streamlit in Snowflake so the Streamlit URL resolves on your private network. This includes AWS PrivateLink and Azure Private Link.
Google Cloud Private Service Connect is not supported for a Streamlit app in a Snowflake Native App. See Unsupported Streamlit features.
Apps with containers¶
Endpoints that the app exposes use the same inbound private connectivity as Snowpark Container Services. See Inbound connectivity.
Open privatelink_ingress_url from SHOW ENDPOINTS, rather than the public
ingress_url. SHOW ENDPOINTS returns privatelink_ingress_url only for Business Critical
accounts.
Egress¶
An app reaches an external endpoint over private connectivity through an external access integration.
The provider requests the endpoint with PRIVATE_HOST_PORTS on the app specification. See
Request external access.
The consumer approves that app specification in the account where the app is installed. See Approve app specifications.
Apps without containers¶
Egress from a UDF, UDTF, or stored procedure uses the same private connectivity setup as external network access. See External network locations using external access integrations.
Apps with containers¶
Egress from the service uses the same private connectivity setup as Snowpark Container Services. See Network egress using private connectivity.
Email notifications¶
Links in email notifications from an app do not correctly link into an account that uses private connectivity. See Known issue with AWS PrivateLink and Azure Private Link.