CREATE APPLICATION SERVICE¶
Creates a new Application Service that deploys a packaged application build from an artifact repository.
An Application Service is a first-class Snowflake object. It manages its own compute, lifecycle, and access control. Unlike a Snowpark Container Services service, an Application Service deploys from a versioned package rather than from a user-supplied service specification.
This command supports the following variants:
- CREATE OR ALTER APPLICATION SERVICE: Creates an Application Service
if it doesn’t exist, or converges an existing one to the state described by a
SPECIFICATION.
- See also:
ALTER APPLICATION SERVICE, DESCRIBE APPLICATION SERVICE, DROP APPLICATION SERVICE, SHOW APPLICATION SERVICES
Syntax¶
Variant syntax¶
CREATE OR ALTER APPLICATION SERVICE¶
Creates an Application Service if it doesn’t already exist, or converges an existing
Application Service to the state described in the statement. The SPECIFICATION is
the full intended state of the service: Snowflake computes the changes needed to reach
it, and resets any property the specification doesn’t set.
CREATE OR ALTER APPLICATION SERVICE requires a SPECIFICATION. It’s the only way to
update a specification, because
ALTER APPLICATION SERVICE can’t set one.
For more information, see CREATE OR ALTER APPLICATION SERVICE usage notes and CREATE OR ALTER <object>.
Required parameters¶
nameSpecifies the identifier for the Application Service. The identifier must be unique for the schema where the service is created. For more details, see Identifier requirements.
The Application Service doesn’t share a namespace with SPCS
SERVICEobjects.FROM ARTIFACT REPOSITORY repository_name PACKAGE package_name
Specifies the artifact repository and package to deploy. The repository must be of type
APPLICATION.You must include
FROM ARTIFACT REPOSITORY. Omitting the repository clause isn’t supported.
Optional parameters¶
VERSION version_aliasSpecifies the version of the package to deploy. You can pass a version name, such as
VERSION$3, or a version alias, such asLATESTorDEFAULT. If you don’t specify a version, Snowflake uses the package’s default version; if the package has no default version, the command returns an error.EXTERNAL_ACCESS_INTEGRATIONS = ( integration_name [ , ... ] )
Specifies the names of the external access integrations that allow the application to access external network locations. The names in this list are case-sensitive.
QUERY_WAREHOUSE = warehouse_nameSpecifies the warehouse used by the application when a container connects to Snowflake without explicitly specifying a warehouse.
EXECUTE_AS_ROLE = role_nameSpecifies the role that Snowflake uses to run owner’s rights queries from the app and to derive caller’s rights grants. Only valid for an app created in a personal database.
Requirements:
- The specified role must be granted to the owning user of the app.
- If omitted, Snowflake sets
EXECUTE_AS_ROLEto the creator’s session primary role.
If the specified role is no longer granted to the owning user when the app starts, startup fails.
AUTO_RESUME = { TRUE | FALSE }Specifies whether Snowflake automatically resumes the service when it receives an inbound request to one of its endpoints.
AUTO_SUSPEND_SECS = numSpecifies the number of seconds of inactivity after which Snowflake automatically suspends the Application Service. The minimum non-zero value is
300. A value of0disables auto-suspend.DEFAULT:
0(disabled)MIN_INSTANCES = numSpecifies the minimum number of instances Snowflake keeps running. Snowflake never runs fewer than this, even if the app is idle.
- Must be at least 1.
- Can’t be greater than
MAX_INSTANCES.
DEFAULT: Not set. Defaults to
1whenMAX_INSTANCESis set. If both are unset, Snowflake runs one instance.MAX_INSTANCES = numSpecifies the maximum number of instances Snowflake runs. Snowflake never runs more than this.
- Must be at least 1 and no more than
10. - Can’t be less than
MIN_INSTANCES.
DEFAULT: Not set. If unset, this matches
MIN_INSTANCES.- Must be at least 1 and no more than
COMMENT = 'string_literal'Specifies a comment for the Application Service.
SPECIFICATION = 'yaml'Specifies an inline manifest that configures the service, as a single-quoted string or a dollar-quoted (
$$ ... $$) block. When you supply a specification, Snowflake uses it as the source of truth for the properties it owns and doesn’t read the manifest packaged in the artifact repository.A specification is required with CREATE OR ALTER APPLICATION SERVICE and optional with
CREATE APPLICATION SERVICE.The specification accepts the following keys. Unknown keys are an error, so a typo such as
min_instancefails rather than being silently ignored.versionThe schema version of the specification. The only supported value is
2.DEFAULT:
2label,description,iconThe display name, description, and icon for the app.
iconis a path relative to the project root and can’t escape it with../. These values appear in theadditional_propertiescolumn of SHOW APPLICATION SERVICES and DESCRIBE APPLICATION SERVICE.query_warehouseEquivalent to
QUERY_WAREHOUSE.min_instances,max_instancesEquivalent to
MIN_INSTANCESandMAX_INSTANCES.auto_resume,auto_suspend_secsEquivalent to
AUTO_RESUMEandAUTO_SUSPEND_SECS.execute_as_roleEquivalent to
EXECUTE_AS_ROLE. Applied when the service is created. You can’t change it later, including withCREATE OR ALTER.external_access_integrationsA list of external access integration names, equivalent to
EXTERNAL_ACCESS_INTEGRATIONS.secretsA list of secrets to expose to the app. Each entry has a
name(the name the app reads) and asecret(the identifier of the Snowflake secret object). Each secret must exist and be accessible to the owning role.environment_variablesA list of environment variables to set in the app’s containers. Each entry has a
nameand avalue.
Properties that the specification owns can’t also appear as top-level clauses in the same statement. Specifying
QUERY_WAREHOUSE,EXTERNAL_ACCESS_INTEGRATIONS,MIN_INSTANCES,MAX_INSTANCES,AUTO_RESUME,AUTO_SUSPEND_SECS, orEXECUTE_AS_ROLEalongsideSPECIFICATIONreturns an error that tells you to set the property inside the specification instead.COMMENTisn’t owned by the specification, so you set it as a top-level clause.
Access control requirements¶
If your role does not own the objects in the following table, then your role must have the listed privileges on those objects:
| Privilege | Object | Notes |
|---|---|---|
| CREATE APPLICATION SERVICE | Schema | Required to create a new Application Service in the schema. |
| READ | Artifact repository | Required on the artifact repository that contains the package. |
| USAGE | External access integration | Required for each integration listed in |
| USAGE | Warehouse | Required if |
| USAGE | Role | Required on the role specified in |
| OWNERSHIP | Application Service | Required when |
| READ | Secret | Required on each secret listed in the secrets key of a SPECIFICATION. |
Operating on an object in a schema requires at least one privilege on the parent database and at least one privilege on the parent schema.
For instructions on creating a custom role with a specified set of privileges, see Creating custom roles.
For general information about roles and privilege grants for performing SQL actions on securable objects, see Overview of Access Control.
Usage notes¶
- The Application Service starts automatically after creation. To check its status, use SHOW APPLICATION SERVICES or DESCRIBE APPLICATION SERVICE.
- To upgrade the service to a different package version, use
ALTER APPLICATION SERVICE with
UPGRADE. - Standalone SPCS SQL commands, such as
CREATE SERVICEandEXECUTE JOB SERVICE, aren’t used to manage an Application Service. UseAPPLICATION SERVICEcommands instead. CREATE OR REPLACEisn’t supported for Application Services. To create a service if it doesn’t exist or update it if it does, use CREATE OR ALTER APPLICATION SERVICE.- You must specify
FROM ARTIFACT REPOSITORYwith the repository name. Commands that specify onlyFROM PACKAGEwithout a repository aren’t supported. - Snowflake App Runtime isn’t available on trial accounts.
EXECUTE_AS_ROLEis set at creation time and can’t be changed with ALTER APPLICATION SERVICE.
- The OR REPLACE and IF NOT EXISTS clauses are mutually exclusive. They can’t both be used in the same statement.
-
CREATE OR REPLACE <object> statements are atomic. That is, when an object is replaced, the old object is deleted and the new object is created in a single transaction.
CREATE OR ALTER APPLICATION SERVICE usage notes¶
-
A
SPECIFICATIONis required.CREATE OR ALTER APPLICATION SERVICEwithout one returns an error. -
CREATE OR ALTERcan’t be combined withIF NOT EXISTS. -
The specification is the full intended state of the service. Snowflake resets every property the specification owns but doesn’t set:
- Omitting
label,description, oriconclears it. - Omitting
external_access_integrations,secrets, orenvironment_variablesremoves all of them. - Omitting
auto_suspend_secs,min_instances, ormax_instancesreturns it to its default. - Omitting
query_warehouseunsets it. - Omitting
auto_resumereturns it to its default.
To keep a value, restate it in every
CREATE OR ALTERstatement. - Omitting
-
execute_as_roleis applied when the service is created and can’t be changed afterward. Sending a different value for an existing service returns an error; omitting it leaves the current role in place. -
The package and the artifact repository are fixed when the service is created. Naming a different package or repository for an existing service returns an error. Re-sending the current value is a no-op.
-
When you include a
VERSIONclause, Snowflake converges the service to that version after applying the specification. Because a version alias is resolved at statement time,VERSION LATESTpicks up a newer version if one has been published since the last deployment. -
A specification can’t be read back. It isn’t shown by DESCRIBE APPLICATION SERVICE or SHOW APPLICATION SERVICES, and GET_DDL doesn’t support Application Services. Keep the specification in source control. For CLI deploys that’s the service-level keys in
app.yml; if you write the SQL yourself, send only the keys listed underSPECIFICATION. You can’t pass a wholeapp.ymlas a specification. For more information, see Validation. -
CREATE OR ALTER APPLICATION SERVICErequires theFROM ARTIFACT REPOSITORYclause.
Examples¶
Deploy the default version of a package from an artifact repository:
Deploy a specific version:
Deploy the LATEST alias:
Deploy in a personal database with a named execution role:
Deploy with 2 to 5 instances:
Create the service if it doesn’t exist, or converge it to this state if it does:
Because the specification is the full intended state, this next statement changes the
warehouse and drops everything else the previous statement set. The integrations and
the secret are removed, the label and description are cleared, and max_instances and
auto_suspend_secs return to their defaults:
Redeploy after publishing a new build. Resolving LATEST again moves the service to
the new version, and restating the specification in full leaves everything else
unchanged: