Skip to content

Quickstart

This runs curral with the example configuration from the repository: two local DuckDB databases (sales and logs) and three users, admin, analyst and etl. You need Docker and git.

  1. Start the server.

    Terminal window
    git clone https://github.com/lucasapassos/curral && cd curral
    docker run --rm -p 127.0.0.1:8080:8080 \
    -v "$PWD/examples:/etc/curral:ro" -e CURRAL_DATA=/var/lib/curral \
    lucasapassos/curral serve \
    --catalog /etc/curral/catalog.yaml \
    --users /etc/curral/users.yaml \
    --policy /etc/curral/policy.rego --policy /etc/curral/roles.json
  2. Create a table as admin. In another terminal:

    Terminal window
    curl -u admin:admin-pw localhost:8080/v1/query \
    -d '{"sql": "CREATE TABLE orders AS SELECT range AS id, range * 10 AS amount FROM range(5)"}'
  3. Read it as analyst.

    Terminal window
    curl -u analyst:analyst-pw 'localhost:8080/v1/query?format=csv' \
    -d '{"sql": "SELECT * FROM orders"}'
  4. Try to write as analyst, without running anything. dry_run asks the policy for its decision and explains it:

    Terminal window
    curl -u analyst:analyst-pw localhost:8080/v1/query \
    -d '{"sql": "DELETE FROM orders", "dry_run": true}'
    {"dry_run":true,"decision":"deny","decided_by":"policy","statement_type":"DELETE",
    "tables":["sales.main.orders"],"targets":["sales.main.orders"], ...}
  5. See what the analyst can query.

    Terminal window
    curl -u analyst:analyst-pw localhost:8080/v1/schema