Skip to main content
Elementary Runtime is in private beta. Reach out to the team to learn more.
Elementary Runtime ships as a container image. Run it as a Docker service on a single host, or on Kubernetes with the Helm chart. Both options use the same image, the same configuration file, and the same file-based secrets.

Requirements

Network

The runtime only opens outbound connections. It exposes no ports and needs no inbound firewall rules. To route Cloud traffic through a proxy, set the standard HTTPS_PROXY and NO_PROXY environment variables. Some warehouse drivers also read these variables, so add warehouse hosts to NO_PROXY if their traffic must bypass the proxy.

Resources

Start with 0.5 vCPU and 1 GiB of memory for the default limits. Memory scales with max_concurrent_tasks and the sample size, because each running task holds its sample in memory until it is sent.

Container image

The image includes the drivers for all supported warehouses.

Behavior to plan for

  • Instances. Each running container registers with Elementary Cloud as a separate instance with a generated instance ID. Set instance.id_prefix to tell replicas apart. You can run more than one replica for availability.
  • Configuration changes. The configuration and secret files are read once, at startup. Restart the container to apply changes or rotated credentials.
  • Startup failures. An invalid configuration makes the container exit with a non-zero code. Let your orchestrator restart it, and check the logs for the failing field.
  • Shutdown. On SIGTERM, the runtime stops accepting new tasks and waits for running tasks to finish. Set the stop grace period to at least max_query_timeout_seconds plus 30 seconds.
  • Health. There is no health endpoint, because the runtime accepts no inbound connections. Instance status and per-connection health are reported to Elementary Cloud.
  • Logs. Logs go to stdout and stderr. They never contain task SQL text, row values, or credentials.

Install

Use Docker Compose to run the runtime on a VM or a single container host.
1

Create the configuration and secret files

Lay out the files on the host:
Reference secrets by their path inside the container. Compose mounts each secret at /run/secrets/<name>:
Restrict the secret files to the container user:
2

Define the service

stop_grace_period is set to the default max_query_timeout_seconds of 300 seconds, plus 30 seconds. Raise it if you raise the timeout.
3

Start the runtime

The instance shows as connected in Elementary Cloud once it registers.
To upgrade, change the image tag in compose.yaml and run docker compose up -d. To apply configuration or secret changes, run docker compose restart elementary-runtime.