Recent Executions
Unified history across engines, shown as business stages.
Unified history across engines, shown as business stages.
Operationally important scores only.
Failures, drift, and stewardship work.
Late data and continuous jobs are visible.
Create
Start from business use cases, not an empty engine canvas.
Build
Design and maintain data pipelines in the embedded Apache Hop workspace. Advanced Ardana designer tools are available when enabled by configuration.
Default Build experience
Use native Hop editing directly from the Build page with the current Ardana session and platform proxy controls.
Copy a saved pipeline from your private Hop Web session to the controlled project area for approval.
No pipeline selected.
Connect
Create, test, discover, and assign governed logical connections for pipeline development and operations.
Select a connection to inspect usage, environments, and schema.
Choose a connection from the list.
Credentials remain server-side environment-secret references and are never returned as values.
Build
Continuously capture source changes into a governed destination. Workflow: Source → Tables → Initial data → Destination → Review.
Checks that run before a CDC definition can be deployed.
Source privileges
Replication or log access on every selected table, with safe per-source DBA instructions when access is missing.
Governed destination
A database, warehouse, object-store, or governed Kafka stream connection.
Connector support
Checking the reviewed SeaTunnel connector capability registry…
Runtime
Checking the SeaTunnel Zeta runtime…
Deployment approval
Deployments enter the normal approval and audit workflow before a job starts.
Deployed streams show lifecycle state, lag, throughput, and snapshot progress.
Loading CDC streams…
Build
Full load, replication, incremental movement, and batch sync between governed connections. Workflow: Source → Destination → Mode → Options → Review.
Governed source and destination connections only. Credentials resolve server-side and never reach the browser.
Each transfer shows source, destination, mode, and runtime state. Operate actions respect workspace roles.
| Name | Source | Destination | Mode | Status | Actions |
|---|
Lifecycle state, checkpoint, and sanitized diagnostics.
Build
SQL transformations, dimensions, facts, marts, and warehouse tests executed by a version-pinned dbt runner. The browser never receives database credentials or profiles.yml values.
A Git-backed project and working branch; credentials resolve server-side and are never submitted by the browser.
No project revision is pinned yet. Discover a branch to list its models, sources, and tests at an immutable commit.
Model list with layer and latest run state from the pinned revision. Select a model for detail, graph, SQL, tests, and history.
| Model | Layer | Path |
|---|
No models are listed yet.
Every action maps to one governed dbt Core command on the pinned revision and records immutable evidence.
Immutable execution evidence: commit, versions, selector, artifacts, and terminal result.
| Run | Command | Status | Commit | Artifacts | Finished |
|---|
No dbt runs are recorded yet.
Graph, SQL, tests, documentation, and per-model history come from ingested manifest and run-results artifacts.
Select a model from the list to see its graph, SQL, tests, documentation, and run history.
Operate
Schedules, dependencies, retries, and release promotion for finite work.
Batch lane
Trigger, refresh, inspect, and correlate scheduled or ad-hoc Hop pipeline runs.
Configured release-backed batch schedules with cadence, next run, and lifecycle controls. Next run is computed from the cron expression in the declared timezone.
| Schedule | Cadence | Next run | State | Actions |
|---|
Prioritized release queue for native Apache Hop .hpl artifacts. Full file discovery is kept behind a compact review list.
Promotion moves an approved release across environments; rollback re-fetches a prior immutable digest. Evidence comes from recorded release promotions only.
Operate
Batch, transfer, and model execution history with CI/CD pipeline visibility and controls.
Runs returned by the control-plane snapshot. Search and filters round-trip through the URL and reset pagination-free lists cleanly.
| Workload | Type | Started | Duration | Status | Trigger |
|---|
Governed Git workflow
GitLab pipelines, deployment evidence, manual jobs, retry/cancel controls, and Airflow evidence correlation.
Batch executions and streaming service events in one operational chronology.
Release queue
Releases awaiting approval or in promotion. Maker-checker approvals, deploys, promotions, and rollbacks are performed on the Orchestration queue with recorded evidence.
Operate
Continuous stream health, incidents, and engine diagnostics.
Live state returned by the control plane for registered streaming services. Lifecycle controls stay in the stream lane below; lag and message times are observed values only.
| Stream | State | Lag | Replicas | Last message |
|---|
Stream lane
Start, stop, restart, and monitor continuous Hop services independently from Airflow DAG runs.
Failures, degraded streams, unhealthy datasets, and inactive schedules that need an operator decision.
Context for the most urgent execution, service, schedule, or health item.
Airflow, platform API, release workflow, and service-registry checks. Engine-native diagnostics stay role-authorized and out of the primary navigation.
Operate
Warehouse tests, freshness, reconciliation, and quality results.
Rules returned by the control-plane snapshot with their last recorded outcome. Row-level results and history arrive with the dbt and OpenMetadata result publishers.
| Rule | Dataset | Kind | Severity | Last outcome |
|---|
Context for the selected rule from live control-plane data. No rule outcomes are inferred when a result source is not connected.
Govern
Governed metadata, discovery, and schema evolution.
Datasets returned by the control-plane snapshot with ownership and quality state.
| Dataset | Layer | Owner | Quality |
|---|
Ownership, layer, project, and quality state for the selected dataset. Column-level schema history arrives with the OpenMetadata sync, which is not connected yet.
Govern
Technical lineage, impact analysis, and execution provenance.
Source-to-target edges returned by the control plane. Search matches either endpoint; direction filters relative to the match. Execution provenance per edge arrives with the lineage publisher.
| From | Operation | To |
|---|
Govern
Environment-scoped runtime policy and targets.
Projects and recorded runs grouped by the environment field returned by the control plane. Readiness is never inferred from the group name.
| Environment | Projects | Recorded runs | Schedules |
|---|
Applied by the control-plane release flow, not by this page.
UAT → PROD promotion requires an approved release and a release-approver, data-owner, or platform-admin role.
Definitions and variable schema promote; resolved environment values and secret values never do.
Rollback restores a prior immutable SHA-256 digest and does not rewrite artifact history.
Environment isolation rules the platform enforces at the secret boundary.
Production secrets never fall back to UAT or DEV values; a missing required secret is a configuration error.
Manage references under Govern → Secrets once the vault backend is connected.
Runtime policy editing is not connected yet; environment policy ships with the configuration repository route.
Govern
Non-sensitive configuration values with Global → Tenant → Project → Environment inheritance. Secrets never live here.
Target structure: lower scopes override higher scopes (Global → Tenant → Project → Environment), the resolved-from scope is always named, and promotions carry definitions, never resolved values.
| Key | Effective value | Resolved from | Overrides |
|---|
No variables are defined yet. Rows appear here with inheritance-accurate effective values once the configuration repository route is connected.
Govern
Masked secret management, rotation, and access policy. Values are never shown by default in any list or audit view.
Target structure: references are masked in every list and audit view, per-environment isolation is enforced (PROD never falls back to UAT or DEV), and rotation and access counts are shown without exposing values.
| Secret reference | Environment | Used by | Last rotation |
|---|
No vault-backed secrets are registered yet. References, rotation posture, and access policy appear here once the vault backend route is connected.
Govern
Identity, role, and workspace-scoped access controls with least-privilege defaults.
Target structure: effective permissions per role and workspace once policy administration ships. Separation of duties (approver ≠ submitter) is enforced server-side.
| Role | Workspace scope | Key permissions | Members |
|---|
The role and workspace matrix appears here when access policy administration is connected.
Target structure: explicit allow rules for destinations, secrets, and environments, with least-privilege review dates.
| Workspace | Members | Admins | Review due |
|---|
No policy rules are defined yet. Workspace access rows with review dates appear here once policy administration is connected.
Admin
Admin-managed user and role administration. Restricted to platform-admin and security-admin roles, with backend audit logging.
List, filter, update, and deactivate users through the control-plane admin API.
Least-privilege defaults. Privileged admin grants stay out of this path.
Admin
Runtime, connector, and engine-native diagnostics.
Admin
Platform configuration and readiness.
Operational capabilities available in the Ardana workspace.
Admin
Immutable audit events for configuration, release, and secret actions.
Admin
Enter the vendor license key to activate subscription entitlements. The control plane verifies the key locally and stays the sole entitlement decision point.
Verified locally by the control plane on every status check. The raw key is never displayed again after saving.
Paste the key exactly as issued. Saving verifies the signature and expiry before storing.