Cloud and BYOC for Orca Agent Engine are in Private Preview — request an invite
Docs
CLI

ork connections

Manage Pulsar, Kafka, and generic connection resources in your Orca Workspace with the ork connections commands.

The ork connections commands manage Connection resources through the Workspace registry API. A connection stores endpoint and authentication details for an external Pulsar cluster, Kafka cluster, or generic system, so functions, sources, sinks, and Kafka Connect connectors can reference it by name. These commands require the cloud.sn.io extension and are unavailable on a self-hosted engine.

Commands read --registry-url / ORCA_REGISTRY_URL and exactly one credential: --access-token / ORCA_ACCESS_TOKEN or --api-key / ORCA_API_KEY. See ork CLI for setup.

ork connections
├── list      List connections
├── get       Get one connection
├── create    Create a connection
├── validate  Validate a connection without storing it
├── update    Update a connection
├── delete    Delete a connection
└── test      Test connection health

ork connections list

List the connections in the Workspace.

ork connections list [flags]
FlagShorthandDefaultDescription
--output-otextOutput format: text, json, or yaml.
ork connections list \
  --registry-url "$ORCA_REGISTRY_URL" \
  --access-token "$ORCA_ACCESS_TOKEN" \
  --output json

The text output lists each connection's name, type, phase, and whether it is internal.

ork connections get

Get one connection by name.

ork connections get [name] [flags]
FlagShorthandDefaultDescription
--output-otextOutput format: text, json, or yaml.
ork connections get my-kafka -o yaml

ork connections create

Create a connection. The --name and --type flags are required. The remaining flags depend on the connection type - Pulsar flags apply only to --type pulsar, Kafka flags only to --type kafka, and generic ("other") flags only to --type other. Mixing flags across types fails validation.

ork connections create --name <name> --type <type> [flags]

Common flags

FlagShorthandDefaultDescription
--nameConnection name. Required.
--typeConnection type: pulsar, kafka, or other. Required.
--output-otextOutput format: text, json, or yaml.

Pulsar flags (--type pulsar)

A Pulsar connection requires at least one of --pulsar-service-url or --pulsar-admin-url.

FlagDescription
--pulsar-service-urlPulsar broker service URL.
--pulsar-admin-urlPulsar admin URL.
--pulsar-auth-typeAuth type: none, token, oauth2, or generic.
--pulsar-token-secret-nameKubernetes Secret name for the Pulsar token.
--pulsar-token-secret-keySecret key for the Pulsar token.
--pulsar-oauth2-issuer-urlPulsar OAuth2 issuer URL.
--pulsar-oauth2-audiencePulsar OAuth2 audience.
--pulsar-oauth2-scopePulsar OAuth2 scope.
--pulsar-oauth2-secret-nameKubernetes Secret name for Pulsar OAuth2 credentials.
--pulsar-oauth2-secret-keySecret key for Pulsar OAuth2 credentials.
--pulsar-generic-auth-pluginPulsar generic auth plugin.
--pulsar-generic-auth-paramsPulsar generic auth parameters.
--pulsar-tls-enabledEnable TLS for the Pulsar connection.
--pulsar-tls-allow-insecureAllow insecure TLS for the Pulsar connection.
--pulsar-tls-enable-hostname-verificationEnable TLS hostname verification.
--pulsar-tls-trust-secret-nameKubernetes Secret name for Pulsar TLS trust certs.
--pulsar-tls-trust-secret-keySecret key for Pulsar TLS trust certs.
--pulsar-tls-cert-secret-nameKubernetes Secret name for the Pulsar TLS client certificate.
--pulsar-tls-cert-secret-keySecret key for the Pulsar TLS client certificate.
--pulsar-tls-key-secret-nameKubernetes Secret name for the Pulsar TLS client key.
--pulsar-tls-key-secret-keySecret key for the Pulsar TLS client key.

Kafka flags (--type kafka)

A Kafka connection requires --kafka-bootstrap-servers.

FlagDescription
--kafka-bootstrap-serversKafka bootstrap servers.
--kafka-auth-typeAuth type: none, plain, scram, oauth2, or generic.
--kafka-plain-secret-nameKubernetes Secret name for Kafka plain auth.
--kafka-plain-username-keySecret key for Kafka plain auth username.
--kafka-plain-password-keySecret key for Kafka plain auth password.
--kafka-scram-secret-nameKubernetes Secret name for Kafka SCRAM auth.
--kafka-scram-username-keySecret key for Kafka SCRAM username.
--kafka-scram-password-keySecret key for Kafka SCRAM password.
--kafka-scram-hashKafka SCRAM hash algorithm: sha-256 or sha-512.
--kafka-oauth2-issuer-urlKafka OAuth2 issuer URL.
--kafka-oauth2-audienceKafka OAuth2 audience.
--kafka-oauth2-scopeKafka OAuth2 scope.
--kafka-oauth2-secret-nameKubernetes Secret name for Kafka OAuth2 credentials.
--kafka-oauth2-secret-keySecret key for Kafka OAuth2 credentials.
--kafka-generic-auth-pluginKafka generic auth plugin.
--kafka-generic-auth-paramsKafka generic auth parameters.
--kafka-tls-enabledEnable TLS for the Kafka connection.
--kafka-tls-trust-secret-nameKubernetes Secret name for the Kafka trust store.
--kafka-tls-trust-file-keySecret key containing the Kafka trust store file.
--kafka-tls-trust-password-keySecret key containing the Kafka trust store password.
--kafka-tls-trust-typeKafka trust store type: JKS, PEM, or PKCS12.
--kafka-tls-key-secret-nameKubernetes Secret name for the Kafka key store.
--kafka-tls-key-file-keySecret key containing the Kafka key store file.
--kafka-tls-key-password-keySecret key containing the Kafka key store password.
--kafka-tls-key-key-password-keySecret key containing the Kafka private key password.
--kafka-tls-key-typeKafka key store type: JKS, PEM, or PKCS12.

Generic flags (--type other)

A generic connection requires --other-endpoint.

FlagDescription
--other-endpointEndpoint for the generic connection.
--other-propertyGeneric connection property in key=value format. Repeatable.
--other-secret-nameKubernetes Secret name for the generic connection secret.
--other-secret-keySecret key for the generic connection secret.

Examples

ork connections create \
  --registry-url "$ORCA_REGISTRY_URL" \
  --access-token "$ORCA_ACCESS_TOKEN" \
  --name my-kafka \
  --type kafka \
  --kafka-bootstrap-servers broker:9092

With -o text (the default), create prints a confirmation. With -o json or -o yaml, it fetches and renders the created connection.

ork connections validate

Validate a connection configuration without storing it. validate accepts the same --name, --type, and type-specific flags as create. It prints a confirmation when the Cloud extension accepts the configuration.

ork connections validate \
  --name my-kafka \
  --type kafka \
  --kafka-bootstrap-servers broker:9092 \
  --kafka-auth-type none

ork connections update

Update an existing connection. The --name flag is required and identifies the connection to change. The CLI reads the current configuration, then merges changed flags. To change the connection type, pass --type with the new value and its required endpoint flags.

ork connections update --name <name> [flags]

update accepts the same type-specific flags as create. The --name flag is required; --type is optional and defaults to the existing connection's type.

ork connections update \
  --registry-url "$ORCA_REGISTRY_URL" \
  --access-token "$ORCA_ACCESS_TOKEN" \
  --name my-kafka \
  --kafka-bootstrap-servers broker-1:9092,broker-2:9092

To disable Pulsar TLS, pass --pulsar-tls-enabled=false without any TLS sub-flags:

ork connections update --name my-pulsar --pulsar-auth-type none --pulsar-tls-enabled=false

ork connections delete

Delete a connection by name.

ork connections delete [name]
ork connections delete my-kafka \
  --registry-url "$ORCA_REGISTRY_URL" \
  --access-token "$ORCA_ACCESS_TOKEN"

ork connections test

Test a connection's health. The CLI reports whether the connection is healthy, its phase, the last test time, and any message.

ork connections test [name] [flags]
FlagShorthandDefaultDescription
--output-otextOutput format: text, json, or yaml.
ork connections test my-kafka -o json \
  --registry-url "$ORCA_REGISTRY_URL" \
  --access-token "$ORCA_ACCESS_TOKEN"

What's next

On this page