Bridge configuration reference
Every key in kimo-bridge.yaml: bridge identity, sources and modes, allow-lists, row filters, limits, caching and audit, with environment variables.
Updated Oct 9, 20266 min readEdit on GitHub
The bridge reads one YAML file, by default /etc/kimo-bridge/kimo-bridge.yaml (override with KIMO_BRIDGE_CONFIG). It lives on your server; Kimo shows a read-only copy in the Bridge console but can never edit it.
Complete example
kimo-bridge.yaml
bridge: name: fra-prod-01 group: prod-eu region: eusources: - id: finance_pg type: postgres dsn_file: /run/secrets/finance_dsn mode: bridge cache_ttl: 0s policy: default: deny tables: analytics.invoices: columns: [id, account_id, amount_cents, currency, paid_at] analytics.accounts: columns: [id, region, plan, mrr_cents, created_at, churned_at] row_filters: - "accounts.region IN ('EU', 'UK')" min_group_size: 5 limits: max_rows: 50000 timeout: 30s rate: 10/s - id: events_ch type: clickhouse dsn_file: /run/secrets/events_dsn mode: cloud sync: interval: 15m policy: default: deny tables: events.page_views: columns: [ts, session_id, path, utm_source, utm_campaign]audit: path: /var/lib/kimo-bridge/audit.jsonl mirror_to_kimo: truebridge
| Key | Default | Description |
|---|---|---|
name | hostname | Display name in the console; must be unique in the workspace |
group | default | Bridges in a group serve the same sources and share load |
region | required | eu or us; must match the workspace region |
sources[]
| Key | Default | Description |
|---|---|---|
id | required | Stable identifier shown in Kimo and in audit entries |
type | required | postgres, mysql, sqlserver, oracle, mongodb, clickhouse, snowflake, bigquery, redshift, kafka, elastic, files |
dsn_file | required | Path to a file holding the connection string; prefer it over dsn |
mode | bridge | bridge, cloud or hybrid |
cache_ttl | 5m | Kimo-side result cache for bridge mode; 0s disables it |
sync.interval | 15m | Sync cadence for cloud and hybrid modes |
sources[].policy
| Key | Default | Description |
|---|---|---|
default | deny | Only deny is accepted; listed tables are the whole surface |
tables.<schema.table>.columns | none | Allow-listed columns. Others are invisible to Kimo |
row_filters | [] | SQL predicates appended to every query on that source |
min_group_size | 1 | Suppresses aggregate rows built from fewer source rows |
limits.max_rows | 50000 | Hard cap on rows returned per query |
limits.timeout | 30s | Cancels queries that run longer |
limits.rate | 10/s | Queries per second accepted from Kimo for this source |
Environment variables
| Variable | Purpose |
|---|---|
KIMO_BRIDGE_CONFIG | Path to the YAML file |
KIMO_BRIDGE_TOKEN_FILE | Path to the one-time enrollment token (or KIMO_BRIDGE_TOKEN) |
KIMO_BRIDGE_LOG_LEVEL | debug, info (default), warn or error |
HTTPS_PROXY / NO_PROXY | Outbound proxy; it must allow CONNECT without TLS interception |
