Kimo Bridge overview
What Kimo Bridge is, how the outbound-only tunnel works, and how to choose between Bridge, Cloud and Hybrid mode for each source.
Updated Oct 9, 20265 min readEdit on GitHub
Kimo Bridge is a small package, kimo-bridge, that you run next to your database. It opens one outbound, mutually authenticated TLS connection to Kimo and keeps it open. Kimo sends queries down that connection; the bridge checks them against a local policy, runs them under a read-only role and returns the results. You open no inbound ports and Kimo never holds your database credentials. The product page at /bridge has an animated walkthrough.
Architecture
- 1Enrollment. On first start the bridge generates a key pair on your host and exchanges a one-time
kbt_token for a short-lived client certificate. The private key never leaves the host. - 2Tunnel. The bridge dials
bridge.eu.getkimo.comorbridge.us.getkimo.comon TCP 443 and negotiates TLS 1.3 with mutual authentication. - 3Query. A dashboard tile, alert or Ask Kimo question compiles to SQL in Kimo’s semantic layer and is pushed down the open tunnel as a signed request.
- 4Policy. The bridge parses the SQL, rejects anything that is not a read, checks every table and column against the allow-list, appends row filters and applies limits.
- 5Execution. The query runs on your database under the role you created. Aggregations happen there, so usually only a handful of rows come back.
- 6Audit. The bridge appends an entry to its local, hash-chained audit log and mirrors it to Activity.
Bridge, Cloud and Hybrid mode
Each source behind a bridge has its own mode. You can mix them freely and change a source with one line and a kimo-bridge reload.
| Mode | What crosses the tunnel | What Kimo stores | Use it for |
|---|---|---|---|
bridge | Pushed-down queries and their results | Nothing persistent; an optional result cache with the TTL you set (cache_ttl, 0s disables it) | Finance ledgers, product databases with personal data, regulated workloads |
cloud | Incremental changes of allowed tables | Allowed tables, encrypted, in your workspace region | Events, marketing data, long history, heavy exploration |
hybrid | Rollups on a schedule, plus live drill-down queries | Pre-aggregated rollups only | Board metrics whose row-level detail must stay home |
Supported sources
- PostgreSQL
- MySQL
- SQL Server
- Oracle
- MongoDB
- ClickHouse
- Snowflake
- BigQuery
- Amazon Redshift
- Apache Kafka
- Elastic Security
- CSV / Excel
Next steps
- Install the bridge with Docker, Helm or the static binary.
- Read the configuration reference for every
kimo-bridge.yamlkey. - Share Bridge security with your security team, or the long-form security model guide.
