Eddytor Cloud

How it works

Multi-tenancy, isolation, and security posture of the hosted environment.

Eddytor Cloud is one shared installation of the same open packages you can self-host, on dedicated Hetzner hardware in Falkenstein, Germany.

The tenancy model

Every request carries a caller scope of (user, organisation, workspace); every query, storage listing, and engine session is keyed by it.

  • Organisations are the tenant boundary: members, roles, API keys, policies, invites, and the audit trail are all organisation-scoped.
  • Workspaces subdivide an organisation: shared storage configurations attach to exactly one workspace; a credential bound to workspace A cannot read workspace B's - org Admins must switch workspaces rather than see everything at once.
  • Engine sessions are per (user, organisation, workspace) - DataFusion session, memory budget, and discovered catalog are yours alone.
  • Row & column security policies load per organisation and are enforced inside the engine on every transport (REST, Flight SQL, MCP).

Compute and the metadata database are shared across tenants; table data is not.

Your data

Eddytor Cloud stores metadata, not table data: organisation and user records, table registrations, policies, and the audit log, all in the EU. Your Delta tables live in the bucket you connect, under your own cloud account and IAM, in your chosen region.

What stays where

DataLives in
Your table data (Delta/Parquet files)Your object store, under your cloud account
Table metadata, organisations, users, policies, audit logEddytor Cloud's database (Hetzner, Falkenstein - Germany)
Storage credentials you registerEddytor Cloud's database, encrypted at rest (AEAD)

Self-hosting later needs no export step - point your installation at the same bucket.

Storage credentials are encrypted under an instance-scoped key; delegated (OAuth-linked) access stores no cloud password - each member authenticates as themselves against Azure or Google.

Deleting a user erases the identity and cascades through their personal data; table data is unaffected.

Transport & platform security

  • TLS terminates at the ingress gateway with Let's Encrypt certificates; in-cluster traffic runs over mutual TLS.
  • The database node has no public address - only a private VLAN.
  • Containers run non-root with a read-only root filesystem and all Linux capabilities dropped.
  • Sign-in is passwordless (email links or per-organisation SSO/OIDC); the OAuth 2.1 identity provider issues all tokens.

Hosts

HostPurpose
app.eddytor.comWeb UI
api.eddytor.comREST API, OAuth, /spec - the canonical API origin
mcp.eddytor.comMCP endpoint for AI clients
flight.eddytor.comArrow Flight SQL (gRPC over TLS)

Good to know

Eddytor Cloud is an evaluation environment: a single cluster, no published SLA, shared capacity - see Limits. For production workloads, self-host.

On this page