Use this skill when converting Dagster code that references resources holding credentials (ConfigurableResource subclasses, EnvVar, integration resources like SnowflakeResource / S3Resource / DbtCliResource, or resources wired into Definitions) to Orchestra. Triggers: any Dagster resource that stores host/login/token/key, any EnvVar used for credentials, or environment-specific resource configuration. Must be read before finalising any Orchestra YAML that contains a connection: field.
Dagster stores credentials in resources — typically ConfigurableResource subclasses (or built-in integration resources like SnowflakeResource, S3Resource, DbtCliResource) wired into Definitions(resources={...}), with secret values supplied via EnvVar. Orchestra connections serve the same purpose but are configured in the Orchestra UI (Settings -> Connections) and referenced by name in pipeline YAML. This skill maps common Dagster resources to their Orchestra equivalents and covers naming, environment patterns, and secrets.
connection: my_snowflake_12345 # format: descriptive-name_XXXXX (5-digit suffix from UI)The 5-digit suffix is assigned by Orchestra when the connection is created — copy it from the UI; never invent it.
No resource referenced? If the @op/@asset doesn't actually instantiate a credentialed resource — pure computation, no external client, no secrets — don't invent a connection name or a fake env var placeholder just to fill the field:
connection: null # no distinct resource in the source; Orchestra uses the workspace default for this integrationOnly set a specific name_XXXXX or ${{ ENV.VAR }} when the source code actually references a distinct resource/credential.
This extends to task parameters that duplicate connection-level scope, too — e.g. Power BI's workspace_id, or any other parameter whose value is also stored on the Orchestra connection itself. If the source code just reads the same single value everywhere (one env var, one resource-level config field) rather than genuinely varying it per task, leave that parameter null/omitted and let the connection's own configured value apply. Only carry an explicit value through (literal, input, or ${{ ENV.VAR }}) when a specific task truly needs to override it — e.g. targeting a different Power BI workspace than the one configured on the connection.
For environment-specific connections:
connection: ${{ ENV.SNOWFLAKE_CONNECTION_NAME }}Set SNOWFLAKE_CONNECTION_NAME=my_snowflake_12345 in Orchestra's environment settings.
| Dagster resource | Orchestra connection type | Key fields |
|---|---|---|
PostgresResource / dagster-postgres | Postgres | host, port, database, user, password |
SnowflakeResource (dagster-snowflake) | Snowflake | account, warehouse, database, role, user, password/key pair |
DatabricksClientResource (dagster-databricks) | Databricks | host (workspace URL), token |
BigQueryResource (dagster-gcp) | GCP Big Query | service account JSON |
S3Resource (dagster-aws) | AWS | access key ID, secret, region |
ADLS2Resource (dagster-azure) | Azure | tenant, client ID, client secret |
MSSQL via pyodbc | SQL Server | host, port, database, user, password |
RedshiftClientResource (dagster-aws) | AWS Redshift | host, port, database, user, password |
MotherDuckResource (dagster-motherduck) | MotherDuck | token |
| Dagster resource | Orchestra connection type | Notes |
|---|---|---|
AirbyteCloudResource | Airbyte Cloud | API key |
AirbyteResource(host=,port=) | Airbyte Server | host URL + API key |
FivetranResource | Fivetran | API key + secret |
DbtCliResource / DbtProject | dbt Core | Git repo URL + branch + warehouse creds |
CensusResource | Census | API token |
HightouchResource | Hightouch | API key |
HexResource | Hex | API token |
| Dagster resource | Orchestra connection type | Notes |
|---|---|---|
SlackResource | Slack | Bot Token (xoxb-...) or Incoming Webhook |
PagerDutyService (dagster-pagerduty) | PagerDuty | integration key |
MSTeamsResource (dagster-msteams) | Microsoft Teams | Incoming Webhook URL |
| email / SMTP | SMTP host, port, login, password |
| Dagster resource | Orchestra connection type | Notes |
|---|---|---|
SSHResource (dagster-ssh) | Linux SSH | host, port, username, private key |
SSHResource (Windows OpenSSH) | Windows SSH | host, port, username, key/password |
SFTPResource / sftp_resource | SFTP | host, port, username, key or password |
requests in an @asset (HTTP) | HTTP | base URL, optional auth headers |
TableauCloudWorkspace | Tableau Cloud | server URL, site, PAT |
Never hardcode credentials in YAML. All credentials go in the Orchestra connection — the YAML references only the connection name.
# Correct
task-001:
integration: SNOWFLAKE
integration_job: SNOWFLAKE_RUN_QUERY
connection: snowflake_prod_12345
parameters:
statement: 'SELECT 1'For secrets fetched at runtime, use AWS_SECRETS_MANAGER or AZURE_KEY_VAULT as a preceding task that sets an output, then reference it downstream.
pipeline:
stage-001:
tasks:
task-001:
integration: SNOWFLAKE
integration_job: SNOWFLAKE_RUN_QUERY
connection: ${{ ENV.SNOWFLAKE_CONN }}
parameters:
statement: 'SELECT * FROM orders LIMIT 10'In Orchestra: Settings -> Environments -> set SNOWFLAKE_CONN=snowflake_dev_11111 in dev and snowflake_prod_22222 in prod. This mirrors how Dagster swaps resources per deployment/environment.
Non-credential config (a table name, an environment flag) supplied via EnvVar or a Config field should become inputs::
# Dagster
class Cfg(Config):
target_table: str = "orders"# Orchestra
inputs:
target_table:
type: string
default: orders
pipeline:
stage-001:
tasks:
task-001:
parameters:
statement: 'SELECT * FROM ${{ inputs.target_table }}'connection: <name> with the real name${{ ENV.VAR }}connection: snowflake_prod fails; use snowflake_prod_12345.AirbyteCloudResource -> Cloud connection; AirbyteResource(host=,port=) -> Server connection.EnvVar — secrets -> connection; non-secret config -> inputs:.3a29fe4
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.