# Snowflake

> Connect a Snowflake account with a key pair or a programmatic access token, see its usage-based cost, suspend warehouses on a schedule, and act on Snowflake cost recommendations.

Source: https://zop.dev/docs/zopnight/concepts/snowflake

---

Snowflake bills by the credit, and a warehouse that stays resumed overnight burns credits whether or not anyone queries it. ZopNight connects to your Snowflake account, discovers its warehouses and storage objects, prices them from your own usage data, suspends warehouses outside working hours, and flags Snowflake configuration that costs more than it needs to.

![Settings → Cloud Accounts with a Snowflake account card showing key-pair authentication and a Read + Write permission level, next to the AWS, GCP, Azure, Databricks, OpenShift and Microsoft 365 accounts](https://storage.googleapis.com/zopdev-blog-resources/1/files/originals/20260924/5a6a666b-11f6-459e-a2b5-5b094a5fa900-newsnowflake.png)

*Settings → Cloud Accounts: a Snowflake account connected with key-pair authentication, alongside the other cloud accounts.*

## Before you start

- **ZopNight permission:** `cloud-account:create`, which the built-in **Admin** role has.
- **A Snowflake user for ZopNight** that signs in with either a **key pair** (the public key registered on the user) or a **programmatic access token (PAT)**.
- **A role for that user** that can read the `SNOWFLAKE.ACCOUNT_USAGE` views and run `SHOW` commands on the objects you want discovered. ZopNight reads cost and inventory from these.
- **To suspend and resume warehouses on a schedule:** the same role must be able to suspend and resume those warehouses, and the account must be connected at the **Read + Write** permission level. See [Read-only vs read + write](https://zop.dev/docs/zopnight/cloud-setup/cloud-accounts#read-only-vs-read--write).
- **Your Snowflake account host.** ZopNight reads the underlying cloud (AWS, GCP, or Azure) from it, so there is no cloud to pick.

## How it works

Snowflake is a standalone connection. It does not ride an AWS, GCP, or Azure cloud account, even though your Snowflake account runs on one. ZopNight reads inventory and usage from `SNOWFLAKE.ACCOUNT_USAGE` and `SHOW` queries, and changes nothing in the account except suspending and resuming warehouses you schedule.

### What gets discovered

ZopNight discovers nine Snowflake resource types. Five are top-level; the other four sit under the database that holds them.

| Type | Level | Notes |
|---|---|---|
| `account` | Top-level | The Snowflake account itself |
| `warehouse` | Top-level | Virtual warehouses; the only type you can start and stop |
| `database` | Top-level | Parent of tables, materialized views, stages, and pipes |
| `user` | Top-level | Snowflake users |
| `resource-monitor` | Top-level | Credit quotas attached to warehouses or the account |
| `table` | Under its database | The schema is part of the resource ID |
| `materialized-view` | Under its database | The schema is part of the resource ID |
| `stage` | Under its database | Stages used for loading data |
| `pipe` | Under its database | Snowpipe ingestion pipes |

Everything shows in the standard [Inventory](https://zop.dev/docs/zopnight/concepts/resources) view with the rest of your estate.

### How cost is calculated

Snowflake cost is usage-based:

- **Compute:** warehouse credits consumed, multiplied by the credit rate for your Snowflake edition.
- **Storage:** active bytes per table.

ZopNight reconciles these figures against your own `SNOWFLAKE.ACCOUNT_USAGE` billing views, so the totals match what Snowflake reports for the account.

## Connect an account

**Open the wizard**

  Go to **Settings → Cloud Accounts → Add Cloud Account** and pick **Snowflake**.

**Choose the auth method**

  Pick **Key-pair JWT** or **PAT** and enter the account and credential details the wizard asks for.

**Verify**

  ZopNight checks the credential against Snowflake before it saves the account. If the check fails, nothing is saved and the wizard shows the reason.

The connected account appears on **Settings → Cloud Accounts** next to your other accounts.

## Suspend warehouses on a schedule

Warehouses use the same [schedules, groups, and overrides](https://zop.dev/docs/zopnight/concepts/scheduling) as VMs and clusters.

| Schedule action | What ZopNight runs |
|---|---|
| **Stop** | `ALTER WAREHOUSE ... SUSPEND` |
| **Start** | `ALTER WAREHOUSE ... RESUME` |

Suspending a warehouse stops credit consumption and keeps its configuration, so a resume brings back the same warehouse. Only warehouses are schedulable; databases, tables, and the other types are read-only.

## Snowflake recommendations

Twenty rules run against Snowflake warehouses, tables, materialized views, pipes, stages, and the account. They are part of the main rule catalogue, not a separate set. What they catch:

| Object | What the rules flag |
|---|---|
| **Warehouses** | Auto-suspend unset, zero, or over 120 seconds; idle (credits burned with no queries over 14 days); oversized or undersized for the load; under-utilised (active under 4 hours a day); minimum or maximum cluster count set wider than the load needs; statement timeout left at the 48-hour default; no resource monitor attached; missing team, cost-centre, or environment tags. |
| **Tables** | Time Travel retention longer than needed; large Fail-safe on permanent tables; Auto-Clustering or Search Optimization that costs more than the queries it speeds up. |
| **Materialized views** | Refresh cost higher than the query benefit. |
| **Pipes** | Snowpipe ingesting many small files. |
| **Stages** | No COPY in over 30 days. |
| **Account** | A premium edition worth reviewing. |

Two of these 20 rules, for large cold tables and for a steady baseline that may suit capacity pricing, need 90 days of history. They are in the catalogue but do not raise findings yet.

Five of these carry a dollar saving, priced on the same credit rate as your cost data: idle warehouse, oversized warehouse, Auto-Clustering, Search Optimization, and materialized-view refresh. The rest are advisory configuration changes with no computed saving. If ZopNight cannot price a finding, it does not raise a zero-dollar recommendation.

You make these changes in Snowflake. ZopNight does not change warehouse, table, or account settings. The Snowflake rules cover cost only, and there are no Snowflake security or compliance rules. See the [rule catalogue](https://zop.dev/docs/zopnight/optimization/recommendation-rules#snowflake) for the full list.

## Troubleshooting

**The wizard**

  ZopNight checks the credential against Snowflake before saving, and nothing is saved on failure. Use the reason the wizard shows, check the key pair or PAT registered on the Snowflake user and the account details you entered, then retry.

**A warehouse on a schedule doesn**

  Two things are needed: the account at the **Read + Write** permission level, and a Snowflake role that can suspend and resume that warehouse. A read-only account gets discovery, cost, and recommendations only.

**I can**

  Only warehouses are schedulable. Databases, tables, and the other Snowflake types are read-only.

**There are no Snowflake security findings**

  The Snowflake rules cover cost only. There are no Snowflake security or compliance rules.

## Next steps

**Scheduling**

    Suspend warehouses outside working hours.

**Snowflake rules**

    The full list of Snowflake rules.

**Cloud accounts**

    Manage the Snowflake connection and its permission level.

**Recommendations**

    Review and act on findings across your estate.
