JDBC Connector

Connect Zluri with Application Database

Zluri with a JDBC database

JDBC (Java Database Connectivity) is a standard interface for connecting to RDBMS databases. Many organisations store user accounts, roles, and permissions in databases such as PostgreSQL, MySQL, Oracle, and SQL Server that run inside their own network and are not reachable over the internet.


🤝Zluri + JDBC

Zluri connects to a database inside your network to help you discover, manage, and secure user access held in systems that have no public API.

With this integration, you can:

  • Sync accounts, roles, and permissions from a database into Zluri.
  • Run multiple queries per database and map each one to the Zluri entity it feeds.
  • Keep your Zluri inventory up to date with scheduled syncs that need no action on the agent.

Connecting Zluri to a database inside your network uses the Zluri JDBC On-Prem Agent, a lightweight Docker-based service deployed on a server in your network with a full Web UI for configuration.

You'll:

  1. Choose or download an agent in Zluri — Select an existing agent, or download a new agent package and copy the registration token.
  2. Deploy via Docker — Load the Docker image and start the agent on a server within your network.
  3. Create an account and register — Access the Web UI, create an admin account, and connect the agent to Zluri using the token.
  4. Add a database connection — Configure your database details (type, host, port, database name, JDBC driver, credentials, TLS mode) and add the queries the agent will expose.
  5. Configure the connector in Zluri — Select the database, map each query to a Zluri entity, map fields, and validate before the connector goes live.

🐞**Troubleshooting**

Problems connecting? Find solutions to most common integration issues in our troubleshooting document.


Architecture

The Zluri JDBC Agent uses an outbound-only communication model. It sits within your intranet, connects to your database over JDBC, and polls Zluri's cloud servers over HTTPS to check for tasks and push sync data. No inbound firewall rules are required.

How it works:

  • Zluri Servers ←(HTTPS Polling)← Zluri JDBC Agent →(JDBC/TLS)→ Database
  • The agent runs as a Docker container with an internal database, accessible via a secure Web UI on HTTPS (default port 8080, or 5001 depending on the build).
  • It only makes outbound calls, polling Zluri for pending tasks and executing the configured queries against your database.

Configuration Options

The Zluri JDBC Agent provides a Web UI (accessible at https://<HOST>:<PORT>/ui) with these main sections:

  • Dashboard — Monitor agent health, registration status, number of database connections, and the last sync.
  • Database Connections — Configure your database connection (type, host or IP, port, database name, max pool size, JDBC driver JAR upload), authentication credentials, and TLS mode.
  • Database Queries — Add the SQL queries the connection exposes, preview the top 100 rows returned, and manage saved queries. Query names must be unique across all database connections.
  • Logs — View agent activity and troubleshoot issues.

Entity mapping happens in the Zluri platform. Supported entities are Accounts, Roles, Permissions, Account Roles, and Role Permissions. Account Roles requires Accounts and Roles. Role Permissions requires Roles and Permissions.


TLS Modes

TLS modeMeaning
Required — enforce TLSThe connection must be encrypted. Recommended.
Preferred — TLS if offeredThe connection uses TLS when the database offers it, and falls back to plaintext otherwise.
Disabled — plaintextThe connection is not encrypted.

System Requirements

RequirementSpecification
CPU Cores8 Core (minimum 4 Core)
RAM16 GB (minimum 8 GB)
Storage50 GB available
Operating SystemAny modern OS — Linux, Windows Server 2022+, or macOS (Docker required)
DockerDocker 20.10+ with Docker Compose v2 (or v1)
Internet ConnectivityYes (outbound HTTPS to Zluri servers)
Ports RequiredDefault 8080 or configured port (TCP). No inbound ports need to be opened.
Database ConnectivityNetwork access from the Docker host to your database on its host and port
JDBC DriverThe .jar driver for your database type, uploaded to the agent

On Windows Server, Docker Desktop is not supported. Install Docker Engine and enable WSL 2 to run Linux containers. On Windows desktop builds, Hyper-V and WSL 2 should be enabled.


Security

  • The agent admin password is stored hashed on the agent host and never leaves it.
  • The agent connects to Zluri over an outbound-only, encrypted connection.
  • Zluri recommends enforcing TLS on the database connection so data between the agent and your database is encrypted in transit.
  • The database user only needs read access to the tables you want to sync.

Got questions? Feel free to submit a ticket or contact us directly at [email protected].


Did this page help you?