> ## Documentation Index
> Fetch the complete documentation index at: https://docs.cedarai.com/llms.txt
> Use this file to discover all available pages before exploring further.

# CDC delivery

> Have Cedar push a snapshot and ongoing change batches of Locations or Waybills as Parquet files to Azure or Amazon S3.

**CDC delivery** (change data capture) keeps a copy of a Cedar data product in your own cloud storage. Cedar first writes a
full snapshot, then pushes the changes as Parquet files on a schedule you choose: every 5, 10, or 15 minutes. You load
the files into your data lake or lakehouse, for example with the [Cedar Databricks notebook](/user-docs/data-depot/databricks).

Choose CDC delivery when you want full control of the data. The data lands in storage you own, and you decide its
retention and who can access it. Your reports then run on your own SLA, not on Cedar's Postgres service. See
[Postgres views or CDC delivery?](/user-docs/data-depot/postgres#postgres-views-or-cdc-delivery) for a comparison.

<Info>
  CDC delivery is an **EU pilot**. Today you can subscribe only for carriers on Cedar's EU production environment. For
  other carriers, the Delivery page explains this, keeps existing deliveries visible, and turns off **Subscribe to
  CDC**.

  **Want CDC delivery in the US?** We're happy to make it available. Contact Cedar sales to discuss your requirements.
  Meanwhile, [Postgres views](/user-docs/data-depot/postgres) and [API clients](/user-docs/data-depot/api-clients) are
  available for every carrier.
</Info>

<Frame caption="The Delivery page with destination options and existing deliveries">
  <img src="https://mintcdn.com/cedaraiinc/lSug5iB_PqnlGPPV/images/data-depot/delivery-hub.png?fit=max&auto=format&n=lSug5iB_PqnlGPPV&q=85&s=6c435bdf1bb8607022f6208f9ace7877" alt="Delivery Method page with Azure, S3, and Product CDC path cards" width="1440" height="900" data-path="images/data-depot/delivery-hub.png" />
</Frame>

## What you can deliver

| Data product | Contents |
| - | - |
| **Locations** | Your carrier's location hierarchy and location template attributes, including deleted locations |
| **Waybills** | Waybill records covering the fields in the ARMS All Waybills grid |

Each subscription delivers one data product to one destination.⁠​​‌​​‌​​‌‌‌​​‌‌​​‌​‌‌‌​​⁠ Deliveries include the full default set of columns for
that product.

What CDC delivery doesn't do:

* Cedar never writes to your Delta or Iceberg tables or their logs. It writes files; you load them.
* Destination credentials are accepted once, when you set up or rotate them, and never shown again.
* For live SQL queries instead of files, use [Postgres views](/user-docs/data-depot/postgres).
* Snowflake data sharing is still configured in ARMS Settings.

## Prepare your destination

Create a place for Cedar to write, and a credential that lets it write there. Cedar checks the credential when you
subscribe by writing, reading, and deleting a small test file under `.cedar-validate/` inside your prefix.

<Tabs>
  <Tab title="Azure Blob / ADLS Gen2">
    1. Create a container (or pick an existing one) and, if you like, a folder prefix for Cedar, such as `cedar`.
    2. Create a **container SAS token** with an expiry date that grants read, add, create, write, delete, and list
       (`racwdl`) permissions on the container.
    3. Have the container's HTTPS URL ready, for example `https://demorailanalytics.blob.core.windows.net/cedar-landing`.

    Data Depot reads the SAS token's expiry date and warns you before it runs out. See
    [Rotate the destination credential](#rotate-the-destination-credential).
  </Tab>

  <Tab title="Amazon S3">
    1. Create a bucket (or pick an existing one) and, if you like, a prefix for Cedar, such as `cedar`.
    2. Create an IAM user with an access key that allows `s3:PutObject`, `s3:GetObject`, and `s3:DeleteObject` under
       that prefix.
    3. Have the bucket name, its region, and the access key ID and secret access key ready.

    AWS access keys don't have an expiry date, so the delivery shows **Credential expiry: Not provided**. Follow your own
    rotation policy for the key.
  </Tab>
</Tabs>

## Subscribe

<Steps>
  <Step title="Open the form">
    Open **Delivery** in the sidebar and select **Subscribe to CDC**.
  </Step>

  <Step title="Name the delivery and pick the data">
    Enter a **Name** that's unique for the carrier, choose the **View** (Locations or Waybills), and choose the
    **Delivery interval**: every 5, 10, or 15 minutes.
  </Step>

  <Step title="Enter the destination">
    Choose **Azure Blob / ADLS Gen2** and enter the **Container HTTPS URL**, an optional **Base prefix**, and the
    **Container SAS token**. Or choose **Amazon S3** and enter the **Bucket**, **Region**, an optional **Prefix**, the
    **Access key ID**, and the **Secret access key**.

    <Frame caption="Subscribing Waybills to an Azure container">
      <img src="https://mintcdn.com/cedaraiinc/lSug5iB_PqnlGPPV/images/data-depot/delivery-subscribe.png?fit=max&auto=format&n=lSug5iB_PqnlGPPV&q=85&s=7664f930ef86281143315cc4bf80a8d7" alt="Subscribe to Product CDC form with name, view, delivery interval, and Azure destination fields" width="1440" height="900" data-path="images/data-depot/delivery-subscribe.png" />
    </Frame>
  </Step>

  <Step title="Create the subscription">
    Select **Create subscription**. Data Depot checks the destination, and Cedar starts writing the snapshot.
  </Step>
</Steps>

<Note>
  For a carrier's first subscription, Data Depot may ask you to **retry in a few minutes** while Cedar prepares delivery.
  Wait a few minutes and submit again.
</Note>

If the destination check fails, the subscription is created but waits for a working credential. Fix the access in Azure
or AWS, then return to **Delivery** and select **Rotate credential** on that subscription to run the check again.

## Track your deliveries

The **CDC deliveries** list on the Delivery page shows each subscription with its destination type, data product,
interval, credential expiry, and status.

<Frame caption="CDC deliveries with a credential that expires soon">
  <img src="https://mintcdn.com/cedaraiinc/lSug5iB_PqnlGPPV/images/data-depot/delivery-subscriptions.png?fit=max&auto=format&n=lSug5iB_PqnlGPPV&q=85&s=7e3b89729f56002b27d99f9407945da0" alt="CDC deliveries list showing an Azure delivery expiring in 21 days and an S3 delivery" width="1440" height="900" data-path="images/data-depot/delivery-subscriptions.png" />
</Frame>

| Status | Meaning |
| - | - |
| **pending validation** | Cedar is checking the destination, or is waiting for a working credential |
| **snapshotting** | The destination works and Cedar is writing the first full snapshot |
| **waiting for route** | Cedar is still preparing delivery for this carrier |
| **live** | The snapshot is delivered and change batches are flowing on schedule |
| **action required** | Delivery stopped and needs you, usually because the destination credential stopped working |
| **paused** | Delivery is paused |
| **deleted** | The subscription was deleted and Cedar no longer delivers |

## Subscription details

Select a delivery to open its details page.

<Frame caption="A live delivery's details">
  <img src="https://mintcdn.com/cedaraiinc/lSug5iB_PqnlGPPV/images/data-depot/delivery-subscription-detail.png?fit=max&auto=format&n=lSug5iB_PqnlGPPV&q=85&s=98f0f85eedde7aef4e33d551c0021876" alt="Subscription details with overview, destination, and Databricks ingestion sections" width="1440" height="900" data-path="images/data-depot/delivery-subscription-detail.png" />
</Frame>

| Field | What it tells you |
| - | - |
| **Generation** | The version of the data product's layout this subscription uses. It stays the same for the life of the subscription |
| **Generation path** | Where this subscription's files are written, relative to your container or prefix |
| **Snapshot delivered** | When the first full snapshot finished. Load nothing until this has a time |
| **Last delivered** | When Cedar last delivered a change batch |
| **Through sequence** | The latest change included in delivered files. It goes up as changes arrive |
| **Validated** | When Cedar last confirmed it can write to the destination |

The **Destination** section shows the container URL or bucket details. Secrets aren't shown. The
**Databricks ingestion** section gives you the exact path to load from, and links to the notebook and its guide.

<Frame caption="Copy the base path and download the Databricks notebook">
  <img src="https://mintcdn.com/cedaraiinc/lSug5iB_PqnlGPPV/images/data-depot/delivery-databricks-ingestion.png?fit=max&auto=format&n=lSug5iB_PqnlGPPV&q=85&s=2053f8c8876a1178b1e01227a1edb0e5" alt="Databricks ingestion, Columns, Delivery interval, and Stop delivery sections" width="1440" height="900" data-path="images/data-depot/delivery-databricks-ingestion.png" />
</Frame>

### Change the interval

Under **Delivery interval**, pick a new **Push every** value and select **Save interval**. Cedar keeps capturing changes
the whole time; the interval only controls how often files are pushed.

### Change the columns

Columns are fixed for a subscription.⁠​​‌​​‌​​‌‌‌​​‌‌​​‌​‌‌‌​​⁠ To deliver a different set, create a new subscription.

### Stop delivery

Under **Stop delivery**, select **Delete subscription** and confirm. Cedar stops writing to the destination. Files
already in your storage are not deleted.

## Rotate the destination credential

On the Delivery page, **Rotate credential** appears under a delivery when its credential expires within 30 days, or the
delivery shows **action required** or **pending validation**. The badge turns from **Expires in N days** to critical within 7 days, and to
**Credential expired** after the expiry date.

<Frame caption="Replace an Azure SAS token">
  <img src="https://mintcdn.com/cedaraiinc/lSug5iB_PqnlGPPV/images/data-depot/delivery-rotate-credential.png?fit=max&auto=format&n=lSug5iB_PqnlGPPV&q=85&s=d583f3e8abd062e06a735081425ed9b6" alt="Rotate credential dialog with the container URL and a new SAS token field" width="1440" height="900" data-path="images/data-depot/delivery-rotate-credential.png" />
</Frame>

<Steps>
  <Step title="Create the new credential">
    Create a new SAS token, or a new AWS access key, with the same permissions as before.
  </Step>

  <Step title="Rotate">
    Select **Rotate credential**, paste the new **Container SAS token** (Azure) or the **Access key ID** and **Secret
    access key** (S3), and select **Rotate credential**.
  </Step>

  <Step title="Let Cedar check it">
    Cedar checks the new credential before it resumes delivery. Remove the old credential in Azure or AWS once the
    delivery is **live** again.
  </Step>
</Steps>

## File layout

Cedar writes each subscription's files under this path inside your container or bucket, after your optional prefix:

```text theme={null}
cedar-cdc/v1/subscription=<subscription-id>/generation=<generation>
```

The first snapshot and each change batch come with a `manifest.json`, which Cedar writes **after** the Parquet files it
describes. A batch is complete only once its manifest exists.

<Warning>
  Don't point Auto Loader or another file watcher straight at the Parquet folders: you could read a batch before it's
  complete. Load by manifest, as the [Cedar Databricks notebook](/user-docs/data-depot/databricks) does.
</Warning>

## Troubleshooting

<AccordionGroup>
  <Accordion title="Subscribe to CDC is turned off">
    CDC delivery is an EU pilot, available today only for carriers on Cedar's EU production environment.⁠​​‌​​‌​​‌‌‌​​‌‌​​‌​‌‌‌​​⁠ Check the
    carrier selected in the sidebar. For a US carrier, contact Cedar sales; we're happy to discuss making CDC delivery
    available for you.
  </Accordion>

  <Accordion title="Destination check did not succeed">
    Check that the SAS token or access key hasn't expired and has the permissions listed in
    [Prepare your destination](#prepare-your-destination), and that the URL, bucket, region, and prefix are right. Then
    select **Rotate credential** on the subscription to check again.
  </Accordion>

  <Accordion title="The name is already used">
    Subscription names must be unique for each carrier. Pick a different name.
  </Accordion>

  <Accordion title="A delivery shows action required">
    The destination credential usually stopped working, for example because the SAS token expired. Rotate the credential.
  </Accordion>
</AccordionGroup>

## Related pages

* [Load deliveries into Databricks](/user-docs/data-depot/databricks)
* [Postgres views](/user-docs/data-depot/postgres)
* [Access and permissions](/user-docs/data-depot/access)


## Related topics

- [Postgres views](/user-docs/data-depot/postgres.md)
- [Use Cedar data in Databricks](/user-docs/data-depot/databricks.md)
- [Choosing the right option](/user-docs/data-depot/choosing.md)
- [Cedar Data Depot](/user-docs/data-depot/overview.md)
- [Access and permissions](/user-docs/data-depot/access.md)
