§33 Loams Flow Connectors: Registry, Capabilities and the Catalog

The connector registry and capability schema; runtimes (native Rust, Iggy's connectors runtime, Camel in `loams-connect`, Debezium Server; Kestra as a companion); envelope and delivery; Arrow/ADBC bulk paths; CDC through Debezium; the 21 ★ connectors; the licence gate; the 200-connector matrix; track CN (D352–D359)

Status: Proposed · 2026-10-01. Source: the owner's drafts "Précis (CDMP, Java stack)", "Top 200 connectors" and "Rollout" (chatdump.md lines 551–628), read as the design of Loams Flow's connector registry, and the owner's direction of 2026-10-01 that event ingestion runs on Apache Iggy and Apache Fluss (§32 D331–D333). This document makes decisions D352–D359 and asks Q348–Q359. It depends on §32 for the envelope (D334), the bridges (D336), Flow routes (D337–D339) and the fabric/ workspace (D343). No code is written by this document.

Names follow §32's owner rulings of 2026-10-01: packages under loams (@loams/* on npm), Go modules under loams.dev/..., CloudEvents types io.loams.dev.<domain>.<name>.v1. Java is deferred: the Camel connector layer stays, as an unmodified Camel runtime driven by generated YAML routes, but any Loams-written Java (a Java SDK, a Kestra plugin, custom Camel processors) waits until the owner lifts the deferral.

Markers are §32's: (verify), (estimate), (read 2026-10-01). "The précis" is the draft's "Précis (CDMP, Java stack)"; "CDMP" there is the draft's name for the canonical event contract, which in Loams is CloudEvents 1.0 (D334).


1. Summary

#DecisionStatus
D352A connector registry in loams-flow: one versioned manifest per connector (connectors/registry/<id>.yaml, schema loams.flow.v1.ConnectorSpec), loaded at start, served by FlowService.ListConnectors/DescribeConnector, and checked by CI (schema, licence, capability tests). A connector instance (credentials, endpoints, tables) is a namespace object; a route (§32 D337) references instancesProposed
D353Every connector declares its capabilities (§4): direction (source, sink), modes (streaming, batch, CDC, webhook, request-reply), delivery per direction, transactional and upsert/delete support, ordering, formats, schema handling, bulk Arrow support, backpressure, auth methods, config schema, secret fields and limits. A route that uses an undeclared capability is refused; a connector's contract tests prove each declared capability (the précis' change 1)Proposed
D354Runtimes, buy first (§5): native Rust connectors in loams-flow for the hot path where Loams has the code or a good crate exists; Iggy's connectors runtime (Rust plugins) where Iggy has the connector; Apache Camel 4.22 for the long tail, run unmodified as loams-connect, driven by generated YAML routes that end in camel-iggy (no Loams-written Java while Java is deferred, owner 2026-10-01); Debezium Server 3.7 (unmodified) for CDC of databases Loams does not bridge itself. Kestra is not a runtime: Resonate is Loams's orchestrator (D210), and Kestra is a companion with a Loams plugin (Q356). Kafka Connect arrives only through Iggy's Kafka gateway (§32 Q331)Proposed
D355One envelope and one delivery contract for every connector (the précis' change 3): sources emit CloudEvents 1.0 with type = io.loams.dev.flow.<connector>.<event>.v1, source = /connectors/<instance>/<resource>, except for input that already is a CloudEvent (Kafka records with valid ce_ headers, Debezium's CloudEvents, CloudEvents webhooks), which keeps its producer's type, source and id (§6), and an id stable across re-reads, so D334's dedup and PK tables make re-delivery harmless; sinks consume CloudEvents and deliver at least once with ce_id as the idempotency keyProposed
D356Bulk data moves as Arrow, never row by row through Camel (the précis' "control plane vs data plane"): batches of 65 536 rows (default), partitioned by a declared key, written by parallel tasks; ADBC (adbc_driver_manager 0.24 with the Apache-2.0 Snowflake, BigQuery, Postgres, SQLite, Flight SQL and DuckDB drivers) for warehouse reads and bulk loads; native drivers for OLTP upserts; JDBC only inside loams-connect; Avro only at Kafka and schema-registry boundaries, Arrow insideProposed
D357CDC is observed, not reinvented (§7): Loams Postgres and WeSQL changes come from Loams's own bridges (D154, §29 D279); external Postgres, MySQL, MariaDB, SQL Server, Oracle, Db2 and MongoDB go through Debezium Server with its HTTP sink posting CloudEvents (Debezium's CloudEvents converter) to loams-fabric ingest; Iggy's postgres_source (logical replication) is the lighter option for Postgres. Current-state tables are Fluss PK tables (Versioned on the source LSN); history is the Iceberg log table; SCD2 is a House view. No triggers; replication-slot lag is monitored and alertedProposed
D358The ★ set is 21 Loams-owned hot-path connectors, each with a fixed runtime (§8), shipped in CN1: the précis' set (Kafka, PostgreSQL, MySQL, Debezium, S3, Iceberg, Parquet/Arrow/Avro, Elasticsearch, ClickHouse, Snowflake and BigQuery via ADBC, HTTP/Webhooks, JDBC), then Kinesis, Redis and OpenTelemetry. CN1's task order is a build order, not a priority order: HTTP/webhooks and the formats come first because the others reuse them; CN1 ships as one release. Phase 2 (CN2) is the remaining P2 connectors through stock Camel and Iggy plugins; phase 3 (CN3) is the long tail through OpenAPI-generated connectorsProposed
D359A licence gate per connector: each manifest names the licence of its runtime component and of every library or driver it loads; CI refuses AGPL, BSL, SSPL, ELv2 and unlicensed dependencies (D11) for anything Loams ships or runs by default; services that are used through their public API (SaaS) are not a licence question. Airbyte (ELv2 platform, mixed connector licences) and Redpanda Connect (Redpanda Community License on part of its connectors) are not runtimesProposed

2. Goals and non-goals

2.1 Goals

  1. Breadth without writing hundreds of adapters (the précis' first line): count unique connectors, reuse Camel's 300-plus components, Iggy's plugins and Debezium, and own only the hot path.
  2. Honest capabilities: a user can see, before running a route, whether a connector is a source or sink, streaming or batch, transactional or not, and which auth it takes.
  3. One envelope (D355) and one bulk path (D356).
  4. Testable: every declared capability has a contract test; the starred set has end-to-end tests against real services in CI.

2.2 Non-goals

  • No Loams-written connector where a maintained Apache-2.0 one exists in Iggy, Camel or Debezium.
  • No JVM in the engine or in loams-fabric: Camel and Debezium run in their own pods.
  • No orchestration layer of Loams's own: schedules, retries and batch flows around connectors are Resonate workflows (D210); Kestra users keep Kestra.
  • Exactly-once claims only where the external system deduplicates.
  • Remote ingress waits for the auth plan. Webhook and OTLP receivers are on ingest's loopback listener (D111), so in CN1 remote providers and collectors cannot reach them, except through a tunnel or reverse proxy the operator runs on the same host (documented as development-only). With the unified auth plan (Q30) they are exposed through the edge (Envoy, D184) with TLS and per-route credentials.

3. Reconciliation with the précis

PrécisLoams
"Camel is the integration layer, Kestra the orchestration layer, CDMP the canonical event contract; everything is Java"Camel is the long-tail runtime (D354), Resonate the orchestrator (D210), CloudEvents the contract (D355); Rust where Loams owns the hot path; Java only in loams-connect and Debezium Server
"Camel and Kestra as one catalog; count unique connectors"The registry is the one catalog (D352); Camel and Kestra columns in Appendix A show who else covers each connector
"Control plane vs data plane: partitioned Arrow batches of ~64K rows"D356
"ADBC/Arrow for warehouses; JDBC or native drivers for OLTP; this includes the MySQL control plane"D356; Loams's own control plane is TiKV (D260), not MySQL
"Arrow internal, Avro at Kafka and serialization boundaries"D356
"WAL/binlog → Debezium → Kafka → Iceberg history + current-state table, SCD2"D357: Debezium → loams-fabric ingest (or Iggy's Kafka gateway later) → Iggy → Fluss PK (current) + Log (history) → Iceberg; SCD2 as a House view
"Warehouse → Elasticsearch: project ~15 fields, then bulk-ingest"A route with a map step projecting the fields, an ADBC source and the Elasticsearch sink (or a Loams collection, which speaks the ES API)
Change 1: per-connector capability declarationsD353
Change 2: only ★ connectors get owned wrappersD358
Change 3: every connector emits and consumes the canonical envelopeD355

4. The capability schema (D353)

apiVersion: loams.flow/v1
kind: Connector
id: kafka                          # [a-z0-9-]{1,48}, unique
name: Apache Kafka
specVersion: 1.0.0                 # of this manifest; bumps on capability changes
category: messaging                # messaging | relational | nosql | search | vector | graph | warehouse | lakehouse
                                   # | object-storage | format | cdc | integration | saas | observability | infra | identity | ai | protocol
priority: P1                       # P1 = CN1 (★), P2 = CN2, P3 = CN3
starred: true
status: preview                    # planned | preview | stable | deprecated
runtime:
  kind: native                     # native | iggy | camel | debezium | openapi
  ref: loams_flow::connectors::kafka   # crate path | Iggy plugin name | Camel URI scheme | Debezium connector class | OpenAPI spec URL
  version: "rdkafka 0.39 / librdkafka 2.x (verify)"
licence:
  component: Apache-2.0
  dependencies: { librdkafka: BSD-2-Clause }
capabilities:
  source:
    streaming: true
    batch: false
    cdc: false
    webhook: false
    resumable: true                # restarts from a committed position
    position: kafka-offsets        # what the source checkpoints
  sink:
    streaming: true
    batch: true
    transactional: false
    upsert: false
    delete: false
    idempotent: true               # the sink itself dedupes retries (Kafka idempotent producer)
  delivery: { source: at_least_once, sink: at_least_once }
  ordering: per_partition          # none | per_key | per_partition | total
  formats: [cloudevents-binary, cloudevents-structured, json, avro, protobuf, bytes]
  schema: { registry: optional, evolution: backward }
  bulk: { arrow: false, max_batch_rows: 65536 }
  backpressure: pull               # pull | push-with-ack | push-rate-limited
auth: [none, sasl-plain, sasl-scram-256, sasl-scram-512, mtls, aws-msk-iam]
config:                            # JSON Schema 2020-12 for an instance's settings
  $ref: schemas/kafka.config.json
secrets: [sasl.password, tls.key_pem]   # resolved through Dapr secret stores (D189); never stored in the instance
envelope:
  emits: io.loams.dev.flow.kafka.record.v1
  consumes: "*"
limits: { max_record_bytes: 16777216 }
conformance: [contract, roundtrip, kill-restart, dup-check]
docs: docs/guides/connectors/kafka.md

Rules:

  1. Refusal. ValidateRoute refuses a route whose from connector lacks the source mode it uses (for example cdc on a polling source), whose to connector lacks upsert when the route upserts, or whose delivery asks for more than the connector declares. The error names the connector, the capability and the manifest version.
  2. Runtime-specific truth. The same system can have different capabilities per runtime (Camel's producer/consumer support, Iggy's source/sink plugins, Kestra's task/trigger split differ); the manifest describes the runtime Loams ships, and Appendix A shows the others.
  3. Tests per capability. conformance lists the suites the connector passes: contract (each declared capability exercised), roundtrip (sink → source returns the events, where both exist), kill-restart (no loss after killing the runtime mid-batch), dup-check (duplicates bounded by the declared delivery), bulk (Arrow path at 1 M rows), cdc (inserts, updates, deletes, DDL, slot or binlog resume).
  4. Versioning. A capability removed or narrowed bumps specVersion's major; routes pinned to the old major keep running until migrated, and ListConnectors shows both.

The protobuf form (proto/loams/flow/v1/connector.proto, FL3/CN1) mirrors the YAML one to one; the YAML is the source and CI checks that both agree.

5. Runtimes (D354)

RuntimeWhat runsWhereSupervised byUsed for
nativeRust connector tasks in loams-fabric flow (loams_flow::connectors::*), leased per instance and partitionloams-fabric podsloams-flow task leases (the worker-lease model of §09 §6, over the metastore's network API)★ hot path: Kafka, Kinesis, webhooks, HTTP, S3, Iceberg, formats, ADBC (Snowflake, BigQuery, Postgres bulk), MySQL/Postgres batch, Redis, OTLP
iggyIggy's connectors runtime (iggy-connectors) with Rust plugins, configured from a generated TOML per instanceits own pods, one runtime per namespace grouploams-flow (renders the config, restarts on change, reads its metrics)Sinks Iggy already has (Elasticsearch, ClickHouse, Postgres, S3, Iceberg, Delta, Doris, InfluxDB, MongoDB, Meilisearch, Quickwit, RabbitMQ, Redshift, HTTP) and the Loams plugins fluss_sink, loams_sink (§32 D336)
camelloams-connect: unmodified Apache Camel 4.22 (Camel Main or Camel Quarkus, decided in CN2 Task 0) running generated YAML-DSL routes, <component> → camel-iggy for sources and camel-iggy → <component> for sinks, with Kamelets as the parameter templatesits own pods (JVM), one per namespace group or per heavy instanceloams-flow (renders routes, applies them through Camel's route-reload or a restart)The long tail (P2/P3) and JDBC ★
debeziumDebezium Server 3.7.0.Final (unmodified), one per source database, HTTP sink → loams-fabric ingest, offsets in its file or Redis store on a PVC (verify the Iggy- or Fluss-backed offset store options)its own podsloams-flow (renders application.properties)CDC of external databases (D357)
openapiA native Rust connector generated from an OpenAPI 3.x spec (polling source with cursors, request sink), with a hand-written manifest for capabilitiesloams-fabricas nativeCN3's long tail of SaaS APIs

Why these and not others:

CandidateLicenceVerdict
Apache Camel 4.22.1 (319 component modules, including camel-iggy since 4.17, camel-clickhouse 4.22, camel-cloudevents, camel-dapr, camel-debezium-*)Apache-2.0Runtime for the long tail
Iggy connectors runtime (iggy_connector_sdk 0.5.0, not published to crates.io)Apache-2.0Runtime; Loams's plugins go upstream
Debezium 3.7.0.Final and Debezium Server (sinks include HTTP, Kafka, Kinesis, Pub/Sub, Pulsar, Redis, NATS, RabbitMQ, Fluss, Qdrant, Milvus, …)Apache-2.0Runtime for CDC
Kestra 2.0.4 (about 190 plugin repositories)Apache-2.0 core; Enterprise Edition proprietaryCompanion, not a runtime: its scheduler, retries and flow state duplicate Resonate (D210, §26), and it needs its own database. Its catalog is a cross-check in Appendix A
Apache Camel Karavan 4.18.1Apache-2.0Designer reference for the Flow UI (§32 D340)
Kafka ConnectApache-2.0Through Iggy's Kafka gateway when it supports consumer groups with offsets (§32 Q331)
AirbyteELv2 platform; connectors under mixed licencesRejected (D359); its open connectors may be read as API references
Redpanda ConnectApache-2.0 core plus the Redpanda Community License on part of the connectorsRejected as a runtime (D359)
Fluvio connectors, VectorApache-2.0, MPL-2.0Not needed: narrower than Iggy's plugins plus Camel

6. Envelope and delivery (D355)

  • Source events. One CloudEvent per record, row change or file. id is derived from the source position so a re-read produces the same id: Kafka "<topic>/<partition>/<offset>"; Debezium the connector's source.lsn/binlog position plus table and key; S3 "<bucket>/<key>@<etag>"; batch reads (ADBC, Postgres/MySQL batch, Iceberg, Parquet objects) "<run-id>/<partition>/<first-row>-<last-row>" for batch-of-rows events, where run-id is the first 16 hex digits of SHA-256(instance ‖ query or object ‖ as-of position: snapshot id, exported snapshot or cursor value), so a retry or a re-read of the same run at the same as-of position yields the same ids, and a later run yields new ones (datacontenttype: application/vnd.apache.arrow.stream). subject is the table, key or path. Extensions: loamsconnector, loamsinstance, and for CDC loamsop (c, u, d, r) and loamslsn.
  • Pass-through. Input that already is a valid CloudEvent keeps its type, source and id (Kafka records with ce_ headers, Debezium CloudEvents, structured CloudEvents webhooks); the connector adds only loamsconnector and loamsinstance. Routes therefore filter on loamsconnector or on the producer's type, never on the io.loams.dev.flow. prefix alone; a manifest that passes events through declares envelope.passthrough: true, and its contract test checks both the pass-through and the wrapped case.
  • Sinks. A sink receives CloudEvents (or Arrow batches for bulk sinks) and maps them per its manifest; HTTP sinks send ce-* headers and Idempotency-Key: <ce_id>; database sinks upsert by the declared key when upsert: true.
  • Positions. A native source commits its position after Iggy (or ingest) acknowledges the batch; Iggy plugins commit Iggy offsets after the sink acknowledges; Debezium commits its offsets after the HTTP sink's 2xx. Every runtime is therefore at-least-once, and D334's dedup key or the target's PK makes it effectively once where the target dedupes.

7. CDC (D357)

Postgres / MySQL / SQL Server / Oracle / Db2 / MongoDB
   │ logical replication · binlog · CDC tables · change streams
   ▼
Debezium Server 3.7 (CloudEvents converter; HTTP sink)  ──or──  Iggy postgres_source (CDC mode)
   │ POST /v1/namespaces/{ns}/fabric/topics/{topic}/events   (structured or batched CloudEvents)
   ▼
loams-fabric ingest (dedup by source + id)  →  Iggy topic <db>.<schema>.<table>
   │ fluss_sink
   ▼
Fluss PK table <table>_current (Versioned on loamslsn; deletes on loamsop = d)   +   Fluss Log table <table>_history
   │ tiering
   ▼
Iceberg (current + history)  →  House: SELECT … FINAL, SCD2 view over history (valid_from = ts, valid_to = next ts per key)
  • Loams Postgres (§28) and WeSQL (§29) use Loams's own change bridges (D154) into collections; a route can forward those changes to the Fabric through the iggy link target (§32 D336).
  • Snapshots use Debezium's incremental snapshots (signal table), which emit loamsop = r.
  • Monitoring: replication-slot lag in bytes and seconds, Debezium's MilliSecondsBehindSource, and an alert when retained WAL passes a threshold (default 10 GiB, (estimate)), because an abandoned slot fills the source's disk.
  • Schema changes flow as Debezium schema-change events into the DLQ-free <db>.schema_changes topic; the route either evolves the Fluss table (additive) or pauses with an error (incompatible), as links do (§09 §4).

8. The ★ set (D358)

#ConnectorDirectionRuntime and implementationCN1 task
1Kafkasource, sinknative: rdkafka 0.39 (MIT; librdkafka BSD-2-Clause, static build) with consumer groups; sink with the idempotent producer6
2PostgreSQLsource (batch), sink (upsert)native: tokio-postgres COPY … TO STDOUT (FORMAT binary) → Arrow for batch reads, ADBC Postgres driver for bulk loads; Iggy postgres_sink for streaming sinks7
3MySQLsource (batch), sink (upsert)native: mysql_async (MIT/Apache-2.0) chunked SELECT by key range, INSERT … ON DUPLICATE KEY UPDATE batches7
4Debezium-Postgressource (CDC)debezium: Debezium Server → ingest8
5Debezium-MySQLsource (CDC)debezium: Debezium Server → ingest8
6S3source, sinknative: object_store 0.14 listing with a high-water key and SQS/S3-event notifications; sink through Iggy s3_sink or native Parquet writer9
7Icebergsource, sinknative source: iceberg-rust 0.10 incremental snapshot scans; sink: Fluss tiering for Fabric tables, Iggy iceberg_sink for raw topics9
8Parquetformatnative: parquet 58/595
9Avroformatnative: apache-avro (Apache-2.0); Confluent wire format (magic byte + schema id) when a registry is configured5
10Arrow IPC / Flightformat, source, sinknative: arrow-ipc, arrow-flight (Flight DoGet source, DoPut sink, including Loams's own Flight SQL)5
11Elasticsearchsource, sinkiggy: elasticsearch_source, elasticsearch_sink (also reaches Loams collections through their ES API)10
12ClickHousesource, sinkiggy: clickhouse_sink; native source over HTTP with clickhouse (Apache-2.0) in ArrowStream format; Loams House is itself a ClickHouse endpoint10
13Snowflakesource, sink (bulk)native: ADBC Snowflake driver (Apache-2.0, loaded by adbc_driver_manager 0.24)11
14BigQuerysource, sink (bulk)native: ADBC BigQuery driver (Apache-2.0)11
15ADBC (generic)source, sink (bulk)native: any ADBC driver the namespace's admin allows (Flight SQL, SQLite, DuckDB, Postgres)11
16HTTP/RESTsource (polling), sinknative: reqwest sink with retries and Idempotency-Key; polling source with cursors (Iggy http_source as an alternative)4
17Webhookssourcenative: loams-fabric ingest signed-webhook routes (HMAC SHA-256; GitHub, Stripe, Slack, Shopify schemes)4
18JDBCsource, sinkcamel: jdbc/sql components in loams-connect; bulk reads through Arrow's JDBC adapter (verify the Java packaging)12
19Kinesissource, sinknative: aws-sdk-kinesis (Apache-2.0), enhanced fan-out optional13
20Redissource (Streams), sinknative: redis crate (BSD-3-Clause) with consumer groups on Streams; SET/HSET/XADD sinks13
21OpenTelemetrysourcenative: OTLP/HTTP and OTLP/gRPC receiver in loams-fabric ingest, one CloudEvent per log record, span or metric point (type io.loams.dev.flow.opentelemetry.<signal>.v1)13

Rollout: CN1 the 21 above; CN2 every P2 row of Appendix A through stock Camel components (loams-connect) or Iggy plugins, each with a manifest and contract tests; CN3 the P3 rows, most through OpenAPI-generated native connectors. CN2 and CN3 are not planned yet.

9. CN1 exit gate

  • Every ★ connector has a manifest that validates, a licence that passes D359, and its conformance suites green in CI against real services (containers for Kafka, Postgres, MySQL, Debezium, RustFS as S3, Lakekeeper, Elasticsearch, ClickHouse, Redis, LocalStack-free Kinesis through floci (D60), and recorded fixtures for Snowflake and BigQuery plus a nightly job against real accounts when credentials exist).
  • End to end: Postgres CDC through Debezium into a Fluss PK table and a Loams collection, with inserts, updates, deletes and a Debezium restart, equals the source table; a 10 M-row Snowflake (fixture) or Postgres read through ADBC lands as Arrow batches in a Fluss Log table in under the budget measured in CN1 Task 0.
  • loams-fabric connectors list|describe|validate and the generated catalog page docs/guides/connectors/index.md.

10. Where it lives (open core)

All of §33 is open source (D220): self-hosters need connectors. loams-connect (YAML route templates and configuration for the unmodified Camel runtime) lives in this repository under connect/ with a path-filtered CI job, or in its own repository (Q353). loam-platform adds the managed fleet: per-tenant connector pods, autoscaling, plan limits on connector count and throughput, the hosted secrets UI, connector metering (through the usage hooks, §27).

11. Risks

#RiskLikelihoodImpactMitigation
CN-R1Capabilities in Appendix A drift from what the runtime really doesHighMediumCapabilities are proven by contract tests (D353 rule 3); the Camel and Kestra columns are regenerated from their catalogs (CN1 Task 2)
CN-R2Camel's JVM footprint per tenantMediumMediumloams-connect per namespace group; Camel Quarkus native images evaluated in CN2
CN-R3Debezium Server per database multiplies podsMediumLowIggy postgres_source for small Postgres sources; one Debezium Server can host several connectors only through Kafka Connect, which waits for Q331
CN-R4ADBC drivers are shared libraries built in Go or C++ that must match the platformMediumMediumPinned driver builds with SHA-256 in the image; a load test per platform (Q349)
CN-R5camel-iggy is a Preview componentMediumMediumContract tests on every Camel bump; contribute fixes upstream; native fallback for P2 connectors that matter
CN-R6SaaS APIs change and rate-limitHighLowOpenAPI-generated connectors are regenerated; rate limits declared in manifests
CN-R7Secrets leak through connector logs or configsLowHighSecrets only through Dapr secret stores (D189), redacted in rendered configs; a test greps rendered configs for secret values

12. Open questions

#QuestionOwnerNeeded by
Q348rdkafka (librdkafka, C build) or a pure-Rust client for the Kafka ★ connector; rskafka 0.6 lacks consumer groupsEngCN1 Task 0
Q349Shipping ADBC drivers (Snowflake and BigQuery are Go builds, verify) inside the loams-fabric image: licences, NOTICE and platform buildsEngCN1 Task 0
Q350Debezium Server's offset and schema-history stores: file on a PVC, Redis, or a Fluss/Iggy-backed store contributed upstreamEngCN1 Task 8
Q351Iggy postgres_source (CDC mode) as the default for Postgres, with Debezium for the rest, or Debezium everywhere for one behaviourEngCN1 Task 8
Q352Camel Main or Camel Quarkus (JVM or native) for loams-connectEngCN2 Task 0
Q353loams-connect's home: connect/ in this repository, or its own repositoryFounderCN1 Task 12
Q354Instance credentials: per namespace through Dapr secret components (D189), or Loams-vended short-lived credentials where the provider supports them (AWS STS, GCP WIF)EngUnified auth plan
Q355Which P2 connectors move into CN1 if a launch customer needs themFounderCN1 start
Q356Publish a Kestra plugin for Loams (tasks for House queries, Fabric produce, route control) so Kestra users can drive Loams. Deferred with Java (owner, 2026-10-01): a Kestra plugin is Java codeFounderWhen Java is un-deferred
Q357Contribute Loams's native connectors (Kafka, ADBC, Kinesis) to Iggy's connectors runtime as plugins, so one Rust connector set serves bothFounderAfter CN1
Q358OpenAPI-generated connectors (CN3): the generator (progenitor, Apache-2.0/MIT, or openapi-generator), and how cursors and webhooks are declared beside the specEngCN3 plan
Q359Connector metering hooks (§27): which counters (events, bytes, API calls) the platform needs per instanceFounderBefore the cloud beta

13. Sources

All read on 2026-10-01: github.com/apache/camel tag camel-4.22.1 (components/ and the camel-aws, camel-azure, camel-google, camel-debezium, camel-ai, camel-salesforce module lists; components/camel-iggy/src/main/docs/iggy-component.adoc; components/camel-clickhouse/src/main/docs/clickhouse-component.adoc); github.com/kestra-io plugin repositories (193 plugin-* repositories; module lists of plugin-jdbc, plugin-aws, plugin-gcp, plugin-azure, plugin-notifications, plugin-serdes, plugin-fs); github.com/kestra-io/kestra v2.0.4 README; github.com/debezium/debezium v3.7.0.Final and github.com/debezium/debezium-server (module list); github.com/apache/iggy core/connectors/{sdk,sinks,sources} and postgres_source/README.md; crates.io: adbc_core and adbc_driver_manager 0.24.0 (arrow ≥ 58, < 60), rdkafka 0.39.0, rskafka 0.6.0, sqlparser 0.63.0; github.com/adbc-drivers/{snowflake,bigquery} (Apache-2.0); github.com/supabase/etl (Apache-2.0, a Rust Postgres replication library, a candidate for Q351); github.com/airbytehq/airbyte (licence NOASSERTION, ELv2 platform); github.com/redpanda-data/connect (no single SPDX licence). Loams: §02 §7.4, §09, §21, §24 (D184, D189), §26 (D210), §27, §28, §29, §32, docs/open-core.md.


Appendix A. The connector matrix

Columns: Source / Sink — the connector reads from / writes to the system. Streaming — continuous, low-latency delivery. Batch — bulk or scheduled transfer. CDC — row-level change capture. Webhook — receives (as a source) or sends (as a sink) webhooks. Auth — the methods the Loams manifest will declare: none, basic (user and password), key (API key or token), oauth2, jwt, hmac (signed payloads), mtls, sasl (PLAIN/SCRAM), iam (AWS), sa (GCP service account or workload identity), aad (Entra ID), ssh, kerb (Kerberos), cs (connection string). Camel — the Camel 4.22.1 component(s) that cover it, or ·. Kestra — the Kestra plugin (and sub-module) that covers it, or ·. Priority — P1 = ★ (CN1), P2 = CN2 (stock Camel or Iggy plugins), P3 = CN3 (long tail, OpenAPI-generated). Y = yes, · = no.

The Camel and Kestra columns were filled from the component and plugin lists read on 2026-10-01; the capability cells are the planned manifest values and are (verify) until each connector's contract tests pass (D353 rule 3). CN1 Task 2 generates this table from the registry and fails CI if they disagree.

A.1 Messaging and streaming (20)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
★ KafkaYYY···sasl, mtls, iamkafkaplugin-kafkaP1
RedpandaYYY···sasl, mtlskafkaplugin-kafkaP2
RabbitMQ / AMQPYYY···basic, mtlsamqpplugin-amqpP2
ActiveMQ / JMSYYY···basic, mtlsactivemq, jms, sjms2plugin-jmsP2
NATSYYY···key, jwt, mtlsnatsplugin-natsP2
PulsarYYY···jwt, oauth2, mtlspulsarplugin-pulsarP2
MQTTYYY···basic, mtlspaho-mqtt5, pahoplugin-mqttP2
AWS SQSYYY···iamaws2-sqsplugin-aws (sqs)P2
AWS SNS·YY··Yiamaws2-snsplugin-aws (sns)P2
★ KinesisYYY···iamaws2-kinesisplugin-aws (kinesis)P1
EventBridgeYYY··Yiamaws2-eventbridgeplugin-aws (eventbridge)P2
Google Pub/SubYYY··Ysagoogle-pubsubplugin-gcp (pubsub)P2
Azure Event HubsYYY···aad, csazure-eventhubsplugin-azure (eventhubs)P2
Azure Service BusYYY···aad, csazure-servicebusplugin-azure (servicebus)P2
Azure Event GridYYY··Yaad, keyazure-eventgrid·P2
Redis StreamsYYY···basic, mtlsredisplugin-redisP2
WebSocketYYY···key, jwtvertx-websocket, atmosphere-websocket·P2
SSEY·Y···key, jwt··P3
★ WebhooksYYY··Yhmac, keywebhook, platform-httpcore (Webhook trigger)P1
gRPCYYY···mtls, jwtgrpc·P2

A.2 Relational (16)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
★ PostgreSQLYYYYY·basic, mtls, iamsql, jdbc, pg-replication-slot, debezium-postgresplugin-jdbc (postgres), plugin-debeziumP1
★ MySQLYYYYY·basic, mtls, iamsql, jdbc, debezium-mysqlplugin-jdbc (mysql), plugin-debeziumP1
MariaDBYYYYY·basic, mtlssql, jdbcplugin-jdbc (mariadb), plugin-debeziumP2
SQL ServerYYYYY·basic, aadsql, jdbc, debezium-sqlserverplugin-jdbc (sqlserver), plugin-debeziumP2
OracleYYYYY·basic, kerbsql, jdbc, debezium-oracleplugin-jdbc (oracle), plugin-debeziumP2
SQLiteYY·Y··nonesql, jdbcplugin-jdbc (sqlite)P3
CockroachDBYYYYY·basic, mtlssql, jdbcplugin-jdbc (postgres)P2
TiDBYYYYY·basic, mtlssql, jdbcplugin-jdbc (mysql)P3
YugabyteDBYYYYY·basic, mtlssql, jdbcplugin-jdbc (postgres)P3
AuroraYYYYY·basic, iamsql, jdbc, debezium-postgres, debezium-mysqlplugin-jdbcP2
AlloyDBYYYYY·basic, sasql, jdbc, debezium-postgresplugin-jdbc (postgres)P3
Azure SQLYYYYY·basic, aadsql, jdbc, debezium-sqlserverplugin-jdbc (sqlserver)P2
Cloud SQLYYYYY·basic, sasql, jdbcplugin-jdbcP3
Db2YYYYY·basicsql, jdbc, debezium-db2plugin-jdbc (db2)P3
SingleStoreYY·Y··basicsql, jdbcplugin-jdbc (mysql)P3
VitessYYYYY·basic, mtlssql, jdbcplugin-jdbc (mysql)P3

A.3 NoSQL, search, vector and graph (20)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
MongoDBYYYYY·basic, mtlsmongodb, debezium-mongodbplugin-mongodbP2
CassandraYY·Y··basic, mtlscqlplugin-cassandraP2
ScyllaDBYY·Y··basic, mtlscqlplugin-scylladbP3
DynamoDBYYYYY·iamaws2-ddb, aws2-ddbstreamplugin-aws (dynamodb)P2
★ RedisYYYY··basic, mtlsredisplugin-redisP1
ValkeyYYYY··basic, mtlsredisplugin-redisP2
CouchbaseYYYY··basiccouchbaseplugin-couchbaseP3
FirestoreYYYY··sagoogle-firestoreplugin-gcp (firestore)P3
Cosmos DBYYYYY·aad, keyazure-cosmosdb·P3
★ ElasticsearchYYYY··basic, keyelasticsearch, elasticsearch-rest-clientplugin-elasticsearchP1
OpenSearchYYYY··basic, iamopensearchplugin-opensearchP2
SolrYY·Y··basicsolr·P3
Meilisearch·YYY··key·plugin-meilisearchP3
Typesense·Y·Y··key·plugin-typesenseP3
QdrantYY·Y··keyqdrant·P2
Pinecone·Y·Y··keypineconeplugin-pineconeP3
Weaviate·Y·Y··keyweaviateplugin-weaviateP3
Milvus·Y·Y··basic, keymilvus·P3
pgvectorYY·Y··basicpgvectorplugin-jdbc (postgres)P2
Neo4jYY·Y··basicneo4jplugin-neo4jP2

A.4 Warehouse, lakehouse, OLAP and compute (20)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
★ SnowflakeYY·Y··key, oauth2, basicsql, jdbcplugin-jdbc (snowflake)P1
★ BigQueryYYYY··sagoogle-bigqueryplugin-gcp (bigquery)P1
RedshiftYY·Y··basic, iamaws2-redshift, sqlplugin-jdbc (redshift)P2
DatabricksYY·Y··oauth2, keysql, jdbcplugin-databricksP2
★ ClickHouseYYYY··basicclickhouse, sqlplugin-jdbc (clickhouse)P1
DuckDBYY·Y··noneduckdbplugin-jdbc (duckdb)P2
DruidYYYY··basic·plugin-jdbc (druid)P3
PinotYYYY··basic·plugin-jdbc (pinot)P3
StarRocksYYYY··basicsql, jdbcplugin-jdbc (mysql)P3
DorisYYYY··basicsql, jdbcplugin-jdbc (mysql)P3
TrinoY··Y··basic, jwt, oauth2sql, jdbcplugin-jdbc (trino)P2
AthenaY··Y··iamaws2-athenaplugin-aws (athena)P3
Synapse / FabricYY·Y··aadsql, jdbcplugin-azure (synapse), plugin-microsoft-fabricP3
★ IcebergYYYY··iam, sa, oauth2·plugin-icebergP1
Delta LakeYY·Y··iam, sa·plugin-databricksP2
HudiYY·Y··iam··P3
HiveYY·Y··kerb, basicsql, jdbc·P3
SparkYY·Y··none·plugin-sparkP3
Flink·Y·Y··noneflinkplugin-flinkP3
TeradataYY·Y··basicsql, jdbc·P3

A.5 Object storage and files (10)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
★ S3YYYY·Yiamaws2-s3plugin-aws (s3)P1
MinIO / RustFSYY·Y·Ykeyminio, aws2-s3plugin-minioP2
Cloudflare R2YY·Y··keyaws2-s3plugin-cloudflareP2
GCSYYYY·Ysagoogle-storageplugin-gcp (gcs)P2
Azure BlobYYYY·Yaad, keyazure-storage-blobplugin-azure (storage)P2
ADLS Gen2YY·Y··aadazure-storage-datalakeplugin-azure (storage)P2
SFTPYY·Y··ssh, basicsftpplugin-fs (sftp)P2
FTP / FTPSYY·Y··basicftp, ftpsplugin-fs (ftp, ftps)P3
SMB / NFSYY·Y··basic, kerbsmb, fileplugin-fs (smb, nfs)P3
Local FS / HDFSYY·Y··none, kerbfileplugin-fs (local)P3

A.6 Formats (6)

Formats are codecs used by other connectors; "Source" and "Sink" mean decode and encode.

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
★ ParquetYY·Y··noneparquet-avroplugin-serdes (parquet)P1
★ AvroYYYY··noneavro, jackson-avroplugin-serdes (avro)P1
ORCYY·Y··none··P3
CSV / NDJSONYYYY··nonecsv, jacksonplugin-serdes (csv, json)P2
★ Arrow IPC / FlightYYYY··none, mtls, jwt·plugin-jdbc (arrow-flight)P1
ProtobufYYYY··noneprotobuf, jackson-protobufplugin-serdes (protobuf)P2

A.7 CDC (6)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
★ Debezium-PostgresY·Y·Y·basic, mtlsdebezium-postgresplugin-debeziumP1
★ Debezium-MySQLY·Y·Y·basic, mtlsdebezium-mysqlplugin-debeziumP1
Debezium-SQL Server / OracleY·Y·Y·basicdebezium-sqlserver, debezium-oracleplugin-debeziumP2
Debezium-MongoDBY·Y·Y·basicdebezium-mongodbplugin-debeziumP2
Debezium Embedded engineY·Y·Y·basicdebezium-* (embedded)plugin-debeziumP3
DynamoDB StreamsY·Y·Y·iamaws2-ddbstreamplugin-aws (dynamodb)P2

A.8 Integration and orchestration (6)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
Camel (runtime)YYYY·Yper component(itself)plugin-camelP1
Kestra (companion)YY·Y·Ykey, basic·(itself)P2
Kafka ConnectYYY·Y·sasl, mtlskafka·P3
Airbyte (licence flag, D359)YY·YY·key·plugin-airbyteP3
dbt·Y·Y··none·plugin-dbtP3
AirflowY··Y·Ybasic·plugin-airflowP3

A.9 CDP, marketing, analytics and ads (22)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
SegmentYYY··Ykey··P2
RudderStackYYY··Ykey··P3
mParticleYYY··Ykey··P3
BrazeYYYY·Ykey··P3
IterableYYY··Ykey··P3
KlaviyoYY·Y·Ykey·plugin-klaviyoP3
MailchimpYY·Y·Ykey, oauth2··P3
SendGridYYY··Ykey·plugin-notifications (sendgrid)P2
Amazon SESYYY··Yiamaws2-ses·P2
Twilio SMSYYY··Ykeytwilioplugin-notifications (twilio)P2
WhatsApp BusinessYYY··Yoauth2whatsappplugin-notifications (whatsapp)P3
FCM·YY···sa··P3
APNs·YY···jwt, mtls··P3
OneSignal·YY···key··P3
Customer.ioYYY··Ykey··P3
AmplitudeYYYY··key··P3
MixpanelYYYY··key, basic··P3
PostHogYYYY·Ykey·plugin-posthogP2
GA4YYYY··sa, key··P3
Meta Ads / CAPIYYYY·Yoauth2·plugin-metaP3
Google AdsYY·Y··oauth2··P3
LinkedIn AdsYY·Y··oauth2·plugin-linkedinP3

A.10 CRM, sales and support (12)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
SalesforceYYYYYYoauth2salesforce·P2
HubSpotYY·Y·Yoauth2, key·plugin-hubspotP2
PipedriveYY·Y·Ykey, oauth2·plugin-pipedriveP3
ZohoYY·Y·Yoauth2··P3
Dynamics 365YY·Y·Yaadolingo4·P3
ZendeskYY·Y·Ykey, oauth2zendeskplugin-zendeskP2
IntercomYY·Y·Ykey··P3
FreshdeskYY·Y·Ykey··P3
ServiceNowYY·Y·Ybasic, oauth2servicenowplugin-servicenowP2
MarketoYY·Y··oauth2··P3
GainsightYY·Y··key··P3
GongY··Y·Ykey, oauth2··P3

A.11 Commerce and payments (8)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
StripeYY·Y·Ykey, hmacstripeplugin-stripeP2
ShopifyYY·Y·Yoauth2, key, hmac·plugin-shopifyP2
WooCommerceYY·Y·Ykey··P3
MagentoYY·Y·Yoauth2··P3
BigCommerceYY·Y·Ykey··P3
PayPalYY·Y·Yoauth2··P3
RazorpayYY·Y·Ykey, hmac··P3
AdyenYY···Ykey, hmac··P3

A.12 Developer and collaboration (14)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
GitHubYY·Y·Yoauth2, key, hmacgithub2plugin-githubP2
GitLabYY·Y·Ykey, oauth2·plugin-gitlabP2
BitbucketYY·Y·Yoauth2, key··P3
JiraYY·Y·Ybasic, oauth2jiraplugin-jiraP2
LinearYY·Y·Ykey, oauth2·plugin-linearP3
ConfluenceYY·Y·Ybasic, oauth2·plugin-confluenceP3
NotionYY·Y·Ykey, oauth2·plugin-notionP3
SlackYYY··Yoauth2, hmacslackplugin-slack, plugin-notifications (slack)P2
Microsoft TeamsYY···Yaad·plugin-notifications (teams)P3
DiscordYY···Ykey·plugin-discordP3
Google WorkspaceYY·Y·Yoauth2, sagoogle-drive, google-sheets, google-mail, google-calendarplugin-googleworkspaceP2
Microsoft 365YY·Y·Yaadmail-microsoft-oauth, olingo4plugin-microsoft365P3
AirtableYY·Y·Ykey·plugin-airtableP3
TelegramYYY··Ykeytelegramplugin-telegramP3

A.13 Observability and incident (10)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
PrometheusYYY···basic, key·plugin-prometheusP2
Grafana·Y···Ykey·plugin-grafanaP3
DatadogYYY··Ykey··P3
New Relic·YY··Ykey··P3
★ OpenTelemetryYYY···key, mtls··P1
LokiYYY···basic··P3
SplunkYYYY··keysplunk, splunk-hec·P2
SentryY····Ykey·plugin-sentryP3
PagerDutyYY···Ykey·plugin-pagerdutyP3
CloudWatchYYYY··iamaws2-cwplugin-aws (cloudwatch)P3

A.14 Infrastructure and runtime (8)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
KubernetesYYY···sa, mtlskubernetesplugin-kubernetesP3
DockerYYY···mtlsdockerplugin-dockerP3
Terraform·Y·Y··none·plugin-terraformP3
Ansible·Y·Y··ssh·plugin-ansibleP3
Lambda / Cloud Run / Azure FunctionsYYY··Yiam, sa, aadaws2-lambda, google-functions, azure-functionsplugin-aws (lambda), plugin-gcp (function), plugin-azure (function)P2
VaultYY····keyhashicorp-vault·P2
Helm / Argo CD·Y·Y·Ykey·plugin-helm, plugin-argocdP3
SSH / ShellYY·Y··sshssh, execplugin-fs (ssh), plugin-scriptsP3

A.15 Identity (4)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
OktaYY·Y·Yoauth2, key··P3
Auth0YY·Y·Yoauth2··P3
KeycloakYY·Y·Yoauth2keycloak·P2
Entra IDYY·Y·Yaad··P3

A.16 AI (10)

AI connectors are mostly sinks used as enrichment steps (embedding, classification, extraction) inside a route, with the result written back into the event.

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
OpenAI·Y·Y··keyopenai, langchain4j-*plugin-openaiP2
Anthropic·Y·Y··keylangchain4j-*plugin-anthropicP2
Gemini·Y·Y··key, sagoogle-vertexai, langchain4j-*plugin-geminiP3
Bedrock·Y·Y··iamaws-bedrockplugin-aws (bedrock)P3
Azure OpenAI·Y·Y··aad, keylangchain4j-*plugin-azure (aifoundry)P3
Ollama·Y·Y··nonelangchain4j-*plugin-ollamaP3
vLLM·Y·Y··keylangchain4j-*·P3
Hugging Face·Y·Y··keyhuggingfaceplugin-huggingfaceP3
MCPYY····oauth2mcp-serverplugin-aiP2
A2AYYY···oauth2a2a·P3

A.17 Generic protocols (8)

ConnectorSourceSinkStreamingBatchCDCWebhookAuthCamelKestraPriority
★ HTTP / RESTYYYY·Ynone, basic, key, oauth2, jwt, mtlshttp, restcore (HTTP tasks)P1
GraphQLYY·Y··key, oauth2graphqlplugin-graphqlP2
SOAPYY·Y··basiccxf, soap·P3
OpenAPI-generatedYY·Y·Yper specrest-openapi·P3
★ JDBCYY·Y··per driverjdbc, sqlplugin-jdbcP1
★ ADBCYY·Y··per driver··P1
SMTP / IMAPYYY···basic, oauth2mailplugin-notifications (mail), plugin-emailP3
RSS / AtomY·Y···nonerss, atom·P3

Totals: 200 connectors; 21 ★ (P1), and the P2 and P3 counts are computed by CN1 Task 2's generator.

On this page