Data + Agent Hackathon: hello world, on StreamNative Cloud · about 40 minutes
You build an agent whose context is a live Kafka stream, kept fresh by streaming SQL, and that asks a human before it acts. Everything runs in your own instance on StreamNative Cloud.
Aegis Financial, a fictional bank, streams every login attempt into Kafka. Somewhere in that stream, an attacker is guessing passwords. Your agent spots them from live data, and flags the account once you say so.
flowchart LR
K["Kafka topic<br/>security.login_events"] --> S["SQL Workspace<br/>materialized view<br/>login_failures"]
J["inject<br/>(you, in Lab 3)"] -- "new login burst" --> K
S -- "StreamNative MCP<br/>sql_workspace_query" --> A["Orca agent<br/>hello-agent-<you>"]
A -- "sql_workspace_insert_rows<br/>(only if you approve)" --> F["SQL table<br/>flagged_accounts"]
| Lab | Time | Where | You | The idea |
|---|---|---|---|---|
| 0. Set up | 10 min | terminal | Fill in .env from your instance, load the topic, run the doctor |
Check service access before you build on it |
| 1. Hello, agent | 5 min | CLI / Python / TS | Create an agent and chat | Agent, environment, session, events |
| 2. Hello, streaming SQL | 8 min | SQL Workspace | Build a materialized view over the topic | Context that keeps itself fresh |
| 3. Agent + live context | 9 min | CLI / Python / TS | Give the agent SQL tools, inject new data | The answer changes with the data |
| 4. Agent acts, human approves | 5 min | CLI / Python / TS | Let the agent write, with your OK | Governed actions |
The times are for the steps. Each lab also has a short quiz and a task to try on your own.
- A login to StreamNative Cloud, in the hackathon organization, with an instance of your own and a service account in it (its name and API key). The organizers set these up.
- In your instance, a Kafka cluster, an agent workspace, and a SQL workspace that imports the Kafka cluster.
- One path installed, plus
ork,jq, andsnctl. All of this is in Before you arrive.
Start with Lab 0: Set up. If something goes wrong, see Troubleshooting. How labs and checks work is in The labs, and a coding agent can tutor you through the course.
No StreamNative Cloud instance? Take the Local course: the same labs, on your laptop.
These pages were rewritten on 2 October 2026 and run against one test instance
on StreamNative Cloud that night, with snctl 1.8.0 and ork 0.6.0. The Kafka
cluster was Serverless; the SQL workspace ran RisingWave 3.1.0-alpha.
- Lab 0: every
snctllookup, the topic, the seeder, and the doctor, on the Python path. On the TypeScript path, the doctor, and the seeder against the topic once it was loaded. - Lab 2: every statement and check, through
psql. The console was not used. - Labs 1, 3 and 4: every step and check, on all three paths, with the model answering: the injected account showing up, one insert approved and one denied. On the CLI path the first Lab 4 run gave up after five minutes: the Agent Engine acted on the approval eight minutes after it was given. The second run passed.
- Not run on this course: the "Try it yourself" tasks, which were run on the Local course, and the clean-up at the end of Lab 4.