Skip to content

[FEATURE]: Create External Location, Catalog, Schema ACL for Principals based on Interactive cluster permission using instance profiles #1193

@HariGS-DB

Description

@HariGS-DB

Is there an existing issue for this?

  • I have searched the existing issues

Problem statement

Currently Users access interactive clusters using instance profile configured which has permission on the underlying was bucket.
When migrating to UC, we need to create permission to interactive clusters users on the external location, catalog and schema based on the underlying instance profile access on the buckets
Related issues:

#887

Proposed Solution

identify interactive clusters with instance profile configured.
check instance profile permission on the underlying buckets
grant appropriate permission on the external location to the users of the interactive clusters
grant use permission on the catalog and schema equivalent tin UC for the users of the interactive clusters

Additional Context

No response

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

Status

No status

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions