-
Notifications
You must be signed in to change notification settings - Fork 101
[FEATURE]: Migrate AWS IAM Instance Profiles to UC Storage Credentials #862
Copy link
Copy link
Closed
Labels
enhancementNew feature or requestNew feature or requestfeat/account-levelcross-workspace installationscross-workspace installationsmigrate/externalgo/uc/upgrade SYNC EXTERNAL TABLES stepgo/uc/upgrade SYNC EXTERNAL TABLES step
Description
Is there an existing issue for this?
- I have searched the existing issues
Problem statement
Many customers are using the AWS Instance Profiles, and we need to ensure that the relevant UC Storage Credential exists to map onto an instance profile.
Related issues:
- Create EXTERNAL LOCATIONs to map to External Tables (Azure) #100
- [FEATURE]:
databricks labs ucx uc-compatible-rolesfor AWS #861 - Added baseline for getting Azure Resource Role Assignments #764
- Add
databricks labs ucx create-uber-principalcommand to automate the creation of SPN with storage access to all locations #693 - Migrate Azure Service Principals that access storage to UC Storage Credentials #339
Proposed Solution
- check all instance profiles
- check all storage credentials
- see which instance profiles have matching storage credentials
- report what credentials are missing
- prompt-confirm creation of storage credential from instance profile
- prompt for trust relationship between an instance profile and UC for prod environment
- give user three options: terraform config, invoke AWS CLI, pick an existing role
Additional Context
No response
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requestfeat/account-levelcross-workspace installationscross-workspace installationsmigrate/externalgo/uc/upgrade SYNC EXTERNAL TABLES stepgo/uc/upgrade SYNC EXTERNAL TABLES step
Type
Projects
Status
No status