User defined groups and blue prints in Lake Formation

0

Hi
We are currently investigating Lake Formation and it looks promising.
There are a few things which we can't figure out to do. Either because we don't know how or because they are not yet developed for Lake Formation

  1. User defined groups
    We cannot see our IAM groups in the grant permission to data access.
    We have a large group of analysts divided into different divisions. We would like to give a specific access to each division, but not having the overhead of doing this for each analyst. I can only find the "everyone" group, which doesn't suit our needs

  2. User defined blueprints
    Currently the number of blueprints is limited to databases and cloudtrail-logs. It would be a nice feature to be able to create your own blueprints in order to recreate userdefined datalake ingestions.

I don't know if anyone has some workarounds for these issues or there is a wish-list somewhere to propose new features

Best and Thanks

질문됨 5년 전499회 조회
2개 답변
0

Thanks for using AWS Lake Formation and for the feedback. Both permissions for IAM groups and user defined blueprints are not yet supported, but the team is aware of these product requests.

In the meantime, a workaround for groups is to create a role to which you grant Lake Formation and querying permissions, then allow members of the IAM group to assume that role. Remember that when they assume the role, they only have that role's permissions. See here:
https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_permissions-to-switch.html

Remember to make the AWS account from which you are calling AssumeRole a trusted entity for the role:
https://docs.aws.amazon.com/IAM/latest/UserGuide/troubleshoot_roles.html#troubleshoot_roles_cant-assume-role

AWS
답변함 5년 전
0

Thank you
Guess this was our conclusion too

답변함 5년 전

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠