借助 Lakehouse 运行时目录,您可以在无边界 Lakehouse 中为目录端点启用凭据分发模式。
凭证分发模式会向授权的查询引擎和工作负载分发短期、降权存储令牌。此身份验证方法无需您或查询运行时对底层 Cloud Storage 存储桶拥有直接的读取和写入权限。
准备工作
- 请参阅关于 Lakehouse 运行时目录,了解 Lakehouse 运行时目录的工作原理以及该服务的限制。
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles. - Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
所需的角色
如需获得启用凭据自动售卖所需的权限,请让您的管理员为您授予以下 IAM 角色:
- 全部:
- 针对项目的 BigLake Admin (
roles/biglake.admin) 角色 - 您项目的 Storage Admin (
roles/storage.admin)
- 针对项目的 BigLake Admin (
-
自动预配的 Apache Iceberg REST 目录服务账号:所有关联的 Cloud Storage 存储桶上的 Storage Object User (
roles/storage.objectUser)。启用凭据自动发放后,请向目录的自动预配 Apache Iceberg REST Catalog 服务账号明确授予所有关联存储桶的 Storage Object User 角色 (roles/storage.objectUser)。
如需详细了解如何授予角色,请参阅管理对项目、文件夹和组织的访问权限。
启用凭证销售
如果 Apache Iceberg REST 目录的身份验证方法设置为最终用户凭证,您可以将其切换为凭证分发模式。
控制台
- 在 Google Cloud 控制台中,打开 Lakehouse 页面。
在您要更新的目录所在的行中,依次选择 更多目录操作 > 修改身份验证。
在身份验证对话框中,选择凭据自动售卖模式。 自动预配的 Apache Iceberg REST 目录服务账号需要对所有关联的 Cloud Storage 存储桶具有明确的 Storage Object User 角色 (
roles/storage.objectUser)。默认情况下,该角色没有任何访问权限。如果没有此角色,出售的凭据就没有足够的范围来执行存储写入操作。选择保存。
Your catalog is updated and the **Catalog details** page opens.在身份验证方法下,选择设置存储桶权限。
在对话框中,选择确认。
此命令会验证目录的服务账号是否对所有关联的存储桶都具有 Storage Object User 角色 (roles/storage.objectUser)。
gcloud
使用 gcloud biglake iceberg catalogs update 命令。
gcloud biglake iceberg catalogs update \ CATALOG_NAME \ --project PROJECT_ID \ --credential-mode vended-credentials
替换以下内容:
CATALOG_NAME:目录的名称。对于 Lakehouse 目录,这是您的自定义目录名称。对于 Cloud Storage 存储桶目录,此值与 REST 目录使用的 Cloud Storage 存储桶 ID 相匹配。当从 BigQuery 查询这些表时,此名称也用作目录标识符。PROJECT_ID: Google Cloud项目 ID。启用凭据出售后,请向目录的自动预配 Apache Iceberg REST 目录服务账号明确授予所有关联存储桶的 Storage Object User 角色 (
roles/storage.objectUser)。
REST
如需使用 REST API 启用凭据自动售卖模式,请向 UpdateIcebergCatalog 端点发出 PATCH 请求:
PATCH /iceberg/v1/restcatalog/extensions/projects/PROJECT_ID/catalogs/CATALOG_ID?updateMask=icebergCatalog.credential_mode
请求正文必须包含一个 IcebergCatalog JSON 载荷,并将 credential_mode 设置为 VENDED_CREDENTIALS。
替换以下内容:
PROJECT_ID:您的 Google Cloud 项目 ID。CATALOG_ID:Lakehouse 运行时目录的 ID。