Katalog runtime Lakehouse memungkinkan Anda mengaktifkan mode pemberian kredensial sementara untuk endpoint katalog di Lakehouse tanpa batas.
Mode pemberian kredensial memberikan token penyimpanan yang memiliki masa berlaku singkat dan cakupan terbatas kepada mesin kueri dan workload yang sah. Metode autentikasi ini menghilangkan kebutuhan Anda atau runtime kueri untuk memiliki izin baca dan izin tulis langsung pada bucket Cloud Storage yang mendasarinya.
Sebelum memulai
- Baca Tentang katalog runtime Lakehouse untuk memahami cara kerja katalog runtime Lakehouse dan batasan untuk layanan ini.
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles. - Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
Peran yang diperlukan
Untuk mendapatkan izin yang Anda perlukan untuk mengaktifkan penyediaan kredensial, minta administrator untuk memberi Anda peran IAM berikut:
-
Semua:
- BigLake Admin (
roles/biglake.admin) di project Anda - Storage Admin (
roles/storage.admin) di project Anda
- BigLake Admin (
-
Akun layanan katalog REST Apache Iceberg yang disediakan otomatis:
Pengguna Objek Penyimpanan (
roles/storage.objectUser) di semua bucket Cloud Storage terkait. Setelah mengaktifkan penyediaan kredensial, berikan peran Storage Object User (roles/storage.objectUser) secara eksplisit di semua bucket penyimpanan terkait ke akun layanan katalog Apache Iceberg REST yang disediakan otomatis.
Untuk mengetahui informasi selengkapnya tentang pemberian peran, lihat Mengelola akses ke project, folder, dan organisasi.
Anda mungkin juga bisa mendapatkan izin yang diperlukan melalui peran khusus atau peran bawaan lainnya.
Mengaktifkan penyediaan kredensial
Jika metode autentikasi untuk katalog REST Apache Iceberg Anda disetel ke kredensial pengguna akhir, Anda dapat mengalihkannya ke mode penyediaan kredensial.
Konsol
- Di konsol Google Cloud , buka halaman Lakehouse.
Di baris katalog yang Anda perbarui, pilih Tindakan katalog lainnya > Edit autentikasi.
Dalam dialog autentikasi, pilih Credential vending mode. Akun layanan katalog REST Apache Iceberg yang disediakan secara otomatis memerlukan peran Storage Object User (
roles/storage.objectUser) yang eksplisit di semua bucket Cloud Storage terkait. Secara default, pengguna tidak memiliki akses. Tanpa peran ini, kredensial yang disediakan tidak memiliki cakupan yang memadai untuk melakukan penulisan penyimpanan.Pilih Save.
Your catalog is updated and the **Catalog details** page opens.Di bagian Metode autentikasi, pilih Set bucket permissions.
Di dialog, pilih Konfirmasi.
Tindakan ini memverifikasi bahwa akun layanan katalog Anda memiliki peran Storage Object User (roles/storage.objectUser) di semua bucket penyimpanan terkait.
gcloud
Gunakan gcloud biglake iceberg catalogs update perintah.
gcloud biglake iceberg catalogs update \ CATALOG_NAME \ --project PROJECT_ID \ --credential-mode vended-credentials
Ganti kode berikut:
CATALOG_NAME: nama untuk katalog Anda. Untuk katalog Lakehouse, ini adalah nama katalog kustom Anda. Untuk katalog bucket Cloud Storage, ini cocok dengan ID bucket Cloud Storage yang digunakan dengan katalog REST. Nama ini juga digunakan sebagai ID katalog saat mengueri tabel ini dari BigQuery.PROJECT_ID: Google Cloud Project ID Anda.Setelah mengaktifkan penyediaan kredensial, berikan peran Storage Object User (
roles/storage.objectUser) secara eksplisit di semua bucket penyimpanan terkait ke akun layanan katalog Apache Iceberg REST yang disediakan otomatis.
REST
Untuk mengaktifkan mode penyediaan kredensial menggunakan REST API, buat permintaan PATCH ke endpoint UpdateIcebergCatalog:
PATCH /iceberg/v1/restcatalog/extensions/projects/PROJECT_ID/catalogs/CATALOG_ID?updateMask=icebergCatalog.credential_mode
Isi permintaan harus berisi payload JSON IcebergCatalog dengan credential_mode yang ditetapkan ke VENDED_CREDENTIALS.
Ganti kode berikut:
PROJECT_ID: Google Cloud Project ID Anda.CATALOG_ID: ID katalog runtime Lakehouse Anda.