启用凭证自动发放

借助 Lakehouse 运行时目录,您可以在无边界 Lakehouse 中为目录端点启用凭据分发模式。

凭证分发模式会向授权的查询引擎和工作负载分发短期、降权存储令牌。此身份验证方法无需您或查询运行时对底层 Cloud Storage 存储桶拥有直接的读取和写入权限。

准备工作

  1. 请参阅关于 Lakehouse 运行时目录,了解 Lakehouse 运行时目录的工作原理以及该服务的限制。
  2. 登录您的 Google Cloud 账号。如果您是 Google Cloud新手,请 创建一个账号来评估我们的产品在实际场景中的表现。新客户还可获享 $300 赠金,用于运行、测试和部署工作负载。

    In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

    Verify that billing is enabled for your Google Cloud project.

    Enable the BigLake API, if it is not already enabled.

    Roles required to enable APIs

    To enable APIs, you need the serviceusage.services.enable permission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.

    Enable the API

    In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

    Verify that billing is enabled for your Google Cloud project.

    Enable the BigLake API, if it is not already enabled.

    Roles required to enable APIs

    To enable APIs, you need the serviceusage.services.enable permission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.

    Enable the API

所需的角色

如需获得启用凭据自动售卖所需的权限,请让您的管理员为您授予以下 IAM 角色:

  • 全部:
  • 自动预配的 Apache Iceberg REST 目录服务账号:所有关联的 Cloud Storage 存储桶上的 Storage Object User (roles/storage.objectUser)。启用凭据自动发放后,请向目录的自动预配 Apache Iceberg REST Catalog 服务账号明确授予所有关联存储桶的 Storage Object User 角色 (roles/storage.objectUser)。

如需详细了解如何授予角色,请参阅管理对项目、文件夹和组织的访问权限。

您也可以通过自定义角色或其他预定义角色来获取所需的权限。

启用凭证销售

如果 Apache Iceberg REST 目录的身份验证方法设置为最终用户凭证,您可以将其切换为凭证分发模式。

控制台

  1. 在 Google Cloud 控制台中,打开 Lakehouse 页面。

前往 Lakehouse

  1. 在您要更新的目录所在的行中,依次选择 更多目录操作 > 修改身份验证。

  2. 在身份验证对话框中,选择凭据自动售卖模式。 自动预配的 Apache Iceberg REST 目录服务账号需要对所有关联的 Cloud Storage 存储桶具有明确的 Storage Object User 角色 (roles/storage.objectUser)。默认情况下,该角色没有任何访问权限。如果没有此角色,出售的凭据就没有足够的范围来执行存储写入操作。

  3. 选择保存。

      Your catalog is updated and the **Catalog details** page opens.
    
  4. 在身份验证方法下,选择设置存储桶权限。

  5. 在对话框中,选择确认。

此命令会验证目录的服务账号是否对所有关联的存储桶都具有 Storage Object User 角色 (roles/storage.objectUser)。

gcloud

使用 gcloud biglake iceberg catalogs update 命令。

gcloud biglake iceberg catalogs update \
    CATALOG_NAME \
    --project PROJECT_ID \
    --credential-mode vended-credentials

替换以下内容:

  • CATALOG_NAME:目录的名称。对于 Lakehouse 目录,这是您的自定义目录名称。对于 Cloud Storage 存储桶目录,此值与 REST 目录使用的 Cloud Storage 存储桶 ID 相匹配。当从 BigQuery 查询这些表时,此名称也用作目录标识符。
  • PROJECT_ID: Google Cloud项目 ID。

    启用凭据出售后,请向目录的自动预配 Apache Iceberg REST 目录服务账号明确授予所有关联存储桶的 Storage Object User 角色 (roles/storage.objectUser)。

REST

如需使用 REST API 启用凭据自动售卖模式,请向 UpdateIcebergCatalog 端点发出 PATCH 请求:

PATCH /iceberg/v1/restcatalog/extensions/projects/PROJECT_ID/catalogs/CATALOG_ID?updateMask=icebergCatalog.credential_mode

请求正文必须包含一个 IcebergCatalog JSON 载荷,并将 credential_mode 设置为 VENDED_CREDENTIALS。

替换以下内容:

  • PROJECT_ID:您的 Google Cloud 项目 ID。
  • CATALOG_ID:Lakehouse 运行时目录的 ID。