Lakehouse ランタイム カタログを使用すると、ボーダーレス Lakehouse でカタログ エンドポイントを管理できます。 Google Cloud コンソールまたは REST API を使用して、これらのカタログ エンドポイントを作成、構成、モニタリングし、クエリ エンジン接続に必要なメタデータ レイヤを確立できます。
始める前に
- Lakehouse ランタイム カタログについてを読んで、Lakehouse ランタイム カタログの仕組みとサービスの制限事項を確認します。
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles. - Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API, if it is not already enabled.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
必要なロール
Lakehouse ランタイム カタログの使用に必要な権限を取得するには、プロジェクトに対する次の IAM ロールを付与するよう管理者に依頼してください。
- BigLake 管理者 (
roles/biglake.admin) - ストレージ管理者 (
roles/storage.admin)
ロールの付与については、プロジェクト、フォルダ、組織へのアクセス権の管理をご覧ください。
必要な権限は、カスタムロールや他の事前定義ロールから取得することもできます。
管理アクション
Google Cloud コンソールまたは REST API を使用して、Apache Iceberg REST カタログ エンドポイント リソースに対して次の管理アクションを実行できます。
- カタログを作成する: 基盤となる Cloud Storage ウェアハウスのロケーション(
CreateIcebergCatalog)を指す Apache Iceberg REST カタログ管理エンドポイントを作成します。 - カタログを更新する: 既存の単一バケット カタログを複数バケット カタログ(
UpdateIcebergCatalog)にアップグレードします。 - Namespace を作成する: Iceberg REST カタログ エンドポイント内に Namespace を作成して、関連するテーブル(
CreateIcebergNamespace)をグループ化します。 - 認証情報ベンディングを有効にする: 既存のカタログの認証方法を認証情報ベンディング モードに切り替えて、有効期間の短いストレージ トークンをクエリエンジン(
UpdateIcebergCatalog)に直接ベンディングします。 - カタログの詳細を取得する: クライアント接続に必要な REST カタログ URI(
GetIcebergCatalog)など、カタログのプロパティとメタデータを表示します。 - 名前空間 ACL を管理する: カタログ名前空間の IAM ポリシーを表示して更新し、特定のプリンシパル(
get-iam-policy、set-iam-policy)のアクセスを制御します。 - カタログを削除する: Lakehouse ランタイム カタログ(
DeleteIcebergCatalog)からカタログ メタデータ管理エンドポイントの登録を解除します。 - 名前空間を削除する: 不要になった Iceberg REST カタログから名前空間を削除します(
DeleteIcebergNamespace)。 - 監査ログを表示する: 管理アクティビティとデータアクセス アクティビティの検証可能なレコードについて Cloud Audit Logs を検査します。
料金
料金の詳細については、Lakehouse の料金をご覧ください。
次のステップ
- 名前空間の ACL を管理する方法を学習する。
- Apache Iceberg REST カタログ エンドポイントの詳細を確認する。