Lakehouse for Apache Iceberg מאפשר לכם להשתמש ביומני הביקורת של Cloud כדי לבדוק רשומות שניתנות לאימות של פעילויות אדמין וגישה לנתונים עבור נקודת הקצה של קטלוג Apache Iceberg REST בתוך קטלוג זמן הריצה של Lakehouse.
ביומנים האלה מתועדים אירועים במחזור החיים של הפעולה, עדכוני מדיניות ושינויים באימות.
לפני שמתחילים
- כדאי לקרוא את המאמר מידע על קטלוג זמן הריצה של Lakehouse כדי להבין איך קטלוג זמן הריצה של Lakehouse פועל ומהן המגבלות של השירות.
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles. - Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
התפקידים הנדרשים
כדי לקבל את ההרשאות שדרושות לצפייה ביומני ביקורת ב Google Cloud מסוף, צריך לבקש מהאדמין להקצות לכם את תפקידי ה-IAM הבאים בפרויקט:
- אדמין ב-BigLake (
roles/biglake.admin) - אדמין באחסון (
roles/storage.admin)
להסבר על מתן תפקידים, ראו איך מנהלים את הגישה ברמת הפרויקט, התיקייה והארגון.
יכול להיות שאפשר לקבל את ההרשאות הנדרשות גם באמצעות תפקידים בהתאמה אישית או תפקידים מוגדרים מראש.
הצגה של יומני ביקורת
במסוף Google Cloud , פותחים את הדף Lakehouse.
בשורה של הקטלוג שמוצג, לוחצים על עוד פעולות בקטלוג > הצגת יומני ביקורת.