Lakehouse for Apache Iceberg 를 사용하면 Cloud 감사 로그를 사용하여 Lakehouse 런타임 카탈로그 내에서 Apache Iceberg REST 카탈로그 엔드포인트 의 관리 및 데이터 액세스 활동에 대한 검증 가능한 레코드를 검사할 수 있습니다.
이러한 로그는 작업 수명 주기 이벤트, 정책 업데이트, 인증 변경사항을 추적합니다.
시작하기 전에
- Lakehouse 런타임 카탈로그 작동 방식과 서비스 제한사항을 이해하려면 Lakehouse 런타임 카탈로그 정보를 읽어보세요.
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles. - Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API.
Roles required to enable APIs
To enable APIs, you need the Service Usage Admin IAM
role (roles/serviceusage.serviceUsageAdmin), which
contains the serviceusage.services.enable permission. Learn how to grant
roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API.
Roles required to enable APIs
To enable APIs, you need the Service Usage Admin IAM
role (roles/serviceusage.serviceUsageAdmin), which
contains the serviceusage.services.enable permission. Learn how to grant
roles.
필요한 역할
콘솔에서 감사 로그를 보는 데 필요한 권한을 얻으려면 관리자에게 프로젝트에 대해 다음 IAM 역할을 부여해 달라고 요청하세요. Google Cloud
- BigLake 관리자 (
roles/biglake.admin) - 스토리지 관리자 (
roles/storage.admin)
역할 부여에 대한 자세한 내용은 프로젝트, 폴더, 조직에 대한 액세스 관리를 참조하세요.
커스텀 역할이나 다른 사전 정의된 역할을 통해 필요한 권한을 얻을 수도 있습니다.
감사 로그 보기
콘솔에서 Lakehouse 페이지를 엽니다. Google Cloud
보고 있는 카탈로그의 행에서 카탈로그 작업 더보기 > 감사 로그 보기 를 클릭합니다.