Creating a Data Share
Learn how resource owners or Data Share administrators can share Iceberg tables in the by registering external clients and creating Data Shares using Knox and Ranger API commands.
Resource owners or Data Share administrators who want to share their Iceberg tables in Cloudera with external clients must first register the
external client (Data Consumer) in the Cloudera on cloud
environment. This provisions a CLIENT_ID and
CLIENT_SECRET for the external user.
After registering the external user, the resource owner creates a Data Share. A Data Share packages specified data assets (Iceberg tables) into a shareable unit and optionally grants access to registered external users at creation time.
Registering external clients for Cloudera on premises
For Cloudera on premises deployments, generate a
CLIENT_ID and CLIENT_SECRET for an external client
through the cdp-share-management Knox topology, and then create the Ranger
group and role that represent the external client.
In Cloudera on premises deployments, external clients are
registered directly against the cdp-share-management Knox topology
gateway rather than a Cloudera on cloud Data Lake. The
registration provisions a CLIENT_ID and
CLIENT_SECRET, which the external client later uses in an OAuth
client credentials flow to authenticate to Cloudera Iceberg REST Catalog. You then create a Ranger group
named after the CLIENT_ID and add it to a Ranger role. To grant
that role SELECT access to the Iceberg tables you want to share,
create a Data Share policy as described in Managing Ranger policies for Data
Shares.
- Declare the
cdp-datashare-accessandcdp-share-managementKnox topologies, as described in Declaring Knox topologies for on premises Data Sharing. - The user that runs the following commands:
- Must exist in the cluster
- Must be configured as a Knox proxy (impersonation) user in the
cdp-share-managementtopology - Must be granted the Ranger administrator role
- Run all commands within the network of your Cloudera Runtime deployment or through a VPN.
The external client is registered with a CLIENT_ID and
CLIENT_SECRET, and a Ranger role that contains the
CLIENT_ID group represents the Data Share. The client uses the
CLIENT_ID and CLIENT_SECRET in an OAuth client
credentials flow to authenticate to Cloudera Iceberg REST Catalog.
Create the Data Share policy that grants the Ranger role SELECT
access to the shared Iceberg tables, as described in Managing Ranger policies.
Managing Ranger policies for Data Shares
Learn how to manage your Ranger policies to authenticate your external users.
The Ranger Administrator must maintain policies for the set of databases and tables for the Ranger role and group to enable read access for these assets.
SELECT access to the databases and tables you want to
share.
Create the policy for the role created in Registering external clients and creating a Data Share for on premises deployments:
curl -k -u [***RANGER-ADMIN-USER***]:[***PASSWORD***] -H "Accept: application/json" -H "Content-Type: application/json" -X POST "https://[***KNOX-GATEWAY-HOST***]:8443/gateway/cdp-share-management/ranger/service/public/v2/api/policy/" -d '{"service":"cm_hive", "policyType": 0, "name": "[***DATA_SHARE_NAME***]", "description": "Policy for SELECT access to the shared Iceberg tables", "isEnabled": true, "resources": { "database": { "values": ["[***DATABASE_NAME***]"] }, "table": { "values": ["[***TABLE_NAME***]"] }, "column": { "values": ["*"] } }, "policyItems": [ { "accesses": [ { "type": "select" } ], "users": [], "groups": [], "roles": ["[***CLIENT_ROLE***]"], "conditions": [] } ] }'
Instead of managing access separately for every shared table, you define a central Ranger policy that groups the relevant tables together into a unified Data Share. This policy grants the required read access to the Ranger role you previously created, ensuring that any external client linked to that role can query the shared data.
The following policy grants the SalesDeptRole role
SELECT access to the employees,
departments, and dept_emp Iceberg
tables, which together form the datashare1 Data
Share:
curl -k -u systest:[***PASSWORD***] -H "Accept: application/json" -H "Content-Type: application/json" -X POST "https://my-knox-gateway-host.root.comops.site:8443/gateway/cdp-share-management/ranger/service/public/v2/api/policy/" -d '{"service":"cm_hive", "policyType": 0, "name": "datashare1", "description": "Policy for SELECT access to the shared Iceberg tables", "isEnabled": true, "resources": { "database": { "values": ["emp_data"] }, "table": { "values": ["employees", "departments", "dept_emp"] }, "column": { "values": ["*"] } }, "policyItems": [ { "accesses": [ { "type": "select" } ], "users": [], "groups": [], "roles": ["SalesDeptRole"], "conditions": [] } ] }'
