Creating a Data Share
Learn how resource owners or Data Share administrators can share Iceberg tables in the by registering external clients and creating Data Shares using the Cloudera Data Catalog user interface or CDP CLI commands.
Resource owners or Data Share administrators who want to share their Iceberg tables in Cloudera with external clients must first register the
external client (Data Consumer) in the Cloudera on cloud
environment. This provisions a CLIENT_ID and
CLIENT_SECRET for the external user.
After registering the external user, the resource owner creates a Data Share. A Data Share packages specified data assets (Iceberg tables) into a shareable unit and optionally grants access to registered external users at creation time.
Creating a Data Share with CDP CLI
Learn how to register external clients in Cloudera on cloud and create Data Shares using CDP CLI commands. This process involves provisioning credentials for external users and managing data sharing through a series of CLI commands. Ensure that prerequisites are met and follow the steps to securely share data assets with external users.
Resource owners or Data Share administrators who want to share their Iceberg tables
in Cloudera with external clients must first
register the external client in the Cloudera on cloud
environment using the cdp datacatalog create-external-users CDP
CLI command. This provisions a CLIENT_ID and
CLIENT_SECRET for the external user.
After registering the external user, the resource owner creates a Data Share using
the cdp datacatalog create-data-share CDP CLI command. The
command packages specified data assets (Iceberg tables) into a shareable unit and
optionally grants access to registered external users during creation using the
--external-users parameter.
The CDP CLI also provides commands to manage the entire Data Share lifecycle, including listing, updating, activating, deactivating, and deleting shares, as well as managing asset membership and external user access.
- Users who run the token generation commands, must be a part of the Knox admin
users and groups configuration. For more information see Knox configuration in
gateway-site.xml.
Having the
DataShareAdminresource role includes theknoxAdminrole. For more information, see Providing access to users. - You must run all commands within the network of your Cloudera Runtime or through a VPN.
- For Cloudera on cloud environments, you can alternatively register external users using the Cloudera Data Catalog user interface. For more information, see Creating external users.
- CDP CLI must be installed and configured. For more information, see CLI client setup.
- Configure the CDP CLI profile to authenticate as a non-machine user (an interactive user
account). You must run all cdp datacatalog Data Sharing
commands with that user, not with a machine user or service principal, even when
the machine user has the
DataShareAdminresource role. Your account must have theCDP_DATA_SHARE_ADMINentitlement. For more information, see Data Sharing overview. - The cdp datacatalog create-external-users command registers
external users (Data Consumers outside Cloudera who
receive a
CLIENT_IDandCLIENT_SECRETfor Iceberg REST Catalog access). It does not create machine users for automation. - You must have the following information before creating a Data Share:
- Share Admin user and password
- Username and password of the Cloudera Administrator. For more information, see Cloudera account administrator.
- Data Lake name
- Go to , copy and record the Data Lake name.
Data Share management commands
The following additional CDP CLI commands are available for Data Share management:
- cdp datacatalog create-external-users — Creates external user
accounts for individuals outside Cloudera, generating a
CLIENT_IDandCLIENT_SECRETfor each user. - cdp datacatalog list-external-users — Lists external users registered for data sharing, with optional filtering and pagination.
- cdp datacatalog revoke-external-user-credentials — Revokes the active credentials for an external user.
- cdp datacatalog regenerate-external-user-credentials — Issues a new set of credentials for an external user, invalidating the old ones.
- cdp datacatalog delete-external-user — Permanently deletes an external user and removes their access to all data shares.
- cdp datacatalog create-data-share — Creates a new data share and packages specified data assets into a shareable unit.
- cdp datacatalog list-data-shares — Lists all available data shares within a specified Data Lake.
- cdp datacatalog get-data-share — Retrieves the full details of a specific data share, including its assets and user access list.
- cdp datacatalog update-data-share — Updates the metadata for an existing data share, such as its name, keywords, or expiration.
- cdp datacatalog delete-data-share — Permanently deletes a data share.
- cdp datacatalog share-data-share — Activates a data share, making its assets available to the configured external users.
- cdp datacatalog unshare-data-share — Deactivates a data share, making its assets temporarily unavailable.
- cdp datacatalog add-assets-to-data-share — Adds new data assets, such as tables or views, to an existing data share.
- cdp datacatalog remove-assets-from-data-share — Removes one or more assets from an existing data share by resource ID.
- cdp datacatalog get-fgac-status-by-assets — Checks whether one or more assets being added to a data share are protected by Apache Ranger fine-grained access control (FGAC) policies, such as column masking or row-level filtering.
- cdp datacatalog grant-access-to-external-users-on-data-share — Grants one or more external users access to a data share, with an optional expiration.
- cdp datacatalog update-access-of-external-users-on-data-share — Adds external users to a data share or updates their access expiration time.
- cdp datacatalog remove-access-of-external-users-on-data-share — Removes one or more external users' access from a specific data share.
After you create the Data Share, publish it so external users can access its assets.
Run the cdp datacatalog share-data-share command with the same
--datalake-crn and --environment-crn values
you used for the cdp datacatalog create-data-share command, and
the dataShareId value from the create command response. The command
calls POST /api/v1/datacatalog/shareDataShare with those three
values in the request body.
cdp datacatalog share-data-share \
--datalake-crn "[***DATALAKE-CRN***]" \
--environment-crn "[***ENVIRONMENT-CRN***]" \
--data-share-id "[***DATA-SHARE-ID***]"
On success, the command returns a JSON object that matches
ShareDataShareResponse:
{
"success": true
}
For example, if you created the share in the previous step, you can publish it using the same environment and Data Lake CRNs along with the returned identifier:
cdp datacatalog share-data-share \
--datalake-crn "crn:cdp:datalake:us-west-1:..." \
--environment-crn "crn:cdp:environments:us-west-1:..." \
--data-share-id "1"
Registering external clients in Cloudera on cloud
Learn how to register external clients in Cloudera on cloud to provision a CLIENT_ID and
CLIENT_SECRET.
- Share Admin user and password
- Username and password of the Cloudera Administrator. For more information, see Cloudera account administrator.
- Knox hostname
- To get the Knox hostname, go to , and copy the hostname for the Knox Gateway role.
- Data Lake name
- Go to and copy and make a note of the Data Lake name.
The registration process results in provisioning a CLIENT_ID and
CLIENT_SECRET followed by creating Ranger ROLE
and adding CLIENT_ID as a Group to the ROLE. You
can verify the creation of your Ranger groups and users in
Managing Ranger policies for Data Shares
Learn how to manage your Ranger policies to authenticate your external users.
The Ranger Administrator must maintain policies for the set of databases and tables for the Ranger role and group to enable read access for these assets.
SELECT access to the databases and tables you want to
share.
Create the policy for the role created in Creating a Data Share with CDP CLI:
curl -k -u [***CDP_ADMIN_USER***]:[***PASSWORD***] -H "Accept: application/json" -H "Content-Type: application/json" -X POST "https://[***RANGER-HOST-NAME***]:8443/[***DATALAKE-NAME***]/cdp-share-management/ranger/service/public/v2/api/policy/" -d '{"service":"hive_service_name", "policyType": 0, "name": "Iceberg Table Policy", "description": "Policy for SELECT access to an CLIENT_ID", "isEnabled": true, "resources": { "database": { "values": "[***DATABASE_NAME***]" }, "table": { "values": "[***TABLE_NAME***]" } ,"column": { "values": ["*"] } } , "policyItems": [ { "accesses": [ { "type": "select" } ], "users": [], "groups":[], "roles": "[***CLIENT_ROLE***]", "conditions": [] } ] }'
curl -k -u [***CDP_ADMIN_USER***]:[***PASSWORD***] -H "Accept: application/json" -H "Content-Type: application/json" -X POST "https://dldanew-vxtt5w-master0.dldanew.svbr-nqvp.int.cldr.work:8443/dldanew-vxtt5w/cdp-share-management/ranger/service/public/v2/api/policy/" -d '{"service":"cm_hive", "policyType": 0, "name": "Hive Table Policy", "description": "Policy for SELECT access to an exteral user", "isEnabled": true, "resources": { "database": { "values": ["emp_data"] }, "table": { "values": ["employees"] } ,"column": { "values": ["*"] } } , "policyItems": [ { "accesses": [ { "type": "select" } ], "users": [], "groups":[], "roles": ["testrole13"], "conditions": [] } ] }'
