Control access to Hologres data
DataWorks controls access to Hologres data through an authorized identity for each Hologres instance and an application-and-approval flow for table-level permissions. This topic describes how to set an authorized identity, apply for permissions on Hologres tables, approve permission applications, and view application and approval records.
Prerequisites
A Hologres instance is created. For instructions, see Purchase a Hologres instance.
A Hologres data source is added. For instructions, see Hologres data source.
Metadata is collected for Hologres. For instructions, see Collect metadata.
The Permission Policypermission model of the database that contains the Hologres tables that you want to apply for permissions on is set to Standard PostgreSQL Authorization Model. For instructions, see Switch permission models.
To set an authorized identity, you must use an Alibaba Cloud account or a Resource Access Management (RAM) user that has the AdministratorAccess policy.
If you use a RAM user as the authorized identity of a Hologres instance, the RAM user must have the AliyunHologresReadOnlyAccess permission and must be assigned the
SuperUserrole of that Hologres instance.
Limits
Review the following limits before you apply for or approve permissions on Hologres tables:
Supported grantees — You can apply for Hologres data access permissions only for the current account or another RAM user. Applying for permissions as a scheduling access account is not supported. In addition, explicit authorization supports only RAM users as grantees, not RAM roles.
Validity and renewal — Table-level permissions for Hologres are permanent, and you cannot specify an expiration time. Renewal is not supported: Hologres permissions in the Approved state are permanently valid, so renewal is neither required nor possible.
Withdrawal — Hologres permission application records support Withdraw, which takes effect only for applications in the Approving state.
Permission audit — The Permission audit tab on the Data access control page currently supports only the MaxCompute engine. Permission audit for the Hologres engine is not yet available on this tab.
Console entry migration — The original Permission application records and Permission approval records tab entries will be migrated to the My Applications and My Approval Tasks pages under the Application & approval group. (Recommended) Use the new page entries directly.
Set an authorized identity
DataWorks accesses each Hologres instance as a specified user, which is the authorized identity of that Hologres instance. This task requires the AdministratorAccess policy described in Prerequisites.
On the Permission Application tab, set Data Source Type to Hologres.
To the right of the Authorized Identity field, click Configure Authorization Identity.
In the Hologres instance authorization identity configuration window, view the Hologres instances that are associated with the current workspace. Each instance has its own authorized identity drop-down list.
For each instance, select an Alibaba Cloud account or a RAM user as the identity that runs authorization commands. If you select a RAM user, make sure that the RAM user meets the permission requirements in Prerequisites.
Click OK to save the configuration.
Apply for permissions
Apply for the table-level permissions that you need on Hologres tables. Before you start, review Limits to confirm which identities you can apply for and how long the granted permissions remain valid.
Go to the Permission Application tab.
Specify the tables that you want to apply for permissions on.
Set Data Source Type to Hologres, and then specify Hologres Instance and Database in sequence.
In the Tables to Be Added section on the left, select the data tables that you want to apply for permissions on.
In the table, select the permissions that you want to apply for. The following table-level permissions are supported:
Select,Insert,Update,Delete,Truncate, andALL.If you select the select-all button in the first row of the table, the application includes that permission for every table.
To cancel a permission for a specific table, clear the check box for that permission of the table.
Configure Application information. The following table describes the parameters.
Parameter Description User Select the identity for which you want to apply for permissions. Current login account: applies for permissions on the target tables for the Alibaba Cloud account that is currently logged on to the DataWorks workspace. Apply on Behalf of Others: the Alibaba Cloud account that is currently logged on to the DataWorks workspace applies for permissions on the target tables on behalf of another identity. If you select this option, you must also configure the Other identity parameter. Reason for Application Enter the reason for applying for permissions on the target tables. Click Apply for Permissions to submit the application.
After you submit the application, you can view its approval details and approval records. For instructions, see View permission application and approval records.
Approve permissions
Approve or reject Hologres permission applications on the My Approval Tasks page.
View applications pending approval.
In the left-side navigation pane, choose Application & approval > My Approval Tasks, and then click the Data access control tab. Set Data Source Type to Hologres, and then use the filter conditions to view the applications that require approval under the Alibaba Cloud account that is currently logged on.
Permission applications for multiple tables that are submitted in the same application are automatically split into multiple applications based on the table owners.
View approval details.
Click Approval in the Operation column of the target application. In the Approval details dialog box, you can view details such as Application Details and Approval record of the target application.
Approve the application.
Based on the application details and your current requirements, determine whether to approve the application. Enter Approval Comments, and then select Agree or Reject for the current application.
To handle several applications at a time, select all applications on the My Approval Tasks page, click Batch Agree or Batch Reject, enter Approval Comments, and then process the target applications in batches.
View permission application and approval records
Track the status of the Hologres permission applications that you submitted and of the applications that you processed as an approver.
To view permission application records
In the left-side navigation pane, choose Application & approval > My Applications, and then click the Data access control tab.
Filter by conditions such as Approval status, Application Time, and Hologres Instance to view the application records that are associated with the Alibaba Cloud account that is currently logged on.
Click View details in the Operation column of the target application to view the details of the application. For an application whose Approval status is Approving, you can also perform the Withdrawal operation.
To view permission approval records
In the left-side navigation pane, choose Application & approval > My Approval Tasks, click the Data access control tab, and then set the task status to All.
Filter by conditions such as Application account number, Approval Results, and Hologres Instance to view the approval records of the Alibaba Cloud account that is currently logged on.