StarRocks data access control

更新时间: 2026-07-10 16:40:51

DataWorks provides data access control for the StarRocks engine, including permission request, permission approval, and permission audit. You can view your application records in My Applications and manage your approval tasks in My Approval Tasks.

Prerequisites

  • You have added StarRocks as a DataWorks data source. For more information, see StarRocks data source.

  • You have added a Ranger configuration and associated it with a Ranger Service. For more information, see Add a Ranger configuration.

  • You have configured an identity credential for the applicant, with the data source type set to StarRocks. For more information, see Identity credentials.

Step 1: Go to data access control

  1. Log on to the DataWorks console. In the target region, click Data Governance > Security Center in the left-side navigation pane. On the page that appears, click Go to Security Center.

  2. On the Security Center page, click Data Access Control in the left-side navigation pane.

Apply for permissions

On the Data Access Control page, apply for permissions by configuring the Application Content and Application information sections.

Note
  • Permission applications for StarRocks do not support custom approval processes or permission audit management.

  • Only a RAM user or RAM role whose account type is set to Administrator in their identity credential can review permission applications for StarRocks.

  1. On the Data Access Control page, click the Permission Application tab.

  2. Apply for resource permissions.

    1. In the Application Content section, set the data source type to StarRocks to configure the application content.

      1. Application Type: Select Database or Table based on your needs.

      2. StarRocks Instance: Select a StarRocks data source instance that has been associated with DataWorks.

      3. Catalog: Select a Catalog that has been configured in the StarRocks-type Service in Ranger. For more information, see Add a Service.

      4. Select the resources and resource permissions that you want to apply for.

        Select a database

        Based on the preceding configurations, the Application Content section loads the metadata databases available for permission requests. Select the target metadata databases and database permissions.

        Available database permissions include ALTER, DROP, CREATE TABLE, CREATE VIEW, CREATE FUNCTION, and CREATE MATERIALIZED VIEW.

        Select a table

        Based on the preceding configurations, select the database that contains the target tables. The system loads all tables available for permission requests. Select the target tables and table permissions.

        In the Tables to Add panel on the left, select the target tables. The selected tables are displayed in the permission configuration area on the right, where you can select permissions such as ALTER, DROP, SELECT, INSERT, UPDATE, EXPORT, and DEL for each table.

    2. Configure the application information.

      Parameter

      Description

      User

      Select the account for which you want to apply for permissions.

      • Current login account: Apply for permissions for the Alibaba Cloud account that is logged on to the DataWorks workspace.

      • Apply on Behalf of Others: The Alibaba Cloud account that is logged on to the DataWorks workspace applies for permissions on behalf of another Alibaba Cloud account. If you select this option, you must configure the Username parameter.

      Application duration

      StarRocks supports only Permanent.

      Reason for Application

      Enter the reason for the permission request.

      When you apply for permissions for StarRocks or Hive users, a DataWorks tenant administrator (or the Alibaba Cloud account) must configure the corresponding StarRocks or Hive user information for the RAM user or RAM role in Security Center > Identity Credentials.

  3. After the configuration is complete, click Apply for Permissions to submit the permission request.

Approve permissions

  1. View the pending applications.

    In the left-side navigation pane, choose Applications & Approvals > My Approval Tasks, and click the Data Access Control tab. Set Data Source Type to StarRocks, and filter by application account, application time, workspace, project name, or object name to view pending applications.

    Note

    Only a RAM user or RAM role whose account type is set to Administrator in their identity credential has the approval permission.

  2. View the approval details.

    Click Approval in the Operation column of the target application. In the Approval details dialog, you can view detailed information such as Application Details and Approval record.

  3. Approve the application.

    Based on the application details and requirements, determine whether to approve the application. Enter Approval Comments, and click Agree or Reject.

    You can also select all applications on the My Approval Tasks page and click Batch Agree or Batch Reject, enter Approval Comments, and process the applications in a batch.

View permission request and approval records

Note
  • StarRocks permission request records support Withdraw (effective only for applications in Pending Approval status). Renewal is not supported because approved StarRocks permissions are permanent.

  • The Permission Audit tab on the Data Access Control page supports only the MaxCompute engine. Permission audit for StarRocks is not available on this tab.

  • The original Permission Approval Records tab on the Data Access Control page has been removed. Only a migration notice is retained. Records have been migrated to the Applications & Approvals > My Approval Tasks page.

  • View permission request records: In the left-side navigation pane, choose Applications & Approvals > My Applications, and click the Data Access Control tab. You can filter by conditions such as Data Source Type, Application Type, Application Time, and Approval status to view the application records under the current Alibaba Cloud account.

  • View permission approval records: In the left-side navigation pane, choose Applications & Approvals > My Approval Tasks, and click the Data Access Control tab. Set the task status to All. You can filter by conditions such as Data Source Type, Application Type, Application account number, Approval Results, and Application Time to view the approval records of the current Alibaba Cloud account.

上一篇: Hive data access control 下一篇: Lindorm data access control
阿里云首页 大数据开发治理平台 DataWorks 相关技术圈