借助 Identity and Access Management (IAM),您可以控制哪些人可以在 Dataplex Universal Catalog 中执行哪些操作。您可以采用最小权限安全原则,以保护私密数据、避免未经授权的访问、缩小攻击面或满足法规遵从要求。
Dataplex Universal Catalog 提供了多个预定义的 IAM 角色,每个角色都具有一组特定的权限,可让用户执行相应操作。您可以使用 IAM 政策授予这些角色。
如需更精细的控制,您可以选择特定权限并向用户分配该新角色,从而创建自定义 IAM 角色。借助自定义角色,您可以构建符合组织需求的访问权限模型。
本文档介绍了与 Dataplex Universal Catalog 相关的预定义和自定义 IAM 角色。
如需详细了解 IAM 及其功能,请参阅 IAM 文档。
Dataplex Universal Catalog 角色简介
Dataplex Universal Catalog IAM 角色是一项或多项权限的集合。您向主账号授予角色,以允许他们对项目中的 Dataplex Universal Catalog 资源执行操作。例如,Dataplex Viewer 角色具有 dataplex.*.get 和 dataplex.*.list 权限,这些权限允许用户获取和列出项目中的 Dataplex Universal Catalog 资源。如需了解详情,请参阅 Dataplex Universal Catalog 权限。
您可以将 Dataplex Universal Catalog 角色应用于服务层次结构中的任何资源,包括项目、数据湖和数据区域。
基本角色
您可以使用 IAM Project 角色在项目级分配基本角色。下面列出了与 IAM 项目角色关联的权限:
| 项目角色 | 权限 |
|---|---|
| Project Owner | 拥有所有“项目修改者”权限,外加为项目管理访问控制的权限(获取/设置 IamPolicy)和设置项目结算的权限 |
| Project Editor | 拥有所有 Project Viewer 权限,外加可修改状态的操作(创建、删除、更新、使用)的所有项目权限 |
| 项目查看者 | 拥有不会修改状态的只读操作(获取、列出)的所有项目权限 |
Dataplex Universal Catalog 的预定义角色
预定义角色可提供执行一项任务或一组相关任务所需的权限。
请注意以下几点:
- 如果您使用的是 Data Catalog,则 Data Catalog 条目访问权限不会自动转移到 Dataplex Universal Catalog 条目。您必须先明确授予对 Dataplex Universal Catalog 条目的访问权限,然后才能使用这些条目。
- Dataplex Administrator、Dataplex Editor 和 Dataplex Viewer 角色不提供对元数据资源(例如条目组、条目类型、切面类型和条目)的访问权限。
- 没有任何角色授予从系统定义的条目群组(例如
@bigquery和@dataplex)添加或删除 Dataplex Universal Catalog 条目的权限。 - Dataplex Entry and EntryLink Owner 角色可提供以下权限:
- 授予对条目相关操作的完整访问权限。
- 授予添加某些系统切面类型(例如
Schema、Generic、Overview和Contacts)的切面的权限。 - 授予创建
GenericEntry类型的条目的权限。 - 借助此角色,您可以创建具有条目类型和切面类型的条目,其中条目类型和切面类型与条目在同一项目中定义。否则,必须针对定义了条目类型和切面类型的项目授予额外的 Dataplex Entry Type User 和 Dataplex Aspect Type User 角色。
- 使用
LookupEntry方法或SearchEntries方法时,此角色不会授予读取从 Dataplex Universal Catalog 之外的Google Cloud 资源(例如 BigQuery 条目)创建的条目的权限。如需读取这些条目,您必须获得源系统资源的权限。或者,您也可以使用GetEntry方法读取仅具有 Dataplex Entry 和 EntryLink Owner 角色的条目。
- 如需查看附加到条目的数据切面,您需要拥有从条目所代表的源资产读取数据的权限,以及查看条目的权限。 如果您有权查看某个条目,但缺少对源资产的数据读取权限,则仍可以查看该条目上的所有其他元数据,但 Dataplex Universal Catalog 会隐藏任何附加的数据切面的内容。
Dataplex Catalog Admin 和 Dataplex Catalog Editor 角色授予查看自定义条目所需的权限。
- 如需使用
SearchEntries方法搜索条目,您必须至少获得在 API 请求中使用的项目的以下 IAM 角色之一:Dataplex Catalog Admin、Dataplex Catalog Editor 或 Dataplex Catalog Viewer。搜索结果的权限检查与所选项目无关。
下表列出了 Dataplex Universal Catalog 预定义角色以及与每个角色关联的权限。
| Role | Permissions |
|---|---|
Dataplex Administrator( Full access to Dataplex Universal Catalog resources, except for catalog resources like entries and entry groups. |
|
Dataplex DataScan Administrator( Full access to DataScan resources. |
|
Dataplex Editor( Write access to Dataplex Universal Catalog resources, except for catalog resources like entries, entry groups, and glossaries. |
|
Dataplex Viewer( Read access to Dataplex Universal Catalog resources, except for catalog resources like entries, entry groups, and glossaries. |
|
Dataplex Aspect Type Owner( Grants access to creating and managing Aspect Types. Does not give the right to create/modify Entries. |
|
Dataplex Aspect Type User( Grants access to use Aspect Types to create/modify Entries with the corresponding aspects. |
|
Dataplex Binding Administrator( Full access on DataAttribute Binding resources. |
|
Dataplex Catalog Admin( Full access to catalog resources, including entries, entry groups, and glossaries. |
|
Dataplex Catalog Editor( Write access to catalog resources, including entries, entry groups, and glossaries. Cannot set IAM policies on resources. |
|
Dataplex Catalog Viewer( Read access to catalog resources, including entries, entry groups, and glossaries. Can view IAM policies on catalog resources. |
|
Dataplex Change Request Owner Beta( Grants Change Request creator necessary permissions on a created ChangeRequest instance. |
|
Dataplex Data Domain Admin Beta( Allows full management of the Data Domain and its bindings. |
|
Dataplex Data Domain Configuration Editor Beta( Allows updating the Data Domain as well as full management of its bindings. |
|
Dataplex Data Domain Entry Reader Beta( Allows discovering and viewing the Data Domain, its subdomains, and metadata of all its resources. |
|
Dataplex Data Domain Configuration Viewer Beta( Allows viewing the configuration of the Data Domain and its bindings. |
|
Dataplex Data Owner( Owner access to data. To be granted to Dataplex Universal Catalog resources Lake, Zone or Asset only. |
|
Dataplex Data Products Admin( Full access to Data Products. |
|