<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic external location on unity catalog permits access to s3 in Data Governance</title>
    <link>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14206#M513</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;when i create external location on unity catalog. even if i dont provide any user grants, i have an write access to the s3 bucket from attached workspace.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;i created external location xxxx&lt;/LI&gt;&lt;LI&gt;i didnt allow any permissions on it &lt;/LI&gt;&lt;LI&gt;on a workspace that is connected to the metastore:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt; df.write.parquet('s3://xxxx-data/amit/suppose_to_fail')&lt;/P&gt;&lt;P&gt; ended successfully&lt;/P&gt;&lt;P&gt;when i removed the external location, it was failing with AWS error of no permissions, so i'm sure the permissions were delegated from UC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do i prevent from users to be able to write to s3 directly when using UC (btw, in the past, i could control the write options on AWS IAM level.  though doesnt provide full solution, as i need to grant write selectively)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Amit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 29 Dec 2022 10:53:17 GMT</pubDate>
    <dc:creator>amitca71</dc:creator>
    <dc:date>2022-12-29T10:53:17Z</dc:date>
    <item>
      <title>external location on unity catalog permits access to s3</title>
      <link>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14206#M513</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;when i create external location on unity catalog. even if i dont provide any user grants, i have an write access to the s3 bucket from attached workspace.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;i created external location xxxx&lt;/LI&gt;&lt;LI&gt;i didnt allow any permissions on it &lt;/LI&gt;&lt;LI&gt;on a workspace that is connected to the metastore:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt; df.write.parquet('s3://xxxx-data/amit/suppose_to_fail')&lt;/P&gt;&lt;P&gt; ended successfully&lt;/P&gt;&lt;P&gt;when i removed the external location, it was failing with AWS error of no permissions, so i'm sure the permissions were delegated from UC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do i prevent from users to be able to write to s3 directly when using UC (btw, in the past, i could control the write options on AWS IAM level.  though doesnt provide full solution, as i need to grant write selectively)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Amit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 10:53:17 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14206#M513</guid>
      <dc:creator>amitca71</dc:creator>
      <dc:date>2022-12-29T10:53:17Z</dc:date>
    </item>
    <item>
      <title>Re: external location on unity catalog permits access to s3</title>
      <link>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14207#M514</link>
      <description>&lt;P&gt;@Amit Cahanovich​&amp;nbsp;: Could you please share your config details,&lt;/P&gt;&lt;P&gt;Which DBR version ?&lt;/P&gt;&lt;P&gt;Cluster has any instance profile?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 11:35:34 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14207#M514</guid>
      <dc:creator>Sivaprasad1</dc:creator>
      <dc:date>2022-12-29T11:35:34Z</dc:date>
    </item>
    <item>
      <title>Re: external location on unity catalog permits access to s3</title>
      <link>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14208#M515</link>
      <description>&lt;P&gt;@Sivaprasad C S​&amp;nbsp;11.2 (includes Apache Spark 3.3.0, Scala 2.12)&lt;/P&gt;&lt;P&gt;Instance profile =None&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 11:49:00 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14208#M515</guid>
      <dc:creator>amitca71</dc:creator>
      <dc:date>2022-12-29T11:49:00Z</dc:date>
    </item>
    <item>
      <title>Re: external location on unity catalog permits access to s3</title>
      <link>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14209#M516</link>
      <description>&lt;P&gt;what is the cluster mode?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please run below command and share results&lt;/P&gt;&lt;P&gt;uc permissions get --external-location &amp;lt;externallocationname&amp;gt; --profile &amp;lt;databricksprofile&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/dev-tools/cli/unity-catalog-cli.html#unity-catalog-cli" target="test_blank"&gt;https://docs.databricks.com/dev-tools/cli/unity-catalog-cli.html#unity-catalog-cli&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 18:15:14 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14209#M516</guid>
      <dc:creator>Sivaprasad1</dc:creator>
      <dc:date>2022-12-29T18:15:14Z</dc:date>
    </item>
    <item>
      <title>Re: external location on unity catalog permits access to s3</title>
      <link>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14210#M517</link>
      <description>&lt;P&gt;{&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"num_workers": 0,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"cluster_name": "xxxxxx",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"spark_version": "11.2.x-scala2.12",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"spark_conf": {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"spark.master": "local[*, 4]",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"spark.databricks.cluster.profile": "singleNode",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"spark.databricks.dataLineage.enabled": "true"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;},&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"aws_attributes": {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"first_on_demand": 1,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"availability": "SPOT_WITH_FALLBACK",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"zone_id": "us-east-2a",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"spot_bid_price_percent": 100,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"ebs_volume_count": 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;},&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"node_type_id": "i3.xlarge",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"driver_node_type_id": "i3.xlarge",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"ssh_public_keys": [],&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"custom_tags": {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"ResourceClass": "SingleNode"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;},&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"spark_env_vars": {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"DB_CLUSTER_NAME": "\"***_xxxx\"",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"DD_SITE": "\"datadoghq.com\"",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"DB_CLUSTER_ID": "\"***_xxxx\"",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"DD_ENV": "staging",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"PYSPARK_PYTHON": "/databricks/python3/bin/python3",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"DD_API_KEY": "3aa81ed18bc46a1f9cc425ee6c5ada78"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;},&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"autotermination_minutes": 120,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"enable_elastic_disk": true,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"cluster_source": "UI",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"init_scripts": [&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;{&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"dbfs": {&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;"destination": "dbfs:/FileStore/utils/datadog-install-driver-only.sh"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;],&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"single_user_name": "xxxx@***.***",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"data_security_mode": "SINGLE_USER",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"runtime_engine": "STANDARD",&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;"cluster_id": "0915-152649-ox2wxwwz"&lt;/P&gt;&lt;P&gt;}&lt;/P&gt;</description>
      <pubDate>Thu, 29 Dec 2022 18:19:00 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14210#M517</guid>
      <dc:creator>amitca71</dc:creator>
      <dc:date>2022-12-29T18:19:00Z</dc:date>
    </item>
    <item>
      <title>Re: external location on unity catalog permits access to s3</title>
      <link>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14211#M518</link>
      <description>&lt;P&gt;@Sivaprasad C S&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;databricks unity-catalog external-locations get --name lakehouse-input --profile DEFAULT&lt;/P&gt;&lt;P&gt;{&lt;/P&gt;&lt;P&gt;​&lt;/P&gt;&lt;P&gt;&amp;nbsp;"name": "xxxx",&lt;/P&gt;&lt;P&gt;&amp;nbsp;"url": "s3://xxxx",&lt;/P&gt;&lt;P&gt;&amp;nbsp;"credential_name": "databricks_unity_catalog",&lt;/P&gt;&lt;P&gt;&amp;nbsp;"read_only": false,&lt;/P&gt;&lt;P&gt;&amp;nbsp;"comment": "xxxxx",&lt;/P&gt;&lt;P&gt;&amp;nbsp;"owner": "xxxx@***.xx",&lt;/P&gt;&lt;P&gt;&amp;nbsp;"metastore_id": "xxxxxxxx",&lt;/P&gt;&lt;P&gt;&amp;nbsp;"credential_id": "94ce13xxxxxxxxx2e3545e5",&lt;/P&gt;&lt;P&gt;&amp;nbsp;"created_at": 1663136630885,&lt;/P&gt;&lt;P&gt;&amp;nbsp;"created_by": "xxxx.xxxx@***.***",&lt;/P&gt;&lt;P&gt;&amp;nbsp;"updated_at": 1663136630885,&lt;/P&gt;&lt;P&gt;&amp;nbsp;"updated_by": "xxxx.xxxx@***.***"&lt;/P&gt;&lt;P&gt;}Is it because i' m the owner of the credentials? &lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 14:28:15 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/external-location-on-unity-catalog-permits-access-to-s3/m-p/14211#M518</guid>
      <dc:creator>amitca71</dc:creator>
      <dc:date>2023-01-06T14:28:15Z</dc:date>
    </item>
  </channel>
</rss>

