<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AWS Unity Catalog S3 Bucket Security in Data Governance</title>
    <link>https://community.databricks.com/t5/data-governance/aws-unity-catalog-s3-bucket-security/m-p/14269#M520</link>
    <description>&lt;P&gt;Hi, Could you please confirm if you have followed this: &lt;A href="https://docs.databricks.com/data-governance/unity-catalog/get-started.html" target="test_blank"&gt;https://docs.databricks.com/data-governance/unity-catalog/get-started.html&lt;/A&gt; , also, please confirm the exact error received? &lt;/P&gt;</description>
    <pubDate>Mon, 02 Jan 2023 18:08:04 GMT</pubDate>
    <dc:creator>Debayan</dc:creator>
    <dc:date>2023-01-02T18:08:04Z</dc:date>
    <item>
      <title>AWS Unity Catalog S3 Bucket Security</title>
      <link>https://community.databricks.com/t5/data-governance/aws-unity-catalog-s3-bucket-security/m-p/14268#M519</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I've got Unity Catalog working but i cant create an external Table.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have several Workspaces (with customer managed VPCs), all with Private Link  connected to the Control Plane. Our Data S3 Buckets are secured via Bucket Policy (in addition to KMS) so only connections from the Control Plane and our own VPC Endpoints can do something  as described here:&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.databricks.com/administration-guide/cloud-configurations/aws/customer-managed-vpc.html#example-bucket-policy-vpce" target="test_blank"&gt;https://docs.databricks.com/administration-guide/cloud-configurations/aws/customer-managed-vpc.html#example-bucket-policy-vpce&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we need the Control Plane in there because of Commit Service &lt;A href="https://docs.databricks.com/administration-guide/cloud-configurations/aws/s3-commit-service.html" target="test_blank"&gt;https://docs.databricks.com/administration-guide/cloud-configurations/aws/s3-commit-service.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;its working without unity catalog (writing into the hive_metastore catalog), but as soon as we try to write through unity catalog we get a s3 permission denied. we can get it working by disabling the commit-service related restrictions but then our buckets are completely open to the control plane.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my Question, why does the control plane need to write directly to our buckets with unity catalog and why isnt our own cluster writing the data with the associated iam_role? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;or does unity catalog with commit-service need some more exception than:&lt;/P&gt;&lt;P&gt;"arn:aws:s3:::&amp;lt;bucket-name&amp;gt;/*_delta_log/*",&lt;/P&gt;&lt;P&gt;"arn:aws:s3:::&amp;lt;bucket-name&amp;gt;/*_spark_metadata/*",&lt;/P&gt;&lt;P&gt;"arn:aws:s3:::&amp;lt;bucket-name&amp;gt;/*offsets/*",&lt;/P&gt;&lt;P&gt;"arn:aws:s3:::&amp;lt;bucket-name&amp;gt;/*sources/*",&lt;/P&gt;&lt;P&gt;"arn:aws:s3:::&amp;lt;bucket-name&amp;gt;/*sinks/*",&lt;/P&gt;&lt;P&gt;"arn:aws:s3:::&amp;lt;bucket-name&amp;gt;/*_schemas/*"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you in advance &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2022 17:58:22 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/aws-unity-catalog-s3-bucket-security/m-p/14268#M519</guid>
      <dc:creator>viSual</dc:creator>
      <dc:date>2022-12-28T17:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: AWS Unity Catalog S3 Bucket Security</title>
      <link>https://community.databricks.com/t5/data-governance/aws-unity-catalog-s3-bucket-security/m-p/14269#M520</link>
      <description>&lt;P&gt;Hi, Could you please confirm if you have followed this: &lt;A href="https://docs.databricks.com/data-governance/unity-catalog/get-started.html" target="test_blank"&gt;https://docs.databricks.com/data-governance/unity-catalog/get-started.html&lt;/A&gt; , also, please confirm the exact error received? &lt;/P&gt;</description>
      <pubDate>Mon, 02 Jan 2023 18:08:04 GMT</pubDate>
      <guid>https://community.databricks.com/t5/data-governance/aws-unity-catalog-s3-bucket-security/m-p/14269#M520</guid>
      <dc:creator>Debayan</dc:creator>
      <dc:date>2023-01-02T18:08:04Z</dc:date>
    </item>
  </channel>
</rss>

