â01-12-2023 08:14 AM
My org is considering a transition from hive metastore to unity catalog. We currently have a workspace for each of dev/uat/production and each of those provide access to their respective blob storage account data. Unity Catalog sits at the account-level and bridges the workspaces; which seem to enable a user (with justifiable access to all envs) to access prod data from any workspace as there doesn't seem to be a way to deny a user the ability to switch catalog (or even set what the default catalog is) within a particular workspace. How can we steer/force users to use each environment-specific workspace as intended?
â01-12-2023 08:36 AM
Hi @James Hâ ,
I believe you're describing something that will be addressed with a feature called "Catalog to workspace bindings". For example, only prod data can be accessed in prod workspaces. This feature is slated to be released hopefully by the end of January
â02-03-2023 07:23 PM
This would be really great. Iâm helping a client build a new lakehouse in Azure and this is one of the only things Iâm stuck on with the proposed architecture. Catalog to workspace binding would really solve that problem.
in the interim, is there any way to leverage cluster policies to force the default catalog on a cluster and prevent the user from changing it?
â05-05-2023 08:32 AM
Hi @Landan Georgeâ - Is "Catalog to workspace bindings" available? I cannot find any documentation on it.
â01-12-2023 12:09 PM
Hi, Please refer : https://docs.databricks.com/data-governance/unity-catalog/manage-privileges/index.html and let us know if this helps.
â01-13-2023 01:42 AM
I did find this document which indicates that you can set the initial catalog on cluster start:: https://learn.microsoft.com/en-us/azure/databricks/data-governance/unity-catalog/hive-metastore#diff...
Join a Regional User Group to connect with local Databricks users. Events will be happening in your city, and you wonât want to miss the chance to attend and share knowledge.
If there isnât a group near you, start one and help create a community that brings people together.
Request a New Group