- What's New
- Function Overview
- Service Overview
- Getting Started
- User Guide
- Best Practices
- Developer Guide
-
API Reference
- Before You Start
- API Overview
- API Calling
-
API
-
Console
- Instance Management
- Job Management
-
Service Authorization Management
- Granting Permissions for Accessing Other Cloud Services
- Querying Cloud Service Access Permissions
- Registering a Tenant Agreement
- Querying whether a Tenant Has Registered an Agreement
- Deleting a Tenant Agreement
- Registering a Tenant Agreement
- Querying whether a Tenant Has Registered an Agreement
- Deleting a Tenant Agreement
- Querying the Current System Agreement
- OBS Management
- Access Management
- Specification Management
- Quota Management Service
- Tag Management Service
- Agency Management
- Alarm Management
- Metadata Management
- Location
-
LakeCat
- Function Management
- Catalog Management
- Database Management
- Table Management
- Data Table Statistics
- Zone-based Management
- Partition Statistics
- Authorization Management
- User Group Management
- Metadata Statistics
-
Role Management
- Creating a Role
- Listing Roles on Different Pages by Condition
- Deleting a Role
- Obtaining a Role
- Modifying a Role
- Listing All Role Names
- Querying the Users or User groups Under a Role
- Adding One or More Users or User Groups to a Role
- Removing One or More Users or User Groups from a Role
- Updating the Entities in a Role
- Credential Management
- Configuration Management
- User
-
Console
- Application Examples
- Permissions and Supported Actions
- Appendix
- FAQs
- General Reference
Copied.
Identity Authentication and Access Control
Identity Authentication
- IAM users of the current tenant access LakeFormation on the console.
LakeFormation authenticates IAM tokens in HTTPS requests delivered by the console to identify tenants and IAM users. If the authentication fails, the request is rejected.
- On the console, IAM users of other tenants switch to the agency role of the current tenant to access LakeFormation.
LakeFormation authenticates the IAM token in the HTTPS request delivered by the console to identify the delegating tenant, agency, delegated tenant, and delegated IAM user. If the authentication fails, the request is rejected.
- Instances or clusters of other cloud services (such as MRS) access LakeFormation as an agency of the current tenant.
LakeFormation authenticates the IAM token in the HTTPS request delivered by the console to identify the delegating tenant (local tenant), agency, delegated tenant (ECS account), and delegated IAM user (built-in user of ECS). If the authentication fails, the request is rejected.
Asset Access Control
- Metadata
When you request metadata access from the console or other cloud services, you first need to verify your identity. Then, IAM authentication checks if you have the permission to operate on the metadata in the request. Finally, fine-grained authentication further verifies your permission to operate on the specific metadata in the request. If the authentication fails, the request is rejected.
- Data permission policy
When you request metadata access from the console or other cloud services, you first need to verify your identity. Then, IAM authentication checks if you have the operation permissions specified in the request. If the authentication fails, the request is rejected.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot