Skip to content

aws.glue.get_data_catalog_encryption_settings

Example SQL Queries

SELECT * FROM
aws.glue.get_data_catalog_encryption_settings;

Description

Retrieves the security configuration for a specified catalog.

Table Definition

Column NameColumn Data Type
catalog_id Input Column

The ID of the Data Catalog to retrieve the security configuration for. If none is provided, the Amazon Web Services account ID is used by default.

VARCHAR
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
data_catalog_encryption_settings

The requested security configuration.

STRUCT(
"encryption_at_rest" STRUCT(
"catalog_encryption_mode" VARCHAR,
"sse_aws_kms_key_id" VARCHAR,
"catalog_encryption_service_role" VARCHAR
),
"connection_password_encryption" STRUCT(
"return_connection_password_encrypted" BOOLEAN,
"aws_kms_key_id" VARCHAR
)
)
Show child fields
data_catalog_encryption_settings.connection_password_encryption

When connection password protection is enabled, the Data Catalog uses a customer-provided key to encrypt the password as part of CreateConnection or UpdateConnection and store it in the ENCRYPTED_PASSWORD field in the connection properties. You can enable catalog encryption or only password encryption.

Show child fields
data_catalog_encryption_settings.connection_password_encryption.aws_kms_key_id

An KMS key that is used to encrypt the connection password.

If connection password protection is enabled, the caller of CreateConnection and UpdateConnection needs at least kms:Encrypt permission on the specified KMS key, to encrypt passwords before storing them in the Data Catalog.

You can set the decrypt permission to enable or restrict access on the password key according to your security requirements.

data_catalog_encryption_settings.connection_password_encryption.return_connection_password_encrypted

When the ReturnConnectionPasswordEncrypted flag is set to "true", passwords remain encrypted in the responses of GetConnection and GetConnections. This encryption takes effect independently from catalog encryption.

data_catalog_encryption_settings.encryption_at_rest

Specifies the encryption-at-rest configuration for the Data Catalog.

Show child fields
data_catalog_encryption_settings.encryption_at_rest.catalog_encryption_mode

The encryption-at-rest mode for encrypting Data Catalog data.

data_catalog_encryption_settings.encryption_at_rest.catalog_encryption_service_role

The role that Glue assumes to encrypt and decrypt the Data Catalog objects on the caller's behalf.

data_catalog_encryption_settings.encryption_at_rest.sse_aws_kms_key_id

The ID of the KMS key to use for encryption at rest.