Skip to content

aws.lakeformation.get_temporary_glue_partition_credentials

Example SQL Queries

SELECT * FROM
aws.lakeformation.get_temporary_glue_partition_credentials
WHERE
"table_arn" = 'VALUE'
AND "partition" = 'VALUE';

Description

This API is identical to GetTemporaryTableCredentials except that this is used when the target Data Catalog resource is of type Partition. Lake Formation restricts the permission of the vended credentials with the same scope down policy which restricts access to a single Amazon S3 prefix.

Table Definition

Column NameColumn Data Type
partition Required Input Column

A list of partition values identifying a single partition.

STRUCT(
"values" VARCHAR[]
)
Show child fields
partition.values[]
table_arn Required Input Column

The ARN of the partitions' table.

VARCHAR
audit_context Input Column

A structure representing context to access a resource (column names, query ID, etc).

STRUCT(
"additional_audit_context" VARCHAR
)
Show child fields
audit_context.additional_audit_context

The filter engine can populate the 'AdditionalAuditContext' information with the request ID for you to track. This information will be displayed in CloudTrail log in your account.

duration_seconds Input Column

The time period, between 900 and 21,600 seconds, for the timeout of the temporary credentials.

BIGINT
permissions Input Column

Filters the request based on the user having been granted a list of specified permissions on the requested resource(s).

VARCHAR[]
Show child fields
permissions[]
supported_permission_types Input Column

A list of supported permission types for the partition. Valid values are COLUMN_PERMISSION and CELL_FILTER_PERMISSION.

VARCHAR[]
Show child fields
supported_permission_types[]
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
access_key_id

The access key ID for the temporary credentials.

VARCHAR
expiration

The date and time when the temporary credentials expire.

TIMESTAMP_S
secret_access_key

The secret key for the temporary credentials.

VARCHAR
session_token

The session token for the temporary credentials.

VARCHAR