Skip to content

aws.lakeformation.get_temporary_glue_table_credentials

Example SQL Queries

SELECT * FROM
aws.lakeformation.get_temporary_glue_table_credentials
WHERE
"table_arn" = 'VALUE';

Description

Allows a caller in a secure environment to assume a role with permission to access Amazon S3. In order to vend such credentials, Lake Formation assumes the role associated with a registered location, for example an Amazon S3 bucket, with a scope down policy which restricts the access to a single prefix.

Table Definition

Column NameColumn Data Type
table_arn Required Input Column

The ARN identifying a table in the Data Catalog for the temporary credentials request.

VARCHAR
audit_context Input Column

A structure representing context to access a resource (column names, query ID, etc).

STRUCT(
"additional_audit_context" VARCHAR
)
Show child fields
audit_context.additional_audit_context

The filter engine can populate the 'AdditionalAuditContext' information with the request ID for you to track. This information will be displayed in CloudTrail log in your account.

duration_seconds Input Column

The time period, between 900 and 21,600 seconds, for the timeout of the temporary credentials.

BIGINT
permissions Input Column

Filters the request based on the user having been granted a list of specified permissions on the requested resource(s).

VARCHAR[]
Show child fields
permissions[]
query_session_context Input Column

A structure used as a protocol between query engines and Lake Formation or Glue. Contains both a Lake Formation generated authorization identifier and information from the request's authorization context.

STRUCT(
"query_id" VARCHAR,
"query_start_time" TIMESTAMP_S,
"cluster_id" VARCHAR,
"query_authorization_id" VARCHAR,
"additional_context" MAP(VARCHAR, VARCHAR)
)
Show child fields
query_session_context.additional_context

An opaque string-string map passed by the query engine.

query_session_context.cluster_id

An identifier string for the consumer cluster.

query_session_context.query_authorization_id

A cryptographically generated query identifier generated by Glue or Lake Formation.

query_session_context.query_id

A unique identifier generated by the query engine for the query.

query_session_context.query_start_time

A timestamp provided by the query engine for when the query started.

s3_path Input Column

The Amazon S3 path for the table.

VARCHAR
supported_permission_types Input Column

A list of supported permission types for the table. Valid values are COLUMN_PERMISSION and CELL_FILTER_PERMISSION.

VARCHAR[]
Show child fields
supported_permission_types[]
_aws_profile Input Column

The AWS profile defines the AWS identity used. It can be defined via credentials or by assuming a IAM role.

STRUCT(
"type" VARCHAR,
"name" VARCHAR,
"account_id" VARCHAR,
"via_profile_name" VARCHAR,
"assumed_role_arn" VARCHAR,
"organization" STRUCT(
"account_name" VARCHAR,
"id" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[],
"master_account" STRUCT(
"id" VARCHAR,
"email" VARCHAR
),
"parents" STRUCT(
"type" VARCHAR,
"id" VARCHAR,
"name" VARCHAR,
"tags" STRUCT(
"key" VARCHAR,
"value" VARCHAR
)[]
)[]
)
)
Show child fields
_aws_profile.account_id

The AWS account id

_aws_profile.assumed_role_arn

The ARN of the assumed role

_aws_profile.name

The unique name of the profile.

_aws_profile.organization

Information about this profile's membership in the AWS organization.

Show child fields
_aws_profile.organization.account_name

The name of account speciifed by the organization

_aws_profile.organization.id

The organization id

_aws_profile.organization.master_account
Show child fields
_aws_profile.organization.master_account.email

The organization master account email address

_aws_profile.organization.master_account.id

The organization master account id

_aws_profile.organization.parents[]
Show child fields
_aws_profile.organization.parents[].id

The id of the parent

_aws_profile.organization.parents[].name

The name of the parent

_aws_profile.organization.parents[].tags[]
Show child fields
_aws_profile.organization.parents[].tags[].key
_aws_profile.organization.parents[].tags[].value
_aws_profile.organization.parents[].type

The type of parent can be an organization unit or a root

_aws_profile.organization.tags[]
Show child fields
_aws_profile.organization.tags[].key
_aws_profile.organization.tags[].value
_aws_profile.type

The type of profile, either 'credentials' or 'assumed_role'

_aws_profile.via_profile_name

This IAM role for this profile is assumed by first utilizing another profile with this name to obtain credentials.

_aws_region Input Column

The AWS region to use.

VARCHAR
access_key_id

The access key ID for the temporary credentials.

VARCHAR
expiration

The date and time when the temporary credentials expire.

TIMESTAMP_S
secret_access_key

The secret key for the temporary credentials.

VARCHAR
session_token

The session token for the temporary credentials.

VARCHAR
vended_s3_path

The Amazon S3 path for the temporary credentials.

VARCHAR[]
Show child fields
vended_s3_path[]