ministryofjustice / analytical-platform

Analytical Platform • This repository is defined and managed in Terraform
https://docs.analytical-platform.service.justice.gov.uk
MIT License
8 stars 4 forks source link

📖 Carry out tests on Lake Formation Hybrid Mode #4359

Closed julialawrence closed 1 month ago

julialawrence commented 3 months ago

User Story

As an AP Engineer, I would like to test out managing a datasource simultaneously using IAM and LakeFormation with both modes enforced rather than only IAM in a way that doesn't break the current permission setup.

Value / Purpose

Using hybrid mode will allow a gradual migration to Lake Formation for permissions management without outright blocking the current setup. This will make the migration process less painful for users and operators.

Useful Contacts

@julialawrence

User Types

Data Engineers, AP Engneers

Hypothesis

If we are able to successfully test and document use of hybrid mode, we can apply it both to Digital Prisons Reporting work and put it towards replacement of of database-access repository.

Proposal

Use an existing glue table/darabase in our ap-dev account and test managing permissions in hybrid mode.

Test the following scenarios:

Additional Information

https://docs.aws.amazon.com/lake-formation/latest/dg/hybrid-access-mode.html

Definition of Done

BrianEllwood commented 1 month ago

The findings are in this document