← 数据产品设计库

数据平台 · 产品截图

SageMaker Unified Studio + Lake Formation

当湖仓增长到数千张表和多个数据域时,逐表授权容易产生权限漂移,分析用户也难以理解为何同一查询对不同身份的结果不同。

做治理 · 治理与评估
SageMaker Unified Studio results: Sarah’s successful query on us_sales_summary查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · SageMaker Unified Studio results: Sarah’s successful query on us_sales_summary

配图 01 / 12

代表界面

要解决的问题
当湖仓增长到数千张表和多个数据域时,逐表授权容易产生权限漂移,分析用户也难以理解为何同一查询对不同身份的结果不同。
可以借鉴 · DataHot 解读

权限产品的验收案例应同时包含应当成功和应当失败的任务。

Architecture linking IAM Identity Center, SageMaker Unified Studio, Lake Formation, the Glue Data Catalog, and Amazon S3查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · Architecture linking IAM Identity Center, SageMaker Unified Studio, Lake Formation, the Glue Data Catalog, and Amazon S3

配图 02 / 12

原文配图 2

配图说明
Architecture linking IAM Identity Center, SageMaker Unified Studio, Lake Formation, the Glue Data Catalog, and Amazon S3
Lake Formation Data Catalog settings with both IAM-only access control checkboxes cleared查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · Lake Formation Data Catalog settings with both IAM-only access control checkboxes cleared

配图 03 / 12

原文配图 3

配图说明
Lake Formation Data Catalog settings with both IAM-only access control checkboxes cleared
CloudFormation console showing all seven CDK stacks in CREATE_COMPLETE status查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · CloudFormation console showing all seven CDK stacks in CREATE_COMPLETE status

配图 04 / 12

原文配图 4

配图说明
CloudFormation console showing all seven CDK stacks in CREATE_COMPLETE status
Lake Formation Data lake locations page listing the registered raw and curated S3 buckets查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · Lake Formation Data lake locations page listing the registered raw and curated S3 buckets

配图 05 / 12

原文配图 5

配图说明
Lake Formation Data lake locations page listing the registered raw and curated S3 buckets
AWS Glue Data Catalog showing the six databases and tables created by the deployment查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · AWS Glue Data Catalog showing the six databases and tables created by the deployment

配图 06 / 12

原文配图 6

配图说明
AWS Glue Data Catalog showing the six databases and tables created by the deployment
Athena query results showing sample commercial rows from the us_sales_summary table查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · Athena query results showing sample commercial rows from the us_sales_summary table

配图 07 / 12

原文配图 7

配图说明
Athena query results showing sample commercial rows from the us_sales_summary table
Governance automation flow with the asset tagging and SSO permission Lambda pipelines查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · Governance automation flow with the asset tagging and SSO permission Lambda pipelines

配图 08 / 12

原文配图 8

配图说明
Governance automation flow with the asset tagging and SSO permission Lambda pipelines
Lake Formation console showing inherited and table-level LF-Tags on the us_sales_summary table查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · Lake Formation console showing inherited and table-level LF-Tags on the us_sales_summary table

配图 09 / 12

原文配图 9

配图说明
Lake Formation console showing inherited and table-level LF-Tags on the us_sales_summary table
Access denied error when Sarah queries eu_drug_discovery outside her domain查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · Access denied error when Sarah queries eu_drug_discovery outside her domain

配图 10 / 12

原文配图 10

配图说明
Access denied error when Sarah queries eu_drug_discovery outside her domain
Query results showing Dr. Chen’s successful query on eu_drug_discovery查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · Query results showing Dr. Chen’s successful query on eu_drug_discovery

配图 11 / 12

原文配图 11

配图说明
Query results showing Dr. Chen’s successful query on eu_drug_discovery
Access denied error when Dr. Chen queries us_sales_summary查看完整原图 ↗
产品截图 · AWS Big Data Blog ↗ · Access denied error when Dr. Chen queries us_sales_summary

配图 12 / 12

原文配图 12

配图说明
Access denied error when Dr. Chen queries us_sales_summary

代表图优先,其余配图保留原文顺序;配图不代表一次连续操作。材料核对于 2026-08-07 · 阅读完整原文 →

设计拆解

公开材料说明

  • AWS 参考方案结合 IAM Identity Center、Lake Formation 标签访问控制和 Unified Studio 信任身份传播。
  • 方案使用 LF-Tags 分类数据,将用户组映射到标签策略,并在查询时由分析引擎强制执行权限。
  • 官方演练用多个人物验证同域查询成功、跨域查询被拒绝,并使用 CloudTrail 记录数据访问。

DataHot 解读

  • 用成功与拒绝的对照状态演示权限,比只展示策略配置页更容易让产品、安全和业务共同验收。
  • 数据探索器只显示身份可使用的资产,将最小权限从后台规则转化为前台信息架构。

功能模块

  • IAM Identity Center 用户与组
  • LF-Tag 数据分类
  • 基于标签的访问策略
  • Unified Studio 数据探索器
  • SQL 查询与允许/拒绝状态

交互方式 · 案例整理

  • 为数据资产继承或补充 LF-Tags
  • 将 Identity Center 组映射到标签策略
  • 用不同业务身份进入 Unified Studio 查询各自数据域
  • 对比授权查询的结果与跨域查询的拒绝反馈

可以借鉴

  • 权限产品的验收案例应同时包含应当成功和应当失败的任务。
  • 政策配置、用户可见资产和查询时反馈是同一权限体验的三个层次,需要用一致的身份与数据域语言连接。

收益与代价

  • 标签策略能随数据集扩展,但前提是标签分类准确、继承关系清晰且异常变更可审计。
  • 拒绝访问可以保护数据,但若只返回通用错误,用户会难以区分是权限、资产或查询本身的问题。

适用边界参考实现面向 S3 上的 Iceberg 表、Glue Data Catalog 与 AWS 分析引擎,不是跨所有数据平台的通用权限模型。 演示人物和数据域是参考场景,真实组织还需要权限申请、审批和应急访问流程。

资料出处

阅读站内原文 →

对你的产品设计有帮助吗?

反馈与收藏分开保存在当前设备。

查看界面