Step 7: Grant data permissions
You must grant permissions to create metadata tables in the Data Catalog. Because the workflow
will run with the role LakeFormationWorkflowRole
, you must grant these permissions
to the role.
-
In the Lake Formation console, in the navigation pane, under Data catalog, choose Databases.
-
Choose the
lakeformation_cloudtrail
database, then, from the Actions drop-down list, choose Grant under the heading Permissions. -
In the Grant data permissions dialog box, make these selections:
-
Under Principals, for IAM user and roles, choose
LakeFormationWorkflowRole
. -
Under LF-Tags or catalog resources, choose Named data catalog resources.
-
For Databases, you should see that the
lakeformation_cloudtrail
database is already added. -
Under Database permissions, select Create table, Alter, and Drop, and clear Super if it is selected.
Your Grant data permissions dialog box should now look like this screenshot.
-
-
Choose Grant.
For more information about granting Lake Formation permissions, see Managing Lake Formation permissions.