Description
An overly broad Glue Data Catalog resource policy can let unnecessary principals read or change database and table metadata. Do not confuse this policy with permission to administer Glue jobs or crawlers, or to access the underlying stored data.
Potential impact
- Unnecessary catalog reads can expose data structures and locations.
- Changing or deleting table and database definitions can interrupt analytics and data-processing workflows.
Remediation
- Specify valid existing IAM principals and only the catalog actions that are needed.
- Scope resources to the catalog associated with the policy, including database, table and ancestor permissions required by each action.
- Review other IAM and Lake Formation permissions and existing users, then test that intended operations succeed while unnecessary reads and changes are denied.
Examples
These excerpts narrow actions and resources in the same resource policy. Define the referenced data sources separately and replace the role ARN and example database name with actual values. Glue requires valid existing principals.
Before
data "aws_iam_policy_document" "glue_example_policy" {
statement {
actions = [
"glue:*",
]
resources = ["arn:${data.aws_partition.current.partition}:glue:${data.aws_region.current.name}:${data.aws_caller_identity.current.account_id}:*"]
principals {
identifiers = ["arn:aws:iam::111122223333:role/catalog-writer"]
type = "AWS"
}
}
}
resource "aws_glue_resource_policy" "example" {
policy = data.aws_iam_policy_document.glue_example_policy.json
}
This grants the specified role broad actions across the catalog. Even a necessary role should be limited to the actions and resources it needs.
After
data "aws_iam_policy_document" "glue_example_policy" {
statement {
actions = [
"glue:CreateTable",
]
resources = [
"arn:${data.aws_partition.current.partition}:glue:${data.aws_region.current.name}:${data.aws_caller_identity.current.account_id}:catalog",
"arn:${data.aws_partition.current.partition}:glue:${data.aws_region.current.name}:${data.aws_caller_identity.current.account_id}:database/example",
"arn:${data.aws_partition.current.partition}:glue:${data.aws_region.current.name}:${data.aws_caller_identity.current.account_id}:table/example/*",
]
principals {
identifiers = ["arn:aws:iam::111122223333:role/catalog-writer"]
type = "AWS"
}
}
}
resource "aws_glue_resource_policy" "example" {
policy = data.aws_iam_policy_document.glue_example_policy.json
}
This narrows the grant to table creation in the example database and includes the required catalog and database ancestor ARNs. Review underlying data access and job execution permissions separately.