AWS Glue Data Catalog 정책의 권한 점검

카탈로그를 사용할 주체와 필요한 작업·리소스만 허용하세요.

설명

Glue Data Catalog의 리소스 정책이 지나치게 넓으면 불필요한 주체가 데이터베이스·테이블 메타데이터를 조회하거나 변경할 수 있습니다. 이 정책을 Glue 잡이나 크롤러 자체의 관리 권한 또는 저장된 원본 데이터의 접근 권한과 혼동하면 안 됩니다.

잠재적 영향

  • 카탈로그 메타데이터의 불필요한 조회로 데이터 구조와 위치가 노출될 수 있습니다.
  • 테이블이나 데이터베이스 정의의 변경·삭제는 분석 및 데이터 처리 흐름을 중단시킬 수 있습니다.

해결 방법

  • 유효한 기존 IAM 주체와 실제 필요한 카탈로그 작업만 명시하세요.
  • 정책이 연결된 카탈로그의 ARN으로 범위를 좁히고, 작업에 필요한 데이터베이스·테이블 및 상위 리소스 권한을 포함하세요.
  • 다른 IAM·Lake Formation 권한과 기존 이용자를 함께 확인하고 정상 작업은 성공하며 불필요한 조회·변경은 거부되는지 시험하세요.

예시

같은 리소스 정책의 작업과 범위를 줄이는 발췌입니다. 참조 데이터 소스를 별도로 정의하고 역할 ARN과 example 데이터베이스 이름을 실제 값으로 바꾸세요. Glue는 유효한 기존 주체를 요구합니다.

변경 전

hcl
data "aws_iam_policy_document" "glue_example_policy" {
  statement {
    actions = [
      "glue:*",
    ]
    resources = ["arn:${data.aws_partition.current.partition}:glue:${data.aws_region.current.name}:${data.aws_caller_identity.current.account_id}:*"]
    principals {
      identifiers = ["arn:aws:iam::111122223333:role/catalog-writer"]
      type        = "AWS"
    }
  }
}

resource "aws_glue_resource_policy" "example" {
  policy = data.aws_iam_policy_document.glue_example_policy.json
}

지정한 역할에 카탈로그 전반의 광범위한 작업을 허용합니다. 필요한 역할이라도 작업과 대상 범위는 줄여야 합니다.

변경 후

hcl
data "aws_iam_policy_document" "glue_example_policy" {
  statement {
    actions = [
      "glue:CreateTable",
    ]
    resources = [
      "arn:${data.aws_partition.current.partition}:glue:${data.aws_region.current.name}:${data.aws_caller_identity.current.account_id}:catalog",
      "arn:${data.aws_partition.current.partition}:glue:${data.aws_region.current.name}:${data.aws_caller_identity.current.account_id}:database/example",
      "arn:${data.aws_partition.current.partition}:glue:${data.aws_region.current.name}:${data.aws_caller_identity.current.account_id}:table/example/*",
    ]
    principals {
      identifiers = ["arn:aws:iam::111122223333:role/catalog-writer"]
      type        = "AWS"
    }
  }
}

resource "aws_glue_resource_policy" "example" {
  policy = data.aws_iam_policy_document.glue_example_policy.json
}

example 데이터베이스의 테이블 생성으로 허용을 좁히고 필요한 상위 카탈로그·데이터베이스 ARN도 포함합니다. 원본 데이터 접근이나 잡 실행 권한은 별도로 검토하세요.

참조