Lakehouse for Apache Iceberg 可让您使用 Cloud Audit Logs 检查 Lakehouse 运行时目录 中 Apache Iceberg REST 目录端点 的管理活动和数据访问权限活动的可验证记录。
这些日志会跟踪操作生命周期事件、政策更新和身份验证更改。
准备工作
- 阅读 关于 Lakehouse 运行时目录,了解 Lakehouse 运行时目录的工作原理以及该服务的限制。
- Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
-
Create a project: To create a project, you need the Project Creator role
(
roles/resourcemanager.projectCreator), which contains theresourcemanager.projects.createpermission. Learn how to grant roles.
In the Google Cloud console, on the project selector page, select or create a Google Cloud project.
Roles required to select or create a project
Verify that billing is enabled for your Google Cloud project.
Enable the BigLake API.
Roles required to enable APIs
To enable APIs, you need the serviceusage.services.enable permission. If you
created the project, then you likely already have this permission through the
Owner role (roles/owner). Otherwise, you can get this permission through the
Service Usage Admin role (roles/serviceusage.serviceUsageAdmin).
Learn how to grant roles.
所需的角色
如需获得在 控制台中查看审核日志所需的权限,请让您的管理员向您授予项目的以下 IAM 角色: Google Cloud
- BigLake Admin (
roles/biglake.admin) - Storage Admin (
roles/storage.admin)
如需详细了解如何授予角色,请参阅管理对项目、文件夹和组织的访问权限。
您也可以通过自定义 角色或其他预定义 角色来获取所需的权限。
查看审核日志
在 Google Cloud 控制台中,打开 Lakehouse 页面。
在您要查看的目录所在的行中,依次点击 更多目录操作 > 查看审核日志。