Skip to content

Conversation

@martyngigg
Copy link
Contributor

Summary

Introduce the OpenFGA as an authorization backend for Lakekeeper. This enables fine-grained permissions with the Lakekeeper warehouses. On bootstrapping Lakekeeper the following happens:

  • a Lakekeeper admin user, supplied as an argument to the ansible playbook, is defined
  • the trino service account is given read access to the warehouses.

The Admin user must use the Lakekeeper UI or REST API to define other permissions. Further work will define more granular permissions in #135 and related issues.

Refs #211

@martyngigg martyngigg changed the title feat: Lakekeeper openfga feat: Enable fine-grained permissions in Lakekeeper catalog Feb 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant