Heya all, we (<Checkout.com>) built an access requ...
# contribute-code
q
Heya all, we (Checkout.com) built an access request feature through DataHub and was wondering if there’s any interest in receiving a contribution from us on it? This is what we’ve done: 1. Extend the metadata model to include an aspect called
accessRequest
and
accessRequests
where an
accessRequest
contains an
auditStamp
and a stringMap of
additionalMetadata
(similar to custom properties). 2. We attached
accessRequests
to
datasets
,
containers
and
dataProducts
3. We implemented a graphQL query
addAccessRequest
which takes looks like this
Copy code
mutation addAccessRequest {
  addAccessRequest(input: {
    resourceUrn: "urn:li:dataset:(urn:li:dataPlatform:hive,SampleHiveDataset,PROD)"
    additionalMetadata: [
      {
        key: "why2"
        value: "I need it"
      },
      {
        key: "who"
        value: "The Data Platform group"
      }
    ]
  })
}
4. We also implemented a button that contains a form that looks like (image attached) which submits the addAccessRequest ticket. (This could likely be made more modular by someone else) 5. Finally we have an action that runs that takes tickets and assigns them to a freshservice queue based on the domain attached (but we could contribute a simpler version that just requires a group_id and freshservice_api key in the config (or as secrets). Not sure which components of these would be useful for other people, but I thought it would at least start a discussion!
plus1 5
blob excited 2
💯 1
👌 4
b
Based on this https://datahubspace.slack.com/archives/C02FWNS2F08/p1705368393571739 there is something similar in the works, though the details on the item is vague
b
@quiet-television-68466 this looks really nice 👌
w
This looks fantastic! 💪 Certainly a feature I would love to see in DataHub! I have a couple of comments I'd like to go through • Request is half of the problem. What about the approval step? • This may link somehow with the recently implemented access policies so once a request is approved for a given role, the corresponding access policy is created. Any plans or ideas for that?
m
This looks great @quiet-television-68466 - we would love to help with getting this in 🙂
both the model extensions and the actions seem like great contribs
q
Heya so we are handling the approval and provision of access outside of DataHub, all our action does is to submit a Freshservice ticket for data owners to action manually. For some additional context we’re working on creating an attribute policy builder yaml file where people build access policies in their own repository based on the users attributes (their team, their department etc) and then we reconcile access based on that over time. Not sure I know much about the access policies that were implemented, I would have to take a look at that, but I’m guessing we could add an attribute APPROVED/REJECT/PENDING to the access policy that can be updated via the data owner which could then trigger creating the access policy. I’ll get a PR today hopefully to contribute at least the model extension for today and link it here when its up.
Apologies for the delay (had some gradle build issues), but I have a PR here now: (this is just for the graphQL and model changes) https://github.com/datahub-project/datahub/pull/9728
Anything else you guys need from me in this PR to get this merged? Didn’t see any tests written for the other mutations similar to this one.
m
Hey @quiet-television-68466 - sorry I missed this message. We're looking at the PR this week.