Skip to content

Commit b3943a4

Browse files
committed
Warehouse Access Control
1 parent 303acdb commit b3943a4

File tree

2 files changed

+20
-0
lines changed

2 files changed

+20
-0
lines changed

docs/en/guides/20-cloud/10-using-databend-cloud/01-warehouses.md

Lines changed: 20 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -81,6 +81,26 @@ To effectively manage your warehouses and ensure optimal performance and cost-ef
8181
- **Monitor & Adjust Usage**
8282
- Regularly review warehouse usage and resize as needed to balance cost and performance.
8383

84+
## Warehouse Access Control
85+
86+
Databend Cloud allows you to manage warehouse access with role-based controls by assigning a specific role to a warehouse, so only users with that role can access the warehouse.
87+
88+
:::note
89+
Warehouse access control is *not* enabled out of the box. To enable it, go to **Support** > **Create New Ticket** and submit a request.
90+
:::
91+
92+
To assign a role to a warehouse, select the desired role in the **Advanced Options** during the warehouse creation or modification process:
93+
94+
![alt text](../../../../../static/img/documents/warehouses/warehouse-role.png)
95+
96+
- The two [Built-in Roles](../../56-security/access-control/02-roles.md#built-in-roles) are available for selection, and you can also create additional roles using the [CREATE ROLE](/sql/sql-commands/ddl/user/user-create-role) command. For more information about Databend roles, see [Roles](../../56-security/access-control/02-roles.md).
97+
- Warehouses without an assigned role default to the `public` role, allowing access to all users.
98+
- You can grant a role to a user (Databend Cloud login email or SQL user) using the [GRANT](/sql/sql-commands/ddl/user/grant) command, or, alternatively, assign a role when inviting the user to your organization. For more information, see [Inviting New Members](00-organization.md#inviting-new-members). This example grants the role `manager` to the user with the email `[email protected]`, allowing access to any warehouse assigned to the `manager` role:
99+
100+
```sql title='Examples:'
101+
GRANT ROLE manager to '[email protected]';
102+
```
103+
84104
## Multi-Cluster Warehouses
85105

86106
A multi-cluster warehouse automatically adjusts compute resources by adding or removing clusters based on workload demand. It ensures high concurrency and performance while optimizing cost by scaling up or down as needed.
40.4 KB
Loading

0 commit comments

Comments
 (0)