Aidp Roles Access

作者 oracle-samples90b42d6c24d4无许可证收录于 2026年10月8日更新于 2026年10月8日

Manage AIDP roles and access — list roles, view permissions, create roles, add/remove members, and grant/revoke per-resource permissions on catalogs, schemas, tables, views, volumes, workspaces, workspace objects, and clusters. Also covers column masking/classification (restricted views + ontology sensitivity — no masking REST API exists). Use when the user asks about roles/RBAC, who can access what, granting/revoking access on any resource, adding someone to a role, or masking/classifying columns. Primary engine is the official `aidp` CLI; the same REST API via `oci raw-request` is the no-CLI fallback.

AI 生成的概览

管理 AIDP 角色与访问权限:列出角色、增删成员,以及授予或撤销各资源的权限。

功能
提供通过 aidp CLI 查看和管理 AIDP 基于角色的访问控制的说明,并以 oci raw-request 调用等效 REST API 作为无 CLI 时的备选方案。内容涵盖角色列出、查看、创建、更新与删除,成员变更,以及针对目录、模式、表、视图、卷、工作区、工作区对象、集群、作业和知识库的各资源权限授予。文档还说明不存在掩码 REST API,并建议以受限视图和本体敏感度作为实际的列级控制手段。变更类操作在应用前需要确认。
适用场景
当用户询问角色或 RBAC、谁可以访问什么、在 AIDP 资源上授予或撤销访问权限、将某人加入或移出角色,或对列进行掩码与分类时使用。
运行要求
需要 aidp CLI,并提供实例 ID、api_key 认证、配置文件和区域;或者使用 oci CLI 发起 raw-request REST 调用;需要访问 AIDP 区域端点的网络连接和有效凭据。可选地,可启用受控的 AIDP MCP 管理工具来执行权限写入。不附带脚本。

aidp-roles-access — roles, permissions, access (RBAC)

Inspect and manage AIDP RBAC.

CLI (preferred): aidp role <command> --instance-id <DATALAKE_OCID> --auth api_key --profile DEFAULT --region <r>

  • Roles: aidp role list | get | create | update | delete | add-member | remove-member | list-permissions
  • Per-resource grants: aidp <catalog|cluster|volume|schema|workspace|workspace-object> list-permissions | manage-permission

Fallback (no CLI): same Role REST API via oci raw-request (identical endpoint + auth). Permission writes (workspace/cluster/volume grants) can also use the gated MCP admin tools as an optional accelerator when configured.

Verify-first + least privilege: bind to the caller's identity; never escalate beyond what they have. Confirm the working path with a live aidp role list (or GET /roles) before any write. Auth + base URL: references/oci-raw-request.md.

When to use

  • "List roles / who has access", "create a role", "add/remove a member", "grant/revoke access to a workspace/cluster/volume".

Read & role CRUD (CLI preferred)

bash
# List roles (smoke test) — CLIaidp role list --instance-id <DATALAKE_OCID> --auth api_key --profile DEFAULT --region us-ashburn-1
# Add a member to a role — CLIaidp role add-member --instance-id <DATALAKE_OCID> --role-key <ROLE_KEY> \  --auth api_key --profile DEFAULT --region us-ashburn-1 \  --principals '["ocid1.user.oc1..xxxx"]'

Mutating ops (create, update, delete, add-member, remove-member, manage-permission): persist the body to .aidp/payloads/ and confirm first (references/payloads.md).

Fallback (no CLI) — REST via oci raw-request

Base: https://aidp.<region>.oci.oraclecloud.com/20240831/dataLakes/<DATALAKE_OCID>/…

  • List roles — GET /roles — ✅ LIVE-VERIFIED 200 (api_key DEFAULT profile, 20240831/dataLakes).
  • Inspect a role — GET /roles/{k}, GET /roles/{k}/permissions.
  • Create / update / delete — POST /roles, PUT /roles/{k}, DELETE /roles/{k} (send if-match: <etag> on PUT/DELETE).
  • Membership — POST /roles/{k}/actions/addMember · POST /roles/{k}/actions/removeMember (body e.g. {"principals":["ocid1.user.oc1..xxxx"]}).
bash
oci raw-request --http-method GET \  --target-uri "https://aidp.us-ashburn-1.oci.oraclecloud.com/20240831/dataLakes/<OCID>/roles" \  --profile DEFAULT

On 401/403/"Security Token", follow the auth ladder in oci-raw-request.md (refresh AIDP_SESSION).

Per-resource permission grants (full matrix)

Role CRUD + membership scope who is in a role; per-resource grants scope what a principal can do to one object. Every resource type exposes a list-permissions + manage-permission pair (CLI preferred; REST …/<resource>/<key>/permissions + …/actions/managePermission fallback). Grant body is consistently {"principals":[…], "permission":"<enum>", "action":"GRANT"|"REVOKE"} — confirm the exact permission enum for each resource via aidp help <resource> manage-permission / a live read before writing.

ResourceCLI verbsREST
Catalogaidp catalog list-permissions | manage-permission…/catalogs/<key>/permissions
Schemaaidp schema list-permissions | manage-permission…/schemas/<key>/permissions
Tableaidp schema list-table-permissions | manage-table-permission <TABLE-KEY>…/tables/<key>/permissions
Viewaidp schema list-view-permissions | manage-view-permission <VIEW-KEY>…/views/<key>/permissions
Volumeaidp volume list-permissions | manage-permission…/volumes/<key>/permissions
Workspaceaidp workspace list-permissions | manage-permission (+ list-create-permissions | manage-create-permission)…/workspaces/<key>/permissions
Workspace objectaidp workspace-object list-permissions | manage-permission…/workspaceObjects/<key>/permissions
Cluster(no GA CLI verb)…/clusters/<key>/permissions
Job/Workflowaidp workflow list-job-permissions <ws> <JOB-KEY> / manage-job-permission <ws> <JOB-KEY> --body…/workspaces/{ws}/jobs/{key}/permissions
Knowledge Baseassign|manage|revoke KB permission (aidp-knowledge-bases)…/knowledgeBases/<key>/permissions

Job/Workflow body shape differs from the generic grant. The CLI README + SDK confirm manage-job-permission does not take {principals,permission,action}. Its grant body is AssignJobPermissionDetails = {"assignees":{"type":"USER|ROLE|GROUP","targets":[…]},"permissions":["READ"|"USE"|"MANAGE"|"ADMIN"]} (permissions is a list aligned 1:1 with assignees.targets); the manage wrapper is {"assignJobPermissionDetails":{…},"revokeJobPermissionDetails":{…}}. Enum names are confirmed-citable (SDK assign_job_permission_details.py lines 18-30 / permission_assignees.py lines 18-26; CLI README workflow manage-job-permission, README lines 7315-7377); still confirm the live enum with aidp help workflow manage-job-permission or a list-job-permissions read before writing.

Optional accelerator: when a gated aidp MCP is configured (AIDP_MCP_ENABLE_ADMIN_TOOLS=true + MCP restart), manage_workspace_permission / manage_cluster_permission / manage_volume_permission / manage_create_workspace_permission wrap the same writes (details_json {"principals":[…],"permission":"WRITE","action":"GRANT"}). Not required — REST verbs above are the source of truth; or apply the grant in the console.

Column masking & classification (honest scope — no data-plane API found)

There is no programmatic masking/classification REST API in the tested tenancy — GET …/maskingPolicies, /dataClassifications, /columnMaskingPolicies, /tags all returned 404 (probed 2026-06-10; recorded in references/rest-endpoint-map.md). Do not fabricate one. What actually exists:

  • Restricted / redacting views — the practical column-level control today: CREATE VIEW exposing only permitted columns (or CASE/hashing to redact), then grant on the view, not the base table (aidp-sql-ddl
    • the View row above). This is the recommended pattern when asked to "mask a column".
  • Ontology-driven sensitivity — the Ontologies feature tags terms (av:isSensitive / av:requiresRole) for governance, but it is UI-driven with no confirmed REST surface here (see the Ontologies note in aidp-semantic-model). If the user needs policy-based dynamic masking, surface that it's UI/ontology-governed today and offer the restricted-view pattern as the API-driven equivalent — don't claim a masking endpoint.

Workflow

  1. Read current state first (GET /roles + the relevant role's /permissions).
  2. Show the exact grant/revoke (principal, permission, target) and confirm before applying.
  3. Apply via REST (role CRUD/membership), or the gated admin tool if it's available; re-read to confirm.

Guardrails

  • Access changes are sensitive — confirm every grant/revoke; never broaden beyond the user's request.
  • Don't propose IAM/permission changes that aren't explicitly asked for.

References

  • references/aidp-cli-map.md · references/payloads.md · references/oci-raw-request.md · references/no-mcp-rest-map.md · references/rest-endpoint-map.md

来源与署名

来源:oracle-samples/oracle-aidp-samples位于ai/claude-code-plugins/oracle-ai-data-platform-workbench-engineer-agent/skills/aidp-roles-access提交90b42d6

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 oracle-samples/oracle-aidp-samples 的技能

Aidp Workspace Admin

oracle-samples

Provision and inspect AIDP DataLake instances and workspaces, including private-network workspaces attached to a customer VCN/subnet. Use when the user wants to create/list/get a workspace or DataLake instance, set up a new (e.g. private) AIDP environment, or replicate a customer setup. Create/delete are guarded — confirm before any provisioning.

待分类2026年10月8日

Aidp Volumes

oracle-samples

Work with AIDP volumes — list volumes, browse files inside a volume, upload/download via the PAR flow, and create directories. Use when the user mentions volumes, needs to stage large/binary files, or move data in/out of a volume (distinct from the workspace filesystem). Control-plane via the official `aidp` CLI.

待分类2026年10月8日

Aidp Verified Queries

oracle-samples

维护经过验证的问题到 Spark SQL 配对库,让智能体在生成新 SQL 前优先复用可信查询。

Data & Analytics2026年10月8日

Aidp User Settings

oracle-samples

通过 aidp CLI 或 oci raw-request 备用方式管理 AIDP DataLake 用户设置与偏好。

Productivity & Workflow2026年10月8日

Aidp Spark Optimization

oracle-samples

指导 Apache Spark 3.5.0 性能调优:分区、shuffle、连接、倾斜、内存、文件布局、AQE 与 Delta Lake。

Data & Analytics2026年10月8日

Aidp Semantic Model

oracle-samples

维护 .aidp/semantic.md 业务语义层,定义指标、连接、同义词和值字典,为自然语言转 SQL 提供依据。

Data & Analytics2026年10月8日