Aidp Roles Access

作者 oracle-samples90b42d6c24d4無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Manage AIDP roles and access — list roles, view permissions, create roles, add/remove members, and grant/revoke per-resource permissions on catalogs, schemas, tables, views, volumes, workspaces, workspace objects, and clusters. Also covers column masking/classification (restricted views + ontology sensitivity — no masking REST API exists). Use when the user asks about roles/RBAC, who can access what, granting/revoking access on any resource, adding someone to a role, or masking/classifying columns. Primary engine is the official `aidp` CLI; the same REST API via `oci raw-request` is the no-CLI fallback.

AI 產生的概覽

管理 AIDP 角色與存取權:列出角色、增減成員,以及授予或撤銷各項資源的權限。

功能
提供透過 aidp CLI 檢視與管理 AIDP 角色型存取控制的說明,並以 oci raw-request 呼叫等效 REST API 作為沒有 CLI 時的備援方式。內容涵蓋角色列出、檢視、建立、更新與刪除、成員異動,以及針對目錄、結構描述、資料表、檢視表、磁碟區、工作區、工作區物件、叢集、作業與知識庫的各資源權限授予。文件也說明並不存在遮罩 REST API,並建議以受限檢視與本體敏感度作為實務上的資料行層級控制方式。變更類操作在套用前需要確認。
適用情境
當使用者詢問角色或 RBAC、誰可以存取什麼、在 AIDP 資源上授予或撤銷存取權、將某人加入或移出角色,或對資料行進行遮罩與分類時使用。
執行需求
需要 aidp CLI,並提供執行個體 ID、api_key 驗證、設定檔與區域;或改用 oci CLI 發出 raw-request REST 呼叫;需要連線至 AIDP 區域端點的網路存取與有效憑證。可選擇啟用受控的 AIDP MCP 管理工具來執行權限寫入。不隨附指令碼。

aidp-roles-access — roles, permissions, access (RBAC)

Inspect and manage AIDP RBAC.

CLI (preferred): aidp role <command> --instance-id <DATALAKE_OCID> --auth api_key --profile DEFAULT --region <r>

  • Roles: aidp role list | get | create | update | delete | add-member | remove-member | list-permissions
  • Per-resource grants: aidp <catalog|cluster|volume|schema|workspace|workspace-object> list-permissions | manage-permission

Fallback (no CLI): same Role REST API via oci raw-request (identical endpoint + auth). Permission writes (workspace/cluster/volume grants) can also use the gated MCP admin tools as an optional accelerator when configured.

Verify-first + least privilege: bind to the caller's identity; never escalate beyond what they have. Confirm the working path with a live aidp role list (or GET /roles) before any write. Auth + base URL: references/oci-raw-request.md.

When to use

  • "List roles / who has access", "create a role", "add/remove a member", "grant/revoke access to a workspace/cluster/volume".

Read & role CRUD (CLI preferred)

bash
# List roles (smoke test) — CLIaidp role list --instance-id <DATALAKE_OCID> --auth api_key --profile DEFAULT --region us-ashburn-1
# Add a member to a role — CLIaidp role add-member --instance-id <DATALAKE_OCID> --role-key <ROLE_KEY> \  --auth api_key --profile DEFAULT --region us-ashburn-1 \  --principals '["ocid1.user.oc1..xxxx"]'

Mutating ops (create, update, delete, add-member, remove-member, manage-permission): persist the body to .aidp/payloads/ and confirm first (references/payloads.md).

Fallback (no CLI) — REST via oci raw-request

Base: https://aidp.<region>.oci.oraclecloud.com/20240831/dataLakes/<DATALAKE_OCID>/…

  • List roles — GET /roles — ✅ LIVE-VERIFIED 200 (api_key DEFAULT profile, 20240831/dataLakes).
  • Inspect a role — GET /roles/{k}, GET /roles/{k}/permissions.
  • Create / update / delete — POST /roles, PUT /roles/{k}, DELETE /roles/{k} (send if-match: <etag> on PUT/DELETE).
  • Membership — POST /roles/{k}/actions/addMember · POST /roles/{k}/actions/removeMember (body e.g. {"principals":["ocid1.user.oc1..xxxx"]}).
bash
oci raw-request --http-method GET \  --target-uri "https://aidp.us-ashburn-1.oci.oraclecloud.com/20240831/dataLakes/<OCID>/roles" \  --profile DEFAULT

On 401/403/"Security Token", follow the auth ladder in oci-raw-request.md (refresh AIDP_SESSION).

Per-resource permission grants (full matrix)

Role CRUD + membership scope who is in a role; per-resource grants scope what a principal can do to one object. Every resource type exposes a list-permissions + manage-permission pair (CLI preferred; REST …/<resource>/<key>/permissions + …/actions/managePermission fallback). Grant body is consistently {"principals":[…], "permission":"<enum>", "action":"GRANT"|"REVOKE"} — confirm the exact permission enum for each resource via aidp help <resource> manage-permission / a live read before writing.

ResourceCLI verbsREST
Catalogaidp catalog list-permissions | manage-permission…/catalogs/<key>/permissions
Schemaaidp schema list-permissions | manage-permission…/schemas/<key>/permissions
Tableaidp schema list-table-permissions | manage-table-permission <TABLE-KEY>…/tables/<key>/permissions
Viewaidp schema list-view-permissions | manage-view-permission <VIEW-KEY>…/views/<key>/permissions
Volumeaidp volume list-permissions | manage-permission…/volumes/<key>/permissions
Workspaceaidp workspace list-permissions | manage-permission (+ list-create-permissions | manage-create-permission)…/workspaces/<key>/permissions
Workspace objectaidp workspace-object list-permissions | manage-permission…/workspaceObjects/<key>/permissions
Cluster(no GA CLI verb)…/clusters/<key>/permissions
Job/Workflowaidp workflow list-job-permissions <ws> <JOB-KEY> / manage-job-permission <ws> <JOB-KEY> --body…/workspaces/{ws}/jobs/{key}/permissions
Knowledge Baseassign|manage|revoke KB permission (aidp-knowledge-bases)…/knowledgeBases/<key>/permissions

Job/Workflow body shape differs from the generic grant. The CLI README + SDK confirm manage-job-permission does not take {principals,permission,action}. Its grant body is AssignJobPermissionDetails = {"assignees":{"type":"USER|ROLE|GROUP","targets":[…]},"permissions":["READ"|"USE"|"MANAGE"|"ADMIN"]} (permissions is a list aligned 1:1 with assignees.targets); the manage wrapper is {"assignJobPermissionDetails":{…},"revokeJobPermissionDetails":{…}}. Enum names are confirmed-citable (SDK assign_job_permission_details.py lines 18-30 / permission_assignees.py lines 18-26; CLI README workflow manage-job-permission, README lines 7315-7377); still confirm the live enum with aidp help workflow manage-job-permission or a list-job-permissions read before writing.

Optional accelerator: when a gated aidp MCP is configured (AIDP_MCP_ENABLE_ADMIN_TOOLS=true + MCP restart), manage_workspace_permission / manage_cluster_permission / manage_volume_permission / manage_create_workspace_permission wrap the same writes (details_json {"principals":[…],"permission":"WRITE","action":"GRANT"}). Not required — REST verbs above are the source of truth; or apply the grant in the console.

Column masking & classification (honest scope — no data-plane API found)

There is no programmatic masking/classification REST API in the tested tenancy — GET …/maskingPolicies, /dataClassifications, /columnMaskingPolicies, /tags all returned 404 (probed 2026-06-10; recorded in references/rest-endpoint-map.md). Do not fabricate one. What actually exists:

  • Restricted / redacting views — the practical column-level control today: CREATE VIEW exposing only permitted columns (or CASE/hashing to redact), then grant on the view, not the base table (aidp-sql-ddl
    • the View row above). This is the recommended pattern when asked to "mask a column".
  • Ontology-driven sensitivity — the Ontologies feature tags terms (av:isSensitive / av:requiresRole) for governance, but it is UI-driven with no confirmed REST surface here (see the Ontologies note in aidp-semantic-model). If the user needs policy-based dynamic masking, surface that it's UI/ontology-governed today and offer the restricted-view pattern as the API-driven equivalent — don't claim a masking endpoint.

Workflow

  1. Read current state first (GET /roles + the relevant role's /permissions).
  2. Show the exact grant/revoke (principal, permission, target) and confirm before applying.
  3. Apply via REST (role CRUD/membership), or the gated admin tool if it's available; re-read to confirm.

Guardrails

  • Access changes are sensitive — confirm every grant/revoke; never broaden beyond the user's request.
  • Don't propose IAM/permission changes that aren't explicitly asked for.

References

  • references/aidp-cli-map.md · references/payloads.md · references/oci-raw-request.md · references/no-mcp-rest-map.md · references/rest-endpoint-map.md

來源與署名

來源:oracle-samples/oracle-aidp-samples位於ai/claude-code-plugins/oracle-ai-data-platform-workbench-engineer-agent/skills/aidp-roles-access提交90b42d6

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 oracle-samples/oracle-aidp-samples 的技能

Aidp Workspace Admin

oracle-samples

Provision and inspect AIDP DataLake instances and workspaces, including private-network workspaces attached to a customer VCN/subnet. Use when the user wants to create/list/get a workspace or DataLake instance, set up a new (e.g. private) AIDP environment, or replicate a customer setup. Create/delete are guarded — confirm before any provisioning.

待分類2026年10月8日

Aidp Volumes

oracle-samples

Work with AIDP volumes — list volumes, browse files inside a volume, upload/download via the PAR flow, and create directories. Use when the user mentions volumes, needs to stage large/binary files, or move data in/out of a volume (distinct from the workspace filesystem). Control-plane via the official `aidp` CLI.

待分類2026年10月8日

Aidp Verified Queries

oracle-samples

維護經過驗證的問題到 Spark SQL 配對庫,讓代理在產生新 SQL 前優先重用可信查詢。

Data & Analytics2026年10月8日

Aidp User Settings

oracle-samples

透過 aidp CLI 或 oci raw-request 備援方式管理 AIDP DataLake 使用者設定與偏好。

Productivity & Workflow2026年10月8日

Aidp Spark Optimization

oracle-samples

指導 Apache Spark 3.5.0 效能調校:分割區、shuffle、join、資料傾斜、記憶體、檔案配置、AQE 與 Delta Lake。

Data & Analytics2026年10月8日

Aidp Semantic Model

oracle-samples

維護 .aidp/semantic.md 業務語意層,定義指標、連接、同義詞與值字典,為自然語言轉 SQL 提供依據。

Data & Analytics2026年10月8日