All skills
aws avatar

/creating-data-lake-table

@b33847d

Create managed Iceberg tables using Amazon S3 Tables (s3tables API namespace) with automatic compaction and snapshot management. Sets up table bucket, namespace, table, schema, Glue catalog registration, partitioning, IAM access control. Triggers on: create table, data lake table, analytics table, structured data storage, S3 Tables, Iceberg, Athena table, partitioning strategy, access permissions. Do NOT use for: importing files (use ingesting-into-data-lake), vector storage (use storing-and-querying-vectors), querying existing tables (use querying-data-lake), or locating existing table (use finding-data-lake-assets).

Use this Skill: https://skilld.dev/gh/aws/agent-toolkit-for-aws/creating-data-lake-table

This session only. Nothing lands on disk.

referencesaccess-control.md

≈370 tokens on demand. Your agent reads this file only when SKILL.md points to it.

S3 Tables Access Control

You MUST use least-privilege permissions when configuring access to S3 Tables.

Bucket Policy (s3tables actions)

Actions: s3tables:GetTableBucket, s3tables:GetNamespace, s3tables:GetTable, s3tables:GetTableMetadataLocation, s3tables:GetTableData

Resources:

  • arn:aws:s3tables:{region}:{account_id}:bucket/{bucket_name}
  • arn:aws:s3tables:{region}:{account_id}:bucket/{bucket_name}/table/*

Set with aws s3tables put-table-bucket-policy --table-bucket-arn <ARN> --resource-policy '<POLICY_JSON>'.

IAM Policy (glue actions)

Actions: glue:GetCatalog, glue:GetDatabase, glue:GetTable

Resources (all three actions on each):

  • arn:aws:glue:{region}:{account_id}:catalog (root -- required for federated catalog resolution)
  • arn:aws:glue:{region}:{account_id}:catalog/s3tablescatalog
  • arn:aws:glue:{region}:{account_id}:catalog/s3tablescatalog/*
  • arn:aws:glue:{region}:{account_id}:database/s3tablescatalog/*/*
  • arn:aws:glue:{region}:{account_id}:table/s3tablescatalog/*/*/*

SSE-KMS

If the table bucket uses SSE-KMS, the querying principal also needs kms:Decrypt and kms:GenerateDataKey on the KMS key.

Glue ETL Service Role

See table-creation-glue-etl.md for the Glue job service role permissions.

Additional Resources

For latest IAM guidance, search AWS docs for "S3 Tables identity-based policies IAM", "S3 Tables access management", and "S3 Tables Glue catalog prerequisites".

Source: SKILL.md on GitHub

No alerts16d3 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a structured workflow for managing Amazon S3 Tables and Glue catalogs using the AWS CLI and Athena. It incorporates security considerations such as emphasizing least-privilege IAM policies, manual verification of credentials, and the use of sandboxed execution environments.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

Signed by skilld at b33847d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 months ago
metadata
{
  "version": "1",
  "argument-hint": "'[table-description|schema-spec]'"
}

README badge

README badge for aws/agent-toolkit-for-aws/creating-data-lake-table