Glue
Important Capabilities
Capability | Status | Notes |
---|---|---|
Column-level Lineage | ✅ | Support via the emit_s3_lineage config field |
Detect Deleted Entities | ✅ | Enabled by default when stateful ingestion is turned on. |
Domains | ✅ | Supported via the domain config field |
Platform Instance | ✅ | Enabled by default |
Table-Level Lineage | ✅ | Enabled by default |
Note: if you also have files in S3 that you'd like to ingest, we recommend you use Glue's built-in data catalog. See here for a quick guide on how to set up a crawler on Glue and ingest the outputs with DataHub.
This plugin extracts the following:
- Tables in the Glue catalog
- Column types associated with each table
- Table metadata, such as owner, description and parameters
- Jobs and their component transformations, data sources, and data sinks
IAM permissions
For ingesting datasets, the following IAM permissions are required:
{
"Effect": "Allow",
"Action": [
"glue:GetDatabases",
"glue:GetTables"
],
"Resource": [
"arn:aws:glue:$region-id:$account-id:catalog",
"arn:aws:glue:$region-id:$account-id:database/*",
"arn:aws:glue:$region-id:$account-id:table/*"
]
}
For ingesting jobs (extract_transforms: True
), the following additional permissions are required:
{
"Effect": "Allow",
"Action": [
"glue:GetDataflowGraph",
"glue:GetJobs",
"s3:GetObject",
],
"Resource": "*"
}
For profiling datasets, the following additional permissions are required:
{
"Effect": "Allow",
"Action": [
"glue:GetPartitions",
],
"Resource": "*"
}
CLI based Ingestion
Starter Recipe
Check out the following recipe to get started with ingestion! See below for full configuration options.
For general pointers on writing and running a recipe, see our main recipe guide.
source:
type: glue
config:
# Coordinates
aws_region: "my-aws-region"
sink:
# sink configs
Config Details
- Options
- Schema
Note that a .
is used to denote nested fields in the YAML recipe.
Field | Description |
---|---|
aws_access_key_id string | AWS access key ID. Can be auto-detected, see the AWS boto3 docs for details. |
aws_advanced_config object | Advanced AWS configuration options. These are passed directly to botocore.config.Config. |
aws_endpoint_url string | The AWS service endpoint. This is normally constructed automatically, but can be overridden here. |
aws_profile string | The named profile to use from AWS credentials. Falls back to default profile if not specified and no access keys provided. Profiles are configured in ~/.aws/credentials or ~/.aws/config. |
aws_proxy map(str,string) | |
aws_region string | AWS region code. |
aws_retry_mode Enum | One of: "legacy", "standard", "adaptive" Default: standard |
aws_retry_num integer | Number of times to retry failed AWS requests. See the botocore.retry docs for details. Default: 5 |
aws_secret_access_key string | AWS secret access key. Can be auto-detected, see the AWS boto3 docs for details. |
aws_session_token string | AWS session token. Can be auto-detected, see the AWS boto3 docs for details. |
catalog_id string | The aws account id where the target glue catalog lives. If None, datahub will ingest glue in aws caller's account. |
emit_s3_lineage boolean | Whether to emit S3-to-Glue lineage. Default: False |
extract_delta_schema_from_parameters boolean | If enabled, delta schemas can be alternatively fetched from table parameters. Default: False |
extract_owners boolean | When enabled, extracts ownership from Glue table property and overwrites existing owners (DATAOWNER). When disabled, ownership is left empty for datasets. Expects a corpGroup urn, a corpuser urn or only the identifier part for the latter. Not used in the normal course of AWS Glue operations. Default: True |
extract_transforms boolean | Whether to extract Glue transform jobs. Default: True |
glue_s3_lineage_direction string | If upstream , S3 is upstream to Glue. If downstream S3 is downstream to Glue. Default: upstream |
ignore_resource_links boolean | If set to True, ignore database resource links. Default: False |
ignore_unsupported_connectors boolean | Whether to ignore unsupported connectors. If disabled, an error will be raised. Default: True |
include_column_lineage boolean | When enabled, column-level lineage will be extracted from the s3. Default: True |
platform string | The platform to use for the dataset URNs. Must be one of ['glue', 'athena']. Default: glue |
platform_instance string | The instance of the platform that all assets produced by this recipe belong to. This should be unique within the platform. See https://datahubproject.io/docs/platform-instances/ for more details. |
read_timeout number | The timeout for reading from the connection (in seconds). Default: 60 |
use_s3_bucket_tags boolean | If an S3 Buckets Tags should be created for the Tables ingested by Glue. Please Note that this will not apply tags to any folders ingested, only the files. Default: False |
use_s3_object_tags boolean | If an S3 Objects Tags should be created for the Tables ingested by Glue. Default: False |
env string | The environment that all assets produced by this connector belong to Default: PROD |
aws_role One of string, array | AWS roles to assume. If using the string format, the role ARN can be specified directly. If using the object format, the role can be specified in the RoleArn field and additional available arguments are the same as boto3's STS.Client.assume_role. |
aws_role.union One of string, AwsAssumeRoleConfig | |
aws_role.union.RoleArn ❓ string | ARN of the role to assume. |
aws_role.union.ExternalId string | External ID to use when assuming the role. |
database_pattern AllowDenyPattern | regex patterns for databases to filter in ingestion. Default: {'allow': ['.*'], 'deny': [], 'ignoreCase': True} |
database_pattern.ignoreCase boolean | Whether to ignore case sensitivity during pattern matching. Default: True |
database_pattern.allow array | List of regex patterns to include in ingestion Default: ['.*'] |
database_pattern.allow.string string | |
database_pattern.deny array | List of regex patterns to exclude from ingestion. Default: [] |
database_pattern.deny.string string | |
domain map(str,AllowDenyPattern) | A class to store allow deny regexes |
domain. key .allowarray | List of regex patterns to include in ingestion Default: ['.*'] |
domain. key .allow.stringstring | |
domain. key .ignoreCaseboolean | Whether to ignore case sensitivity during pattern matching. Default: True |
domain. key .denyarray | List of regex patterns to exclude from ingestion. Default: [] |
domain. key .deny.stringstring | |
table_pattern AllowDenyPattern | regex patterns for tables to filter in ingestion. Default: {'allow': ['.*'], 'deny': [], 'ignoreCase': True} |
table_pattern.ignoreCase boolean | Whether to ignore case sensitivity during pattern matching. Default: True |
table_pattern.allow array | List of regex patterns to include in ingestion Default: ['.*'] |
table_pattern.allow.string string | |
table_pattern.deny array | List of regex patterns to exclude from ingestion. Default: [] |
table_pattern.deny.string string | |
profiling GlueProfilingConfig | Configs to ingest data profiles from glue table |
profiling.column_count string | The parameter name for column count in glue table. |
profiling.enabled boolean | Whether profiling should be done. Default: False |
profiling.max string | The parameter name for the max value of a column. |
profiling.mean string | The parameter name for the mean value of a column. |
profiling.median string | The parameter name for the median value of a column. |
profiling.min string | The parameter name for the min value of a column. |
profiling.null_count string | The parameter name for the count of null values in a column. |
profiling.null_proportion string | The parameter name for the proportion of null values in a column. |
profiling.profile_table_level_only boolean | Whether to perform profiling at table-level only, or include column-level profiling as well. Default: False |
profiling.row_count string | The parameter name for row count in glue table. |
profiling.stdev string | The parameter name for the standard deviation of a column. |
profiling.unique_count string | The parameter name for the count of unique value in a column. |
profiling.unique_proportion string | The parameter name for the proportion of unique values in a column. |
profiling.operation_config OperationConfig | Experimental feature. To specify operation configs. |
profiling.operation_config.lower_freq_profile_enabled boolean | Whether to do profiling at lower freq or not. This does not do any scheduling just adds additional checks to when not to run profiling. Default: False |
profiling.operation_config.profile_date_of_month integer | Number between 1 to 31 for date of month (both inclusive). If not specified, defaults to Nothing and this field does not take affect. |
profiling.operation_config.profile_day_of_week integer | Number between 0 to 6 for day of week (both inclusive). 0 is Monday and 6 is Sunday. If not specified, defaults to Nothing and this field does not take affect. |
profiling.partition_patterns AllowDenyPattern | Regex patterns for filtering partitions for profile. The pattern should be a string like: "{'key':'value'}". Default: {'allow': ['.*'], 'deny': [], 'ignoreCase': True} |
profiling.partition_patterns.ignoreCase boolean | Whether to ignore case sensitivity during pattern matching. Default: True |
profiling.partition_patterns.allow array | List of regex patterns to include in ingestion Default: ['.*'] |
profiling.partition_patterns.allow.string string | |
profiling.partition_patterns.deny array | List of regex patterns to exclude from ingestion. Default: [] |
profiling.partition_patterns.deny.string string | |
stateful_ingestion StatefulStaleMetadataRemovalConfig | Base specialized config for Stateful Ingestion with stale metadata removal capability. |
stateful_ingestion.enabled boolean | Whether or not to enable stateful ingest. Default: True if a pipeline_name is set and either a datahub-rest sink or datahub_api is specified, otherwise False Default: False |
stateful_ingestion.remove_stale_metadata boolean | Soft-deletes the entities present in the last successful run but missing in the current run with stateful_ingestion enabled. Default: True |
The JSONSchema for this configuration is inlined below.
{
"title": "GlueSourceConfig",
"description": "Base configuration class for stateful ingestion for source configs to inherit from.",
"type": "object",
"properties": {
"aws_access_key_id": {
"title": "Aws Access Key Id",
"description": "AWS access key ID. Can be auto-detected, see [the AWS boto3 docs](https://boto3.amazonaws.com/v1/documentation/api/latest/guide/credentials.html) for details.",
"type": "string"
},
"aws_secret_access_key": {
"title": "Aws Secret Access Key",
"description": "AWS secret access key. Can be auto-detected, see [the AWS boto3 docs](https://boto3.amazonaws.com/v1/documentation/api/latest/guide/credentials.html) for details.",
"type": "string"
},
"aws_session_token": {
"title": "Aws Session Token",
"description": "AWS session token. Can be auto-detected, see [the AWS boto3 docs](https://boto3.amazonaws.com/v1/documentation/api/latest/guide/credentials.html) for details.",
"type": "string"
},
"aws_role": {
"title": "Aws Role",
"description": "AWS roles to assume. If using the string format, the role ARN can be specified directly. If using the object format, the role can be specified in the RoleArn field and additional available arguments are the same as [boto3's STS.Client.assume_role](https://boto3.amazonaws.com/v1/documentation/api/latest/reference/services/sts.html?highlight=assume_role#STS.Client.assume_role).",
"anyOf": [
{
"type": "string"
},
{
"type": "array",
"items": {
"anyOf": [
{
"type": "string"
},
{
"$ref": "#/definitions/AwsAssumeRoleConfig"
}
]
}
}
]
},
"aws_profile": {
"title": "Aws Profile",
"description": "The [named profile](https://docs.aws.amazon.com/cli/latest/userguide/cli-configure-profiles.html) to use from AWS credentials. Falls back to default profile if not specified and no access keys provided. Profiles are configured in ~/.aws/credentials or ~/.aws/config.",
"type": "string"
},
"aws_region": {
"title": "Aws Region",
"description": "AWS region code.",
"type": "string"
},
"aws_endpoint_url": {
"title": "Aws Endpoint Url",
"description": "The AWS service endpoint. This is normally [constructed automatically](https://boto3.amazonaws.com/v1/documentation/api/latest/reference/core/session.html), but can be overridden here.",
"type": "string"
},
"aws_proxy": {
"title": "Aws Proxy",
"description": "A set of proxy configs to use with AWS. See the [botocore.config](https://botocore.amazonaws.com/v1/documentation/api/latest/reference/config.html) docs for details.",
"type": "object",
"additionalProperties": {
"type": "string"
}
},
"aws_retry_num": {
"title": "Aws Retry Num",
"description": "Number of times to retry failed AWS requests. See the [botocore.retry](https://boto3.amazonaws.com/v1/documentation/api/latest/guide/retries.html) docs for details.",
"default": 5,
"type": "integer"
},
"aws_retry_mode": {
"title": "Aws Retry Mode",
"description": "Retry mode to use for failed AWS requests. See the [botocore.retry](https://boto3.amazonaws.com/v1/documentation/api/latest/guide/retries.html) docs for details.",
"default": "standard",
"enum": [
"legacy",
"standard",
"adaptive"
],
"type": "string"
},
"read_timeout": {
"title": "Read Timeout",
"description": "The timeout for reading from the connection (in seconds).",
"default": 60,
"type": "number"
},
"aws_advanced_config": {
"title": "Aws Advanced Config",
"description": "Advanced AWS configuration options. These are passed directly to [botocore.config.Config](https://botocore.amazonaws.com/v1/documentation/api/latest/reference/config.html).",
"type": "object"
},
"env": {
"title": "Env",
"description": "The environment that all assets produced by this connector belong to",
"default": "PROD",
"type": "string"
},
"database_pattern": {
"title": "Database Pattern",
"description": "regex patterns for databases to filter in ingestion.",
"default": {
"allow": [
".*"
],
"deny": [],
"ignoreCase": true
},
"allOf": [
{
"$ref": "#/definitions/AllowDenyPattern"
}
]
},
"table_pattern": {
"title": "Table Pattern",
"description": "regex patterns for tables to filter in ingestion.",
"default": {
"allow": [
".*"
],
"deny": [],
"ignoreCase": true
},
"allOf": [
{
"$ref": "#/definitions/AllowDenyPattern"
}
]
},
"platform_instance": {
"title": "Platform Instance",
"description": "The instance of the platform that all assets produced by this recipe belong to. This should be unique within the platform. See https://datahubproject.io/docs/platform-instances/ for more details.",
"type": "string"
},
"stateful_ingestion": {
"$ref": "#/definitions/StatefulStaleMetadataRemovalConfig"
},
"platform": {
"title": "Platform",
"description": "The platform to use for the dataset URNs. Must be one of ['glue', 'athena'].",
"default": "glue",
"type": "string"
},
"extract_owners": {
"title": "Extract Owners",
"description": "When enabled, extracts ownership from Glue table property and overwrites existing owners (DATAOWNER). When disabled, ownership is left empty for datasets. Expects a corpGroup urn, a corpuser urn or only the identifier part for the latter. Not used in the normal course of AWS Glue operations.",
"default": true,
"type": "boolean"
},
"extract_transforms": {
"title": "Extract Transforms",
"description": "Whether to extract Glue transform jobs.",
"default": true,
"type": "boolean"
},
"ignore_unsupported_connectors": {
"title": "Ignore Unsupported Connectors",
"description": "Whether to ignore unsupported connectors. If disabled, an error will be raised.",
"default": true,
"type": "boolean"
},
"emit_s3_lineage": {
"title": "Emit S3 Lineage",
"description": "Whether to emit S3-to-Glue lineage.",
"default": false,
"type": "boolean"
},
"glue_s3_lineage_direction": {
"title": "Glue S3 Lineage Direction",
"description": "If `upstream`, S3 is upstream to Glue. If `downstream` S3 is downstream to Glue.",
"default": "upstream",
"type": "string"
},
"domain": {
"title": "Domain",
"description": "regex patterns for tables to filter to assign domain_key. ",
"default": {},
"type": "object",
"additionalProperties": {
"$ref": "#/definitions/AllowDenyPattern"
}
},
"catalog_id": {
"title": "Catalog Id",
"description": "The aws account id where the target glue catalog lives. If None, datahub will ingest glue in aws caller's account.",
"type": "string"
},
"ignore_resource_links": {
"title": "Ignore Resource Links",
"description": "If set to True, ignore database resource links.",
"default": false,
"type": "boolean"
},
"use_s3_bucket_tags": {
"title": "Use S3 Bucket Tags",
"description": "If an S3 Buckets Tags should be created for the Tables ingested by Glue. Please Note that this will not apply tags to any folders ingested, only the files.",
"default": false,
"type": "boolean"
},
"use_s3_object_tags": {
"title": "Use S3 Object Tags",
"description": "If an S3 Objects Tags should be created for the Tables ingested by Glue.",
"default": false,
"type": "boolean"
},
"profiling": {
"title": "Profiling",
"description": "Configs to ingest data profiles from glue table",
"allOf": [
{
"$ref": "#/definitions/GlueProfilingConfig"
}
]
},
"extract_delta_schema_from_parameters": {
"title": "Extract Delta Schema From Parameters",
"description": "If enabled, delta schemas can be alternatively fetched from table parameters.",
"default": false,
"type": "boolean"
},
"include_column_lineage": {
"title": "Include Column Lineage",
"description": "When enabled, column-level lineage will be extracted from the s3.",
"default": true,
"type": "boolean"
}
},
"additionalProperties": false,
"definitions": {
"AwsAssumeRoleConfig": {
"title": "AwsAssumeRoleConfig",
"type": "object",
"properties": {
"RoleArn": {
"title": "Rolearn",
"description": "ARN of the role to assume.",
"type": "string"
},
"ExternalId": {
"title": "Externalid",
"description": "External ID to use when assuming the role.",
"type": "string"
}
},
"required": [
"RoleArn"
]
},
"AllowDenyPattern": {
"title": "AllowDenyPattern",
"description": "A class to store allow deny regexes",
"type": "object",
"properties": {
"allow": {
"title": "Allow",
"description": "List of regex patterns to include in ingestion",
"default": [
".*"
],
"type": "array",
"items": {
"type": "string"
}
},
"deny": {
"title": "Deny",
"description": "List of regex patterns to exclude from ingestion.",
"default": [],
"type": "array",
"items": {
"type": "string"
}
},
"ignoreCase": {
"title": "Ignorecase",
"description": "Whether to ignore case sensitivity during pattern matching.",
"default": true,
"type": "boolean"
}
},
"additionalProperties": false
},
"DynamicTypedStateProviderConfig": {
"title": "DynamicTypedStateProviderConfig",
"type": "object",
"properties": {
"type": {
"title": "Type",
"description": "The type of the state provider to use. For DataHub use `datahub`",
"type": "string"
},
"config": {
"title": "Config",
"description": "The configuration required for initializing the state provider. Default: The datahub_api config if set at pipeline level. Otherwise, the default DatahubClientConfig. See the defaults (https://github.com/datahub-project/datahub/blob/master/metadata-ingestion/src/datahub/ingestion/graph/client.py#L19).",
"default": {},
"type": "object"
}
},
"required": [
"type"
],
"additionalProperties": false
},
"StatefulStaleMetadataRemovalConfig": {
"title": "StatefulStaleMetadataRemovalConfig",
"description": "Base specialized config for Stateful Ingestion with stale metadata removal capability.",
"type": "object",
"properties": {
"enabled": {
"title": "Enabled",
"description": "Whether or not to enable stateful ingest. Default: True if a pipeline_name is set and either a datahub-rest sink or `datahub_api` is specified, otherwise False",
"default": false,
"type": "boolean"
},
"remove_stale_metadata": {
"title": "Remove Stale Metadata",
"description": "Soft-deletes the entities present in the last successful run but missing in the current run with stateful_ingestion enabled.",
"default": true,
"type": "boolean"
}
},
"additionalProperties": false
},
"OperationConfig": {
"title": "OperationConfig",
"type": "object",
"properties": {
"lower_freq_profile_enabled": {
"title": "Lower Freq Profile Enabled",
"description": "Whether to do profiling at lower freq or not. This does not do any scheduling just adds additional checks to when not to run profiling.",
"default": false,
"type": "boolean"
},
"profile_day_of_week": {
"title": "Profile Day Of Week",
"description": "Number between 0 to 6 for day of week (both inclusive). 0 is Monday and 6 is Sunday. If not specified, defaults to Nothing and this field does not take affect.",
"type": "integer"
},
"profile_date_of_month": {
"title": "Profile Date Of Month",
"description": "Number between 1 to 31 for date of month (both inclusive). If not specified, defaults to Nothing and this field does not take affect.",
"type": "integer"
}
},
"additionalProperties": false
},
"GlueProfilingConfig": {
"title": "GlueProfilingConfig",
"type": "object",
"properties": {
"enabled": {
"title": "Enabled",
"description": "Whether profiling should be done.",
"default": false,
"type": "boolean"
},
"profile_table_level_only": {
"title": "Profile Table Level Only",
"description": "Whether to perform profiling at table-level only, or include column-level profiling as well.",
"default": false,
"type": "boolean"
},
"row_count": {
"title": "Row Count",
"description": "The parameter name for row count in glue table.",
"type": "string"
},
"column_count": {
"title": "Column Count",
"description": "The parameter name for column count in glue table.",
"type": "string"
},
"unique_count": {
"title": "Unique Count",
"description": "The parameter name for the count of unique value in a column.",
"type": "string"
},
"unique_proportion": {
"title": "Unique Proportion",
"description": "The parameter name for the proportion of unique values in a column.",
"type": "string"
},
"null_count": {
"title": "Null Count",
"description": "The parameter name for the count of null values in a column.",
"type": "string"
},
"null_proportion": {
"title": "Null Proportion",
"description": "The parameter name for the proportion of null values in a column.",
"type": "string"
},
"min": {
"title": "Min",
"description": "The parameter name for the min value of a column.",
"type": "string"
},
"max": {
"title": "Max",
"description": "The parameter name for the max value of a column.",
"type": "string"
},
"mean": {
"title": "Mean",
"description": "The parameter name for the mean value of a column.",
"type": "string"
},
"median": {
"title": "Median",
"description": "The parameter name for the median value of a column.",
"type": "string"
},
"stdev": {
"title": "Stdev",
"description": "The parameter name for the standard deviation of a column.",
"type": "string"
},
"partition_patterns": {
"title": "Partition Patterns",
"description": "Regex patterns for filtering partitions for profile. The pattern should be a string like: \"{'key':'value'}\".",
"default": {
"allow": [
".*"
],
"deny": [],
"ignoreCase": true
},
"allOf": [
{
"$ref": "#/definitions/AllowDenyPattern"
}
]
},
"operation_config": {
"title": "Operation Config",
"description": "Experimental feature. To specify operation configs.",
"allOf": [
{
"$ref": "#/definitions/OperationConfig"
}
]
}
},
"additionalProperties": false
}
}
}
Concept Mapping
Source Concept | DataHub Concept | Notes |
---|---|---|
"glue" | Data Platform | |
Glue Database | Container | Subtype Database |
Glue Table | Dataset | Subtype Table |
Glue Job | Data Flow | |
Glue Job Transform | Data Job | |
Glue Job Data source | Dataset | |
Glue Job Data sink | Dataset |
Compatibility
To capture lineage across Glue jobs and databases, a requirements must be met – otherwise the AWS API is unable to report any lineage. The job must be created in Glue Studio with the "Generate classic script" option turned on (this option can be accessed in the "Script" tab). Any custom scripts that do not have the proper annotations will not have reported lineage.
Code Coordinates
- Class Name:
datahub.ingestion.source.aws.glue.GlueSource
- Browse on GitHub
Questions
If you've got any questions on configuring ingestion for Glue, feel free to ping us on our Slack.