SYSTEM Cited by 1 source
AWS Lake Formation¶
Definition¶
AWS Lake Formation is AWS's data-lake governance service. It layers fine-grained, centrally managed permissions (database, table, column, row, and tag-based) over the Glue Data Catalog and the underlying S3 data, and brokers cross-account sharing of catalog databases and tables. When a producer grants a consumer account access to a Lake Formation resource, Lake Formation creates the underlying AWS RAM resource share on its behalf — RAM is the transport, Lake Formation is the authority.
Role for this wiki¶
Canonical wiki reference: the 2026-08-24 payment-processor AWS Organizations migration. The post's central insight is the layering:
- Lake Formation is the durable, service-managed source of truth for cross-account catalog permissions.
- RAM is the mechanism it uses; a Lake-Formation-created share is a RAM resource share whose lifecycle Lake Formation owns.
"The original AWS Lake Formation-created share remains the durable, service-managed permission object. If a team adds a grant or changes a shared resource during the migration window, that change applies to the original share, not automatically to the bridge." (Source: sources/2026-08-24-aws-preserving-ram-shares-and-lake-formation-permissions-during-organizations-migration)
This is why the restore-original-then-delete-bridge discipline exists: a temporary bridge share can carry access through an account move, but new Lake Formation grants keep attaching to the original share, so the original must be restored as authoritative and the bridge removed to avoid two divergent permission paths.
Glue Data Catalog + Lake Formation in the migration¶
In the migration, the embedded-payments platform shared Glue Data Catalog databases and tables across 10 accounts with account IDs as principals. Because Glue/Lake-Formation shares carry both catalog metadata and the permission grants, this workstream required bridge-share validation in disposable accounts (reproducing the config and recording the resource policy through a cross-organization move) before touching production. It completed its production migration on 2026-07-21.
What Lake Formation provides¶
- Fine-grained permissions over Glue Catalog objects (DB / table / column / row / LF-tag).
- Cross-account grants — implemented as Lake-Formation-managed RAM resource shares.
- Centralized authority — the grant model is the source of truth; the RAM share is an implementation artifact underneath it.
Generalisation¶
The structural property: a governance service that owns permission state and delegates the cross-tenant transport to a lower-level sharing primitive. Comparable layering: Databricks Unity Catalog governing tables while delegating storage/credential vending; GCP BigQuery authorized-datasets / IAM over cross-project sharing.
Seen in¶
- sources/2026-08-24-aws-preserving-ram-shares-and-lake-formation-permissions-during-organizations-migration — canonical wiki reference; first dedicated Lake Formation page. Named as the durable, service-managed permission object that RAM bridge shares must be restored back to after an Organizations account move.
Related¶
- systems/aws-glue — the Glue Data Catalog Lake Formation governs.
- systems/aws-resource-access-manager-ram — the underlying cross-account share transport Lake Formation drives.
- systems/aws-organizations — the trust boundary whose crossing breaks org-bound Lake-Formation/RAM shares.
- systems/aws-s3 — the data the catalog and permissions sit over.
- organization-bound-resource-share — the failing share type in the migration.
- external-principal-association — the surviving share type the bridge exploits.