npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@aws-mdaa/lakeformation-access-control

v1.6.0

Published

MDAA lakeformation-access-control module

Readme

Lake Formation Access Control

Note: This documentation is also available in a rendered format here.

Deploys Lake Formation fine-grained access grants for databases and tables, supporting federated users/groups, IAM roles, and cross-account resource links. This module should be used to manage LF grants to Glue resources created outside of MDAA. For Glue resources created within the DataOps Project module, grants can be configured within the module itself. Use this module when you need to grant specific users, groups, or roles read, write, or admin access to Glue databases and tables that were created outside of your DataOps projects.


Deployed Resources

This module deploys and integrates the following resources:

Lake Formation Access Grants - Grants deployed for each specification in the config.

  • Database or table scoped grants (read, write, or super)
  • Supports role, federated user, and federated group principals

Lake Formation Cross Account Resource Link Grants - Optional cross-account describe grants pointing to resource links.

LakeFormation


Related Modules

  • Lake Formation Settings — Configure account-level Lake Formation admin roles and IAM Allowed Principals behavior before deploying access grants
  • Data Lake — Data lake buckets register Lake Formation locations that this module can grant access to
  • DataOps Project — DataOps projects can configure Lake Formation grants directly; use this module for Glue resources created outside of MDAA
  • Roles — Create IAM roles that can be used as principals for Lake Formation grants
  • Glue Catalog Settings — Configure cross-account Glue Catalog access for resource link grants

Security/Compliance Details

This module is designed in alignment with MDAA security/compliance principles and CDK nag rulesets. Additional review is recommended prior to production deployment, ensuring organization-specific compliance requirements are met.

  • Least Privilege:
    • Fine-grained Lake Formation grants at database and table level
    • Three permission tiers: read (SELECT/DESCRIBE), write (INSERT/DELETE), and super (ALTER/DROP)
  • Separation of Duties:
    • Supports SAML-federated users and groups via IAM identity providers
    • Cross-account resource links with describe grants for data mesh/hub-spoke architectures

Configuration

MDAA Config

Add the following snippet to your mdaa.yaml under the modules: section of a domain/env in order to use this module:

lakeformation-access-control: # Module Name can be customized
  module_path: '@aws-mdaa/lakeformation-access-control' # Must match module NPM package name
  module_configs:
    - ./lakeformation-access-control.yaml # Filename/path can be customized

Module Config Samples and Variants

Copy the contents of the relevant sample config below into the ./lakeformation-access-control.yaml file referenced in the MDAA config snippet above.

Minimal Configuration

Required properties only — a single IAM role principal with a basic database grant. Start here for a straightforward Lake Formation grant to one role on one database.

sample-config-minimal.yaml

# Contents available via above link
--8<-- "target/docs/packages/apps/governance/lakeformation-access-control-app/sample_configs/sample-config-minimal.yaml"

Comprehensive Configuration

All optional properties covered — federation providers, federated user/group and IAM role principals, database and table-scoped permissions, and local/cross-account resource links. Start here when evaluating all available options for principal types, permission tiers, and cross-account resource link grants.

sample-config-comprehensive.yaml

# Contents available via above link
--8<-- "target/docs/packages/apps/governance/lakeformation-access-control-app/sample_configs/sample-config-comprehensive.yaml"

Config Schema Docs