@aws-mdaa/lakeformation-settings
v1.8.1
Published
MDAA lakeformation-settings module
Readme
Lake Formation Settings
Note: This documentation is also available in a rendered format here.
Configures account-level Lake Formation settings including administrator roles, default IAM Allowed Principals behavior, DataZone admin role creation, IAM Identity Center integration, and S3 Tables integration with AWS analytics services. Use this module as a prerequisite when setting up Lake Formation-based data governance, to establish admin roles and control whether new Glue resources default to IAM or Lake Formation permissions.
⚠️ Account-Level Module — This module can only be deployed once per AWS account. A second deployment to the same account will fail. See Account-Level Modules for details.
Deployed Resources
This module deploys and integrates the following resources:
LakeFormation Settings - Configures LakeFormation administrator roles and default permissions behavior for IAM Allowed Principals on new Glue Databases/Tables.
DataZone Manage Access Role (Optional) - IAM role with cross-account trust for centralized DataZone data governance, with ARN stored in SSM Parameter Store.
IAM Identity Center Configuration (Optional) - Configures Lake Formation integration with IAM Identity Center for SSO-based access.
S3 Tables Integration (Optional) - Automates the S3 Tables "Enable integration" action by creating the s3tablescatalog Glue federated catalog, making S3 table buckets in this account/Region queryable from AWS analytics services (Athena, Redshift, EMR, QuickSight) without a manual console step. Glue registers the table bucket location with Lake Formation using IAM (IAM_ALLOWED_PRINCIPALS) access controls. The s3tablescatalog catalog is created with IAM_ALLOWED_PRINCIPALS/ALL default database and table permissions and full external table access regardless of this module's iamAllowedPrincipalsDefault setting — so these catalogs are governed by IAM rather than fine-grained Lake Formation grants (this matches the S3 console "Enable integration" behavior, and does not change the default permissions applied to your other, non-S3-Tables, databases and tables). Because the integration is a single shared resource per account/Region, it is deliberately placed in this account-level module. On stack delete the integration is left in place by default (so queries for other deployments don't break); set removeOnDelete: true to tear it down. If the s3tablescatalog catalog already exists (for example it was enabled from the S3 console, or by an earlier deployment), MDAA treats that as success and leaves the existing catalog's permissions unchanged — it does not re-apply or verify the default permissions against an already-present catalog.

Related Modules
- Lake Formation Access Control — Deploy fine-grained Lake Formation grants after configuring account-level settings with this module
- Data Lake — Data lake Lake Formation locations require admin roles configured by this module
- DataZone — DataZone domains integrate with Lake Formation admin roles configured here
- SageMaker (Domain) — SageMaker domains integrate with Lake Formation admin roles configured here
- Glue Catalog Settings — Configure Glue Catalog encryption alongside Lake Formation settings for the account
- S3 Tables — Enable
s3TablesIntegrationhere so S3 table buckets deployed by that module are queryable from AWS analytics services
Security/Compliance Details
This module is designed in alignment with MDAA security/compliance principles and CDK nag rulesets. Additional review is recommended prior to production deployment, ensuring organization-specific compliance requirements are met.
- Least Privilege:
- Lake Formation admin roles (lakeFormationAdminRoles) control all data access grants
- IAM Allowed Principals default configurable (disable for strict LF-only governance)
- Optional CDK deploy role as LF admin for automated deployments
- Separation of Duties:
- DataZone admin role with cross-account trust for centralized data governance
- IAM Identity Center integration for SSO-based Lake Formation access
Configuration
MDAA Config
Add the following snippet to your mdaa.yaml under the modules: section of a domain/env in order to use this module:
lakeformation-settings: # Module Name can be customized
module_path: '@aws-mdaa/lakeformation-settings' # Must match module NPM package name
module_configs:
- ./lakeformation-settings.yaml # Filename/path can be customizedModule Config Samples and Variants
Copy the contents of the relevant sample config below into the ./lakeformation-settings.yaml file referenced in the MDAA config snippet above.
Minimal Configuration
Required properties only — Lake Formation admin roles and IAM Allowed Principals default. Start here for basic account-level Lake Formation setup with an admin role.
# Contents available via above link
--8<-- "target/docs/packages/apps/governance/lakeformation-settings-app/sample_configs/sample-config-minimal.yaml"Comprehensive Configuration
Covers Lake Formation admin roles, IAM permission defaults, cross-account sharing, DataZone integration, IAM Identity Center integration, and S3 Tables integration for centralized data governance. Start here when evaluating all available options for admin roles, SSO integration, cross-account DataZone governance, and automated S3 Tables analytics enablement.
sample-config-comprehensive.yaml
# Contents available via above link
--8<-- "target/docs/packages/apps/governance/lakeformation-settings-app/sample_configs/sample-config-comprehensive.yaml"