# Lake Formation

Source: /aws/services/lakeformation/

## Introduction

Lake Formation is a managed service that allows users to build, secure, and manage data lakes.
Lake Formation allows users to define and enforce fine-grained access controls, manage metadata, and discover and share data across multiple data sources.

LocalStack allows you to use the Lake Formation APIs in your local environment to register resources, grant permissions, and list resources and permissions.
The supported APIs are available on our [API Coverage section](#api-coverage), which provides information on the extent of Lake Formation's integration with LocalStack.

## Getting started

This guide is designed for users new to Lake Formation and assumes basic knowledge of the AWS CLI and our [`lstk aws`](/aws/developer-tools/running-localstack/lstk/cloud-and-iac-commands/#aws) command.

Start your LocalStack container using your preferred method.
We will demonstrate how to register an S3 bucket as a resource in Lake Formation, grant permissions to a user, and list the resources and permissions.

### Register the resource

Create a new S3 bucket named `test-bucket` using the `mb` command:

```bash
lstk aws s3 mb s3://test-bucket
```

You can now register the S3 bucket as a resource in Lake Formation using the [`RegisterResource`](https://docs.aws.amazon.com/lake-formation/latest/dg/API_RegisterResource.html) API.
Create a file named `input.json` with the following content:

```json
{
    "ResourceArn": "arn:aws:s3:::test-bucket",
    "UseServiceLinkedRole": true
}
```

Run the following command to register the resource:

```bash
lstk aws lakeformation register-resource \
    --cli-input-json file://input.json
```

### List resources

You can list the registered resources using the [`ListResources`](https://docs.aws.amazon.com/lake-formation/latest/dg/API_ListResources.html) API.
Execute the following command to list the resources:

```bash
lstk aws lakeformation list-resources
```

```bash title="Output"
{
    "ResourceInfoList": [
        {
            "ResourceArn": "arn:aws:s3:::test-bucket",
            "LastModified": "2024-07-11T23:27:30.699312+05:30"
        }
    ]
}
```

### Grant permissions

You can grant permissions to a user or group using the [`GrantPermissions`](https://docs.aws.amazon.com/lake-formation/latest/dg/API_GrantPermissions.html) API.
Create a file named `permissions.json` with the following content:

```json showshowLineNumbers
{
    "CatalogId": "000000000000",
    "Principal": {
        "DataLakePrincipalIdentifier": "arn:aws:iam::000000000000:user/lf-developer"
    },
    "Resource": {
        "Table": {
            "CatalogId": "000000000000",
            "DatabaseName": "tpc",
            "TableWildcard": {}
        }
    },
    "Permissions": [
        "SELECT"
    ],
    "PermissionsWithGrantOption": []
}
```

Run the following command to grant permissions:

```bash
lstk aws lakeformation grant-permissions \
    --cli-input-json file://check.json
```

### List permissions

You can list the permissions granted to a user or group using the [`ListPermissions`](https://docs.aws.amazon.com/lake-formation/latest/dg/API_ListPermissions.html) API.
Execute the following command to list the permissions:

```bash
lstk aws lakeformation list-permissions
```

## API Coverage


### Lake Formation API coverage

Source service: `lakeformation`. 9 of 61 tracked operations are implemented.

Service documentation: /aws/services/lakeformation/
License availability: available starting with the Ultimate plan. See /aws/licensing/ for current plan details.

| Operation | Status |
| --- | --- |
| AddLFTagsToResource | Not implemented |
| AssumeDecoratedRoleWithSAML | Not implemented |
| BatchGrantPermissions | Not implemented |
| BatchRevokePermissions | Not implemented |
| CancelTransaction | Not implemented |
| CommitTransaction | Not implemented |
| CreateDataCellsFilter | Not implemented |
| CreateLFTag | Not implemented |
| CreateLFTagExpression | Not implemented |
| CreateLakeFormationIdentityCenterConfiguration | Not implemented |
| CreateLakeFormationOptIn | Not implemented |
| DeleteDataCellsFilter | Not implemented |
| DeleteLFTag | Not implemented |
| DeleteLFTagExpression | Not implemented |
| DeleteLakeFormationIdentityCenterConfiguration | Not implemented |
| DeleteLakeFormationOptIn | Not implemented |
| DeleteObjectsOnCancel | Not implemented |
| DeregisterResource | Implemented |
| DescribeLakeFormationIdentityCenterConfiguration | Not implemented |
| DescribeResource | Implemented |
| DescribeTransaction | Not implemented |
| ExtendTransaction | Not implemented |
| GetDataCellsFilter | Not implemented |
| GetDataLakePrincipal | Not implemented |
| GetDataLakeSettings | Implemented |
| GetEffectivePermissionsForPath | Not implemented |
| GetLFTag | Not implemented |
| GetLFTagExpression | Not implemented |
| GetQueryState | Not implemented |
| GetQueryStatistics | Not implemented |
| GetResourceLFTags | Not implemented |
| GetTableObjects | Not implemented |
| GetTemporaryDataLocationCredentials | Not implemented |
| GetTemporaryGluePartitionCredentials | Not implemented |
| GetTemporaryGlueTableCredentials | Not implemented |
| GetWorkUnitResults | Not implemented |
| GetWorkUnits | Not implemented |
| GrantPermissions | Implemented |
| ListDataCellsFilter | Not implemented |
| ListLFTagExpressions | Not implemented |
| ListLFTags | Not implemented |
| ListLakeFormationOptIns | Not implemented |
| ListPermissions | Implemented |
| ListResources | Implemented |
| ListTableStorageOptimizers | Not implemented |
| ListTransactions | Not implemented |
| PutDataLakeSettings | Implemented |
| RegisterResource | Implemented |
| RemoveLFTagsFromResource | Not implemented |
| RevokePermissions | Implemented |
| SearchDatabasesByLFTags | Not implemented |
| SearchTablesByLFTags | Not implemented |
| StartQueryPlanning | Not implemented |
| StartTransaction | Not implemented |
| UpdateDataCellsFilter | Not implemented |
| UpdateLFTag | Not implemented |
| UpdateLFTagExpression | Not implemented |
| UpdateLakeFormationIdentityCenterConfiguration | Not implemented |
| UpdateResource | Not implemented |
| UpdateTableObjects | Not implemented |
| UpdateTableStorageOptimizer | Not implemented |
