Apache Iceberg Adds Specs for Unified Data Governance Across Engines and Catalogs
Apache Iceberg has introduced two new specifications, read restrictions and catalog labels, to standardize data governance across diverse engines and federated catalogs. These additions aim to remove fragmented enforcement, allowing policies to be consistently applied in an Open Lakehouse environment. Read restrictions delegate policy enforcement decisions to trusted query engines, enhancing security and control. Catalog labels enable the portability of governance metadata, such as PII indicators or business domains, between federated catalogs for consistent application across systems.
- →Read Restrictions for Delegated Policy Enforcement
- →Catalog Labels for Portable Governance Metadata
- →New Apache Iceberg Specs for Unified Governance
Features (2) ›
- Read Restrictions for Delegated Policy Enforcement
Read restrictions enable catalogs to delegate policy enforcement decisions to trusted query engines. When a reader loads a table, the catalog returns filtering or masking instructions, rather than the raw policy, for the engine to apply.
- Catalog Labels for Portable Governance Metadata
Catalog labels allow catalogs to exchange lightweight key-value metadata at the table and column level via Open APIs. These labels make governance context, such as PII indicators or business domains, portable across federated catalogs without complex policy reconciliation.
Notes (1) ›
- New Apache Iceberg Specs for Unified Governance
The Apache Iceberg community has introduced two new specifications, read restrictions and catalog labels, to the Iceberg REST Catalog. These additions aim to standardize policy enforcement across different data engines and improve governance context portability between federated catalogs.
https://www.databricks.com/blog/unifying-governance-across-engines-and-catalogs-open-lakehouse
Related releases
- Databricks-managed MCP Connectors for Genie One Now Generally Available Databricks Release Notes ·
- Databricks Genie Agents Get GA APIs and Unity Catalog Function Tools Databricks Release Notes ·
- Databricks Enhances Dashboards with AI, Materialization, and Visualization Features Databricks Release Notes ·
- Databricks Genie Agents to Restrict Data Access to Explicitly Attached Sources Databricks Release Notes ·
- Databricks Excel Add-in Reaches General Availability Databricks Release Notes ·
- Databricks Introduces Maintenance Windows for Continuous Lakeflow Pipelines Databricks Release Notes ·