Manage Resources List¶
You can configure the MSSQL connector to manage access control policies for specific databases, schemas, and tables/views. You can specify lists to include and exclude resources. The connector manages access control policies for resources in the include list and ignores resources in the exclude list. If a resource is in the exclude list, the connector does not manage it, even if it is also in the include list.
Use the following properties to specify comma-separated databases, schemas, and tables/views whose access control should be managed by PolicySync. To manage all resources, do not specify these properties. You can use wildcard characters (*) to match multiple databases, schemas, and tables/views.
Example:
- Databases:
sales_db,production_db,test_* - Schemas:
sales_db.schema1,sales_db.sales*,production_db.* - Tables/Views:
sales_db.schema1.table1,sales_db.sales*.orders*,sales_db.schema1.view1
Setup¶
Warning
- Values are case-sensitive.
- Provide fully qualified names for schemas, tables, and views. For example:
database.schema.table - Replace the example values with your actual resource names.
- If you leave a property empty, all resources of that type will be managed (unless excluded).
-
SSH to the instance where Privacera Manager is installed.
-
Run the following command to open the
.ymlfile to be edited.If you have multiple connectors, then replace
instance1with the appropriate connector instance name.Bash -
Set the following properties to enable the connector to manage the permissions for databases, schemas, tables, and views in MSSQL:
-
For excluding resources, set the following properties:
-
Once the properties are configured, run the following commands to update your Privacera Manager platform instance:
Step 1 - Setup which generates the helm charts. This step usually takes few minutes.
Step 2 - Apply the Privacera Manager helm charts. Step 3 - (Optional) Post-installation step which generates Plugin tar ball, updates Route 53 DNS and so on. This step is not required if you are updating only connector properties.
-
In PrivaceraCloud portal, navigate to Settings -> Applications.
-
On the Connected Applications screen, select MSSQL.
-
Click the pen icon or the Account Name to modify the settings.
-
On the Edit Application screen, go to Access Management -> ADVANCED tab.
-
For including resources, enter the following values in the respective fields:
- Database to set access control policies:
sales_db,production_db - Schemas to set access control policies:
sales_db.schema1,sales_db.sales* - Tables to set access control policies:
sales_db.schema1.table1,sales_db.sales*.orders*
- Database to set access control policies:
-
For excluding resources, enter the following values in the respective fields:
- Databases to ignore while setting access control policies:
test_db,dev_* - Schemas to ignore while setting access control policies:
sales_db.sys,sales_db.INFORMATION_SCHEMA
- Databases to ignore while setting access control policies:
-
Click SAVE to apply the changes.
- Prev topic: Advanced Configuration