Meta tags:
description= Introduction to Firebolt security features and functionality;
Headings (most frequently used words):
security, data, on, access, roles, and, managed, reference, aws, documentation, index, this, page, network, identity, management, control, iam, protection, overview, performance, observability, self, service, guides, sql, release, notes, api, legal, single, sign, sso, multi, factor, authentication, mfa, users, objects, permissions, at, rest, in, motion, secure, communication, protocols, privatelink, hipaa, compliance, the, confused, deputy, problem, strengthen, with, an, external, id,
Text of the page (most frequently used words):
the (76), and (69), firebolt (48), role (38), access (33), data (31), that (27), #security (24), can (23), with (20), permissions (20), your (19), account (19), roles (19), for (18), aws (18), users (16), example (14), sales (13), user (13), are (12), secure (12), following (12), create (12), control (11), service (11), principal (11), policy (11), you (10), set (10), authentication (10), information (9), from (9), use (9), login (9), network (9), using (8), its (8), objects (8), through (8), not (8), engine (8), kate (8), identity (8), this (7), compliance (7), all (7), which (7), external (7), trust (7), specific (7), mfa (7), documentation (6), based (6), supports (6), privatelink (6), new (6), management (6), only (6), any (6), each (6), grant (6), database (6), code (6), object (6), sql (6), sso (6), overview (6), hipaa (5), protected (5), more (5), see (5), between (5), ensuring (5), unauthorized (5), managed (5), available (5), statement (5), deputy (5), have (5), accounts (5), has (5), resources (5), allows (5), granted (5), defined (5), organization (5), sign (5), my_network_policy (5), built (4), uses (4), layer (4), rest (4), amazon (4), standards (4), sts (4), trust_policy_role (4), allow (4), value (4), assume (4), confused (4), problem (4), them (4), their (4), iam (4), ability (4), grants (4), assigned (4), what (4), bob (4), creates (4), system (4), custom (4), rbac (4), single (4), contain (3), platform (3), table (3), page (3), stored (3), within (3), without (3), over (3), provide (3), one (3), communication (3), protocols (3), such (3), protection (3), these (3), when (3), party (3), two (3), moves (3), automatically (3), motion (3), either (3), functionality (3), other (3), condition (3), version (3), does (3), credentials (3), unique (3), services (3), revokes (3), sales_eng (3), revoke (3), dev_account (3), sales_db (3), permission (3), actions (3), engines (3), queries (3), associated (3), multiple (3), they (3), administrators (3), authorized (3), types (3), model (3), ensures (3), manage (3), acme (3), com (3), authenticate (3), configuration (3), multi (3), applications (3), policies (3), individual (3), ranges (3), end (3), assistant (2), column (2), modify (2), support (2), designed (2), privacy (2), health (2), ensure (2), confidentiality (2), integrity (2), availability (2), request (2), organizational (2), enables (2), vpc (2), public (2), private (2), api (2), during (2), transport (2), tls (2), against (2), attacks (2), transmitted (2), transmission (2), sensitive (2), systems (2), remains (2), default (2), encrypted (2), storage (2), keys (2), kms (2), securely (2), encryption (2), both (2), per (2), customer (2), externalid (2), assumerole (2), action (2), effect (2), statement1 (2), sid (2), 2012 (2), add (2), setting (2), then (2), strengthen (2), tenant (2), entire (2), behalf (2), trusted (2), account_name (2), own (2), schema (2), adding (2), query (2), start (2), stop (2), operate (2), usage (2), privileges (2), revoked (2), directly (2), necessary (2), inherit (2), those (2), managing (2), databases (2), instance (2), securable (2), list (2), linked (2), created (2), workspace (2), fine (2), grained (2), requiring (2), requires (2), explicit (2), true (2), implementation (2), compliant (2), factor (2), process (2), protecting (2), accessible (2), auth0 (2), industry (2), individuals (2), verifying (2), network_policy (2), alter (2), my_organization (2), description (2), allowed_ip_list (2), machine (2), will (2), address (2), capture (2), cloud (2), features (2), practices (2), reference (2), release (2), notes (2), guides (2), search (2), index (2), responses, generated, may, mistakes, hosted, mintlify, developer, powered, instagram, youtube, facebook, linkedin, next, previous, compression, yes, was, helpful, state, contact, team, consists, federal, regulations, safeguard, patient, electronic, ephi, administrative, administrator, connectivity, routing, traffic, internet, way, connection, transit, additional, man, middle, occur, intercepts, alters, points, encrypting, connections, prevents, tampering, safeguarding, encrypts, being, components, across, networks, cannot, intercepted, parties, simple, key, firmly, committed, manages, properly, safeguarded, strict, customers, already, isolates, tenants, layers, controlled, check, top, conditions, stronger, than, recommends, configuring, external_id, stringequals, second, independent, choose, treat, secret, credential, must, keep, confidential, but, known, matching, denies, call, present, exact, aws_role_external_id, scoping, returned, above, closes, vector, never, privilege, escalation, class, holds, legitimate, induced, should, cross, arises, too, broad, trusting, instead, third, background, root, scope, because, names, satisfied, where, org_db, information_schema, select, find, querying, bedrock, reaches, assuming, referencing, assumes, time, store, long, lived, aws_role_arn, copy, location, once, allowing, define, operations, performed, running, accessing, controls, controlling, examples, include, tables, there, instances, predefined, full, order, gain, later, align, common, personas, responsibilities, including, about, account_admin, system_admin, pre, cases, statements, become, soon, first, group, defines, perform, contains, restrict, read, columns, providing, governance, views, level, hierarchical, inherited, relationships, composable, means, total, result, combining, giving, collective, every, supported, preventing, secured, centered, around, principles, appropriate, engage, implements, is_mfa_enabled, is_password_enabled, peterson, last_name, first_name, password, strengthens, forms, many, industries, regulatory, require, securing, certain, fully, offering, method, simplifying, improving, centralized, simplify, streamline, enhancing, overall, posture, breaches, org_account, provides, methods, provider, registration, standard, cryptography, exchanged, saml, protocol, step, verification, involves, identifying, applies, restricts, according, rules, attached, logins, exists, addresses, used, represent, application, interact, human, intervention, represents, identified, email, who, programmatic, properties, definition, property, blocked_ip_list, creation, extra, exercise, implementing, employs, layered, strategy, deliver, warehouse, tailored, modern, enterprise, needs, integrating, advanced, best, establishing, clear, boundaries, isolate, introduction, close, act, switching, legal, openapi, spec, uploading, files, asynchronous, synchronous, archive, settings, functions, commands, transactions, lexical, structure, migrate, integrate, develop, learning, iceberg, lake, export, change, load, dialect, regions, pricing, billing, consumption, fundamentals, organizations, web, arguments, connect, http, standalone, binaries, helm, chart, operator, self, indexing, runtime, planning, performance, observability, core, concepts, architecture, quickstart, navigation, ask, home, skip, main, content, file, discover, pages, before, exploring, further, fetch, complete, llms, txt,
Text of the page (random words):
security firebolt documentation documentation index fetch the complete documentation index at llms txt use this file to discover all available pages before exploring further skip to main content firebolt documentation home page search k ask assistant sign up sign up search navigation security security overview what is firebolt quickstart architecture core concepts performance and observability overview query planning runtime storage and indexing security overview role based access control guides self managed overview firebolt operator helm chart standalone binaries connect over http engine arguments engine configuration web ui managed service organizations and accounts engine fundamentals engine consumption pricing and billing available regions support security operate engines manage organization objects guides manage organization sql dialect load data change data capture export data iceberg and data lake ai and machine learning develop with firebolt integrate with firebolt migrate to firebolt sql reference lexical structure explicit transactions data types information schema sql commands sql functions system settings release notes overview release notes archive api reference overview synchronous queries asynchronous queries uploading files openapi spec legal eu data act switching close on this page network security identity management single sign on sso multi factor authentication mfa access control roles users objects and permissions iam roles aws the confused deputy problem strengthen access with an external id data protection data at rest data in motion secure communication protocols aws privatelink hipaa compliance security security introduction to firebolt security features and functionality firebolt employs a layered security strategy to deliver a secure and trusted cloud data warehouse tailored to modern enterprise needs by integrating advanced security features and industry best practices firebolt ensures that its security practices are compliant with security standards your data is protected remains secure and is accessible only to authorized individuals access to objects and resources is managed through accounts establishing clear boundaries to isolate and secure data network security firebolt ensures secure data transmission by implementing end to end encryption with transport layer security tls version 1 2 protecting data as it moves between end users and the cloud service firebolt supports the creation of custom network policies adding an extra layer of security to your applications this functionality allows administrators to exercise fine grained control over which ip ranges can access firebolt in firebolt network policies contain allowed_ip_list and blocked_ip_list properties that capture definition of ip address ranges each property is a list that can contain one or more ip ranges firebolt supports individual and programmatic access through the following login a login object represents an individual user identified by an email address who will authenticate by verifying their identity to access firebolt service account a service account object is used to represent a machine or application that will authenticate and interact with firebolt without human intervention example the following code example creates a network policy my_network_policy with a description that allows only two ip addresses create network policy if not exists my_network_policy with allowed_ip_list 4 5 6 1 2 4 5 1 description my new network policy a network policy can be attached to an organization individual logins and service accounts example the following code example applies my_network_policy to my_organization and to the login associated with kate acme com which restricts access according to the rules of that policy alter organization my_organization set network_policy my_network_policy alter login kate acme com set network_policy my_network_policy for more information see network policies identity management identity management is a multi step verification process designed to ensure that only authorized individuals services and applications can access organizational resources identity management involves both identifying users and verifying their identity through authentication firebolt uses auth0 as its identity provider for managing customer registration all authentication data stored in auth0 is protected with industry standard cryptography authentication information is securely exchanged using the saml 2 0 protocol firebolt provides the sso and mfa authentication methods single sign on sso single sign on sso is an authentication method that allows users to access multiple applications or services using a single set of login credentials simplifying the authentication process and improving security through centralized identity management firebolt uses sso to simplify and streamline implementation of secure access to its platform enhancing the overall security posture and protecting against unauthorized access and data breaches sso configuration is accessible to users with the org_account built in role multi factor authentication mfa mfa strengthens security by requiring users to provide multiple forms of authentication to access their accounts many industries have compliance and regulatory standards that require the use of mfa for securing certain types of data and systems firebolt fully supports these standards by offering mfa configuration and implementation directly linked to the login object ensuring secure and compliant access control example the following code example creates a login for a user enables password based authentication and requires mfa to authenticate create login kate acme com with first_name kate last_name peterson is_password_enabled true is_mfa_enabled true access control access control ensures that users have the necessary and appropriate permissions to engage with firebolt s system or resources firebolt implements role based access control rbac to manage permissions the rbac model is centered around the following principles all objects can be secured every supported statement requires explicit permission preventing unauthorized actions the rbac model is composable which means that a user s total permissions are the result of combining all the roles assigned to them giving them the collective access granted by each role roles are hierarchical and allow permissions to be inherited through role relationships column level security allows administrators to restrict read access to specific columns of a table providing fine grained data governance without requiring views the rbac model contains the following roles users objects and permissions roles a role is a set of permissions assigned to a user or group that defines what actions they are authorized to perform and what resources they can access within firebolt firebolt has the following types of roles built in roles have a set of pre defined permissions and custom user defined roles that can allow for more specific use cases you can use grant and revoke statements to modify permissions for custom roles built in roles become available as soon as a new organization is created and the first account is set up user defined roles are custom roles that administrators can create to grant a specific set of permissions system defined roles align with common user personas and responsibilities including public which is granted to each new user by default a system_admin role and an account_admin role for more information about these roles see system defined roles you can create a role by using either the firebolt workspace or using the create role sql statement example the following example creates a new role sales which can later be assigned specific permissions and granted to users to inherit those permissions create role sales users users are linked to either a login or service account in order to gain access to firebolt they can be created using the create user statement in sql or through the firebolt workspace example the following code creates a new users kate and bob create user kate create user bob example the following code example grants the permissions associated with the sales role to kate and revokes it from bob grant role sales to user kate revoke role sales from user bob objects and permissions permissions in firebolt define the actions or operations that can be performed such as managing databases and engines running queries or accessing data each instance of a securable object or an object that can be protected by access controls has specific permissions that are associated with it controlling what users can do with it examples of securable objects include databases tables and engines if there are multiple instances of an engine object each instance has its own set of predefined permissions for a full list of available permissions see role based access control any permission that firebolt supports can be granted or revoked to or from roles privileges can be granted or revoked only for roles not directly for users once a role has the necessary permissions it can then be assigned to users allowing them to inherit those privileges example the following code example grants the sales role permission to use the sales_db database allows the role to access any database within dev_account and revokes the ability of the sales role to start or stop the sales_eng engine grant usage on database sales_db to sales grants the ability to use sales_db database to the sales role grant usage any database on account dev_account to sales grants the ability to use any database in dev_account to the sales role revoke operate on engine sales_eng from sales revokes the ability to start and stop the sales_eng engine from sales role iam roles when you use create location copy from or create external table to access aws services such as amazon s3 and amazon bedrock firebolt reaches resources in your aws account by assuming an iam role that you create and control you grant access by adding firebolt s principal to your role s trust policy and referencing the role with aws_role_arn firebolt assumes the role at query time and does not store long lived credentials for your account aws each firebolt account has its own unique iam principal that firebolt uses to assume your role find the principal for your account by querying the information schema select trust_policy_role from org_db information_schema accounts where account_name account_name scope your role s trust policy to this principal because the principal is unique to your account a trust policy that names it can only be satisfied by your account not by any other firebolt tenant version 2012 10 17 statement sid statement1 effect allow principal aws trust_policy_role action sts assumerole the confused deputy problem the confused deputy problem is a privilege escalation class in which a service that holds legitimate access the deputy is induced to use its permissions on behalf of a party that should not have them in an aws cross account setting it arises when a role s trust policy is too broad for example trusting an entire aws account root instead of a specific principal so that a third party can have the trusted service assume the role on their behalf for background see aws s the confused deputy problem scoping your trust policy to the per account principal returned above closes this vector the principal is unique to your account so no other firebolt tenant can assume your role trust the specific trust_policy_role value never an entire aws account strengthen access with an external id you can add a second independent condition by setting an external id an external id is a value you choose and control aws does not treat it as a secret so it is not a credential you must keep confidential but you set its value and it is known only to you set aws_role_external_id in your firebolt credentials and add a matching sts externalid condition to your role s trust policy aws then denies any assume role call that does not present the exact value version 2012 10 17 statement sid statement1 effect allow principal aws trust_policy_role action sts assumerole condition stringequals sts externalid external_id the per account principal already isolates your role from other tenants an external id layers a customer controlled check on top of it and two conditions are stronger than one so firebolt recommends configuring an external id for role based access data protection firebolt is firmly committed to data security privacy and compliance by ensuring that all data it manages is properly safeguarded and protected through strict encryption standards for data both in motion and at rest the following security functionality is automatically available to customers data at rest by default all data at rest is encrypted and stored using amazon simple storage service s3 all new objects are automatically encrypted using either amazon s3 managed keys or aws key management service kms keys which are securely managed through aws kms data in motion firebolt automatically encrypts sensitive data being transmitted between service components ensuring that it remains secure as it moves across networks and cannot be intercepted by unauthorized parties secure communication protocols firebolt uses secure communication protocols such as transport layer security tls to provide an additional layer of protection against man in the middle attacks these attacks occur when an unauthorized party intercepts or alters data as it is transmitted between two points by encrypting data and ensuring secure connections firebolt prevents unauthorized access or tampering during data transmission safeguarding sensitive information as it moves between systems aws privatelink aws privatelink enables secure connectivity between your vpc and firebolt without routing traffic over the public internet firebolt supports aws privatelink to provide a private one way connection from your vpc to the firebolt private api ensuring data confidentiality integrity and availability during transit users with an account administrator or organizational administrative role can request access to privatelink for more information see request privatelink access hipaa compliance hipaa compliance consists of federal regulations designed to safeguard the privacy and security of patient health information firebolt supports hipaa compliance to ensure the confidentiality integrity and availability of electronic protected health information ephi stored within its platform to modify the state of hipaa compliance for your account contact the firebolt support team was this page helpful yes no table and column compression previous role based access control next i linkedin facebook youtube instagram x powered by this documentation is built and hosted on mintlify a developer documentation platform assistant responses are generated using ai and may contain mistakes
|