AmazonDataZoneGlueAccess-<region>-<domainId> - Amazon DataZone


The AmazonDataZoneGlueAccess-<region>-<domainId> role has the AmazonDataZoneGlueManageAccessRolePolicy attached. This role grants Amazon DataZone permissions to publish AWS Glue data to the catalog. It also gives Amazon DataZone permissions to grant access or revoke access to AWS Glue published assets in the catalog.

The default AmazonDataZoneGlueAccess-<region>-<domainId> role has the following trust policy attached:

{ "Version": "2012-10-17", "Statement": [ { "Effect": "Allow", "Principal": { "Service": "" }, "Action": "sts:AssumeRole", "Condition": { "StringEquals": { "aws:SourceAccount": "{{domain_account}}" }, "ArnEquals": { "aws:SourceArn": "arn:aws:datazone:{{region}}:{{domain_account}}:domain/{{root_domain_id}}" } } } ] }