You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 0a042eb
Browse filesBrowse the repository at this point in the historyBrowse files
keep Athena queries out of auto-approve unless the target allows it
An Athena archive query is reviewed even for a waiver holder: waivers and the
fingerprint cache do not apply unless the target sets
engine_config.auto_approve to true. What an archive query costs depends on the
partitions it reads, so a fleet-wide waiver, or a fingerprint that ignores
literal values, would let the expensive variant of a cheap, once-approved query
run unreviewed. A super-admin's own submission is unchanged. Every caller that
decides or announces auto-approval asks one helper,
engines.auto_approve_allowed, and a test scans the package for callers that
skip it.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Copy file name to clipboardExpand all lines: docs/CONFIGURATION.md
+17-1Lines changed: 17 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -134,7 +134,7 @@ default rather than stopping the process.
134
134
135
135
| Key | Default | What it does |
136
136
|---|---|---|
137
-
|`fingerprint_cache_enabled`|`on`| Auto-approve a re-submission identical to a previously approved query. |
137
+
|`fingerprint_cache_enabled`|`on`| Auto-approve a re-submission identical to a previously approved query. Not on an Athena target unless it allows auto-approve (see "Amazon Athena targets"). |
138
138
|`fingerprint_cache_ttl_days`|`30`| How long a fingerprint stays eligible for auto-approve. |
139
139
|`require_justification`|`false`| Require a justification note on every submission. |
140
140
|`max_open_access_requests_per_user`|`5`| Cap on pending target-access requests per user. |
@@ -228,6 +228,22 @@ described by `target_servers.engine_config`, a JSON object per target:
228
228
|`role_arn`| yes | Read-only role the gateway assumes for every call: Glue, Athena and S3. |
229
229
|`catalog`| no | Data catalog. Default `AwsDataCatalog`. |
230
230
|`freshness_marker`| no |`s3://bucket/key` of the archive's freshness marker. When set, the approver's hint says how far the archive reaches. |
231
+
|`auto_approve`| no | Default `false`: auto-approve waivers and the fingerprint approval cache do not apply, so every query goes to an approver. Set `true` to let them apply. |
232
+
233
+
Auto-approve is off on Athena because a query's cost depends on the partitions
234
+
it reads, and neither a waiver nor a fingerprint match sees which ones. Only a
235
+
JSON `true` or `false` counts; any other value means the default. A
236
+
super-admin's own query is auto-approved either way. With auto-approve off,
237
+
neither the Slack badge nor the web editor and connection list say a query
238
+
will skip review, and a request for an auto-approve window on the target is
239
+
refused. The key works the same on a PostgreSQL, SQL Server or ClickHouse
240
+
target, where the default is `true`.
241
+
242
+
```sql
243
+
UPDATE target_servers
244
+
SET engine_config = COALESCE(engine_config, '{}') ||'{"auto_approve": true}'
245
+
WHERE alias ='example-archive';
246
+
```
231
247
232
248
The freshness marker is one JSON object that the archive writes with a single
0 commit comments