Grant an Application Direct Access to a JDBC Datastore
The raw SQL actions on the Jdbc Type, such as Jdbc#queryTuples and Jdbc#exec, are restricted to cluster administrators. Direct access lets a cluster administrator allowlist a specific application to run those actions against a specific named datastore, without granting the application cluster-admin privileges. Every direct-access query re-checks the allowlist before it runs, and an application cannot allowlist itself.
Allowlist an application (cluster administrator)
Map the application id (<cluster>-<env>-<app>) to the datastore names in Jdbc.DirectAccess.Config. The value is a list, so an application can be allowlisted for more than one datastore:
Jdbc.DirectAccess.Config.inst()
.setConfigMapValue("allowedDatastoreByAppId", "myCluster-myEnv-myApp", ["MyDatastore"], ConfigOverride.CLUSTER);To revoke access, remove the entry with removeConfigMapKey("allowedDatastoreByAppId", "myCluster-myEnv-myApp", ConfigOverride.CLUSTER).
Run a direct-access query (allowlisted application)
Obtain a Jdbc.DirectAccess handle from a named datastore connection and run raw SQL:
var directAccess = Jdbc.connectToDatastore("MyDatastore").directAccess();
var rows = directAccess.queryTuples("SELECT ID, NAME FROM MY_TABLE", false);Obtaining the handle throws an authorization error if the application is not allowlisted for the datastore.