Governance boundaries
Identify which principal and policy plane controls each workshop data path.
There is no single identity spanning the full hybrid architecture. Review each path and the handoff between them.
Identity and control matrix
| Path | Executing identity | Metadata/control plane | Data authorization | Write authority in this workshop | Evidence and owner |
|---|---|---|---|---|---|
| Databricks source MCP | Read-only Databricks runtime principal used by MigrationRoom | Unity Catalog catalog/schema/table grants | Databricks SQL warehouse executes authorized reads | None; runtime needs USE CATALOG, USE SCHEMA, and SELECT only | MCP read test and source baseline; participant/source owner |
| Zero-copy Unity in ClickHouse | Workshop-scoped service principal or OAuth identity configured for the catalog attachment | Unity Catalog exposes namespaces, tables, and snapshots | Credential vending and/or scoped object-store credentials permit file reads | None through this lab path | SHOW TABLES, count/hash, redacted plan; participant and Unity/storage owners |
| Shared REST catalog | Instructor-issued read-only fixture identity | Iceberg REST service exposes the fixture namespace and table metadata | Fixture's vending/storage policy permits ClickHouse Cloud to read objects | None | Published invariant plus participant count/hash; instructor fixture owner |
| Native ClickHouse copy | Migration writer during copy; participant ClickHouse user during queries | ClickHouse databases, tables, grants, quotas, and settings | ClickHouse RBAC controls copied rows on ClickHouse storage | Migration and lab DDL write only to the participant target | Validation/invariant evidence and ClickHouse grants; participant/target owner |
Handoff at copy time
When MigrationRoom reads Databricks and writes native tables, the resulting copy crosses a governance boundary. Unity continues to govern the source, but it does not automatically govern ClickHouse's copy. ClickHouse RBAC, retention, deletion, encryption, and audit controls apply to that copy. Policy translation, row filters, masks, and continuous CDC are not automated by this workshop.
Zero-copy access is different: Unity or the REST catalog continues to control catalog visibility and storage access for its registered data, while ClickHouse also controls who may use the attached database and execute the query. Describe this as composed controls, not “the same governance everywhere.”
Least privilege and evidence safety
- Separate the provisioning principal from the read-only MigrationRoom runtime principal.
- Use short-lived, workshop-scoped catalog credentials and revoke them after the session.
- Grant the shared REST identity read-only access to a stable fixture, not administrative access.
- Scope ClickHouse users to participant databases and remove temporary grants at teardown.
- Store only hostnames, identifier suffixes, result hashes, row counts, and redacted errors in evidence. Tokens, passwords, full authorization headers, and signed URLs fail review.
Failure ownership
Route failures by layer: Databricks grants/warehouse to the source owner; Unity metadata or credential vending to the metastore owner; object reads to the storage owner; REST reachability/fixture content to the instructor; and native grants or lifecycle to the ClickHouse owner. This prevents broadening privileges merely to make a lab step pass.