Container compute platform
A data platform for executing containers is provided. In some examples, the data platform receives an application from an application package of a provider account, the application including a setup script and a manifest of a service. The data platform activates access roles based on the manifest and creates the service and a compute pool using the setup script and a specification file accessed from the application package using an access role. The service is executed in the compute pool, accessing objects of the application package and of the data platform using the access roles.
1 . A machine-implemented method, comprising:
receiving, in a consumer account of a data platform, an application from an application package of a provider account of the data platform, the application including a setup script and a manifest of a service provided by the application, the application package comprising one or more components stored in a hidden repository within the provider account by the data platform, the one or more components hidden from a provider user of the provider account by the data platform such that the provider user cannot access or change the one or more components after installation of the application;
activating one or more access roles based on the manifest;
creating the service and a compute pool of the data platform using the setup script and a specification file accessed from the application package using an access role of the one or more access roles; and
executing the service in the compute pool, the executing of the service including accessing objects of the application package and of the data platform using the one or more access roles.
2 . The machine-implemented method of claim 1 , wherein the one or more access roles are exclusive to the service and are not associated with a consumer user of the consumer account or a provider user of the provider account.
3 . The machine-implemented method of claim 1 , further comprising:
creating a query warehouse of the data platform using the setup script; and
querying, by the service, one or more objects of the data platform using the query warehouse and the one or more access roles.
4 . The machine-implemented method of claim 1 , wherein the service specification file includes a list of container images and corresponding versions to be used by the service.
5 . The machine-implemented method of claim 4 , further comprising scanning the container images for security vulnerabilities before the service is executed in the compute pool.
6 . The machine-implemented method of claim 1 , further comprising:
isolating the compute pool to prevent the service from accessing other services or resources not specified in the application package.
7 . The machine-implemented method of claim 6 , wherein the compute pool is exclusively dedicated to the service.
8 . The machine-implemented method of claim 1 , further comprising:
enabling the service to communicate with external networks through an external access integration that is configured and controlled by the consumer account.
9 . The machine-implemented method of claim 8 , wherein the setup script defines one or more network rules for the external access integration that control communication between the service and the external networks.
10 . A system comprising:
at least one hardware processor; and
at least one memory storing instructions that, when executed by the at least one hardware processor, cause the system to perform operations comprising:
receiving, in a consumer account of a data platform, an application from an application package of a provider account of the data platform, the application including a setup script and a manifest of a service provided by the application, the application package comprising one or more components stored in a hidden repository within the provider account by the data platform, the one or more components hidden from a provider user of the provider account by the data platform such that the provider user cannot access or change the one or more components after installation of the application;
activating one or more access roles based on the manifest;
creating the service and a compute pool of the data platform using the setup script and a specification file accessed from the application package using an access role of the one or more access roles; and
executing the service in the compute pool, the executing of the service including accessing objects of the application package and of the data platform using the one or more access roles.
11 . The system of claim 10 , wherein the one or more access roles are exclusive to the service and are not associated with a consumer user of the consumer account or a provider user of the provider account.
12 . The system of claim 10 , wherein the operations further comprise:
creating a query warehouse of the data platform using the setup script; and
querying, by the service, one or more objects of the data platform using the query warehouse and the one or more access roles.
13 . The system of claim 10 , wherein the service specification file includes a list of container images and corresponding versions to be used by the service.
14 . The system of claim 13 , wherein the operations further comprise scanning the container images for security vulnerabilities before the service is executed in the compute pool.
15 . The system of claim 10 , wherein the operations further comprise:
isolating the compute pool to prevent the service from accessing other services or resources not specified in the application package.
16 . The system of claim 15 , wherein the compute pool is exclusively dedicated to the service.
17 . The system of claim 10 , wherein the operations further comprise:
enabling the service to communicate with external networks through an external access integration that is configured and controlled by the consumer account.
18 . The system of claim 17 , wherein the setup script defines one or more network rules for the external access integration that control communication between the service and the external networks.
19 . A machine-storage medium storing instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:
receiving, in a consumer account of a data platform, an application from an application package of a provider account of the data platform, the application including a setup script and a manifest of a service provided by the application, the application package comprising one or more components stored in a hidden repository within the provider account by the data platform, the one or more components hidden from a provider user of the provider account by the data platform such that the provider user cannot access or change the one or more components after installation of the application;
activating one or more access roles based on the manifest;
creating the service and a compute pool of the data platform using the setup script and a specification file accessed from the application package using an access role of the one or more access roles; and
executing the service in the compute pool, the executing of the service including accessing objects of the application package and of the data platform using the one or more access roles.
20 . The machine-storage medium of claim 19 , wherein the one or more access roles are exclusive to the service and are not associated with a consumer user of the consumer account or a provider user of the provider account.
21 . The machine-storage medium of claim 19 , wherein the operations further comprise:
creating a query warehouse of the data platform using the setup script; and
querying, by the service, one or more objects of the data platform using the query warehouse and the one or more access roles.
22 . The machine-storage medium of claim 19 , wherein the service specification file includes a list of container images and corresponding versions to be used by the service.
23 . The machine-storage medium of claim 22 , wherein the operations further comprise scanning the container images for security vulnerabilities before the service is executed in the compute pool.
24 . The machine-storage medium of claim 19 , wherein the operations further comprise:
isolating the compute pool to prevent the service from accessing other services or resources not specified in the application package.
25 . The machine-storage medium of claim 24 , wherein the compute pool is exclusively dedicated to the service.
26 . The machine-storage medium of claim 19 , wherein the operations further comprise:
enabling the service to communicate with external networks through an external access integration that is configured and controlled by the consumer account.
27 . The machine-storage medium of claim 26 , wherein the setup script defines one or more network rules for the external access integration that control communication between the service and the external networks.