Skip to main content

Redshift Schema

datashare​

The datashare block describes a datashare created in this database, and the consumers granted access to it. A function is shared by name: Redshift does not report which of its overloads a datashare holds, so every overload is added to and removed from the share together.

datashare "sales_share" {
public_accessible = false
schema {
for = schema.sales
objects = [table.orders, view.summary]
}
schema {
for = schema.logs
include_new = true
}
schema {
for = schema.events
include_new_except = [table.audit]
}
namespaces = ["00000000-0000-0000-0000-000000000000"]
accounts = ["000000000000"]
}

datashare attributes​

Name and descriptionRequiredValue

accounts

AWS account IDs of the consumers granted usage on the datashare. Used for a consumer in another account, which then grants its own namespaces.

false

List of strings

namespaces

Namespace identifiers of the consumers granted usage on the datashare. Used for a consumer in the same AWS account.

false

List of strings

public_accessiblefalsebool

datashare blocks​

datashare.schema​

A schema shared by the datashare, and the objects shared from it.

datashare.schema attributes​
Name and descriptionRequiredValue
fortrue

Schema reference or name can be one of:

  1. Object reference to schema
  2. string

include_new

Share every object of the schema, including the ones created later. Redshift shares only the objects created after this is set, so the ones that already exist are shared by Atlas.

falsebool

include_new_except

Share every object of the schema except these. Implies include_new.

false

List of values, where each can be one of:

  1. Object reference to table
  2. Object reference to view
  3. Object reference to materialized
  4. Object reference to function
objectsfalse

List of values, where each can be one of:

  1. Object reference to table
  2. Object reference to view
  3. Object reference to materialized
  4. Object reference to function
  5. string
datashare.schema blocks​

datashare.schema.annotation​

datashare.schema.annotation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Allow unknown blockstrue
Allow unknown attributestrue
datashare.schema constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue
Mutually exclusive sets[objects, include_new, include_new_except]

datashare constraints​

ConstraintValue
Requiredfalse
Require Name (e.g., datashare "name" )true
One of required sets[namespaces, accounts]

function​

The function block describes a function in a database schema.

function "positive" {
schema = schema.public
lang = SQL
arg "v" {
type = integer
}
...
}

function attributes​

NameRequiredValue
astruestring
depends_onfalse

List of object references

langtrue

Function language can be one of:

  1. string
  2. enum (SQL)
returnfalse

Function return type can be one of:

  1. Schema type
  2. Raw expression defined with sql("expr")
schematrue

Object reference to schema

volatilityfalse

enum (VOLATILE, STABLE, IMMUTABLE)

function blocks​

function.annotation​

function.annotation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Allow unknown blockstrue
Allow unknown attributestrue

function.arg​

function.arg attributes​
NameRequiredValue
typetrue

Function argument type can be one of:

  1. Schema type
  2. Raw expression defined with sql("expr")
function.arg constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue

function constraints​

ConstraintValue
Requiredfalse
Require Name (e.g., function "name" )true
Allow Qualifier (e.g., function "schema" "name" )true
Repeatabletrue

materialized​

The materialized block describes a materialized view in a database schema.

materialized "name" {
schema = schema.public
column "total" {
null = true
type = numeric
}
...
}

materialized attributes​

NameRequiredValue
astruestring
auto_refreshfalsebool
commentfalsestring
depends_onfalse

List of object references

schematrue

Object reference to schema

materialized blocks​

materialized.annotation​

materialized.annotation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Allow unknown blockstrue
Allow unknown attributestrue

materialized.column​

materialized.column attributes​
NameRequiredValue
commentfalsestring
nullfalsebool
typetrue

Column type can be one of:

  1. Schema type
  2. Raw expression defined with sql("expr")
materialized.column blocks​

materialized.column.annotation​

materialized.column.annotation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Allow unknown blockstrue
Allow unknown attributestrue
materialized.column constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., materialized.column "name" )true

materialized.distribution​

materialized.distribution attributes​
NameRequiredValue
columnfalse

Object reference

stylefalse

enum (EVEN, ALL, KEY)

materialized.sort​

materialized.sort attributes​
NameRequiredValue
columnsfalse

List of object reference to column

stylefalse

enum (COMPOUND)

materialized constraints​

ConstraintValue
Requiredfalse
Require Name (e.g., materialized "name" )true
Allow Qualifier (e.g., materialized "schema" "name" )true

permission​

The permission block describes privileges granted on database objects.

permission {
to = user.app
for = table.users
privileges = [SELECT]
}

permission attributes​

NameRequiredValue
fortrue

Permission target resource can be one of:

  1. Object reference to schema
  2. Object reference to table
  3. Object reference to view
  4. Object reference to materialized
  5. Object reference to function
  6. Object reference to procedure
  7. Object reference to table.column
  8. Object reference to view.column
  9. Object reference to materialized.column
grantablefalsebool
privilegestrue

List of strings or/and enums (SELECT, INSERT, UPDATE, DELETE, DROP, REFERENCES, TRUNCATE, ALTER, TRIGGER, RULE, CREATE, USAGE, EXECUTE, ALL)

totrue

Permission grantee can be one of:

  1. string
  2. Object reference to role
  3. Object reference to user

permission constraints​

ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue

procedure​

The procedure block describes a procedure in a database schema.

procedure "proc" {
schema = schema.public
lang = SQL
arg "a" {
type = integer
}
...
}

procedure attributes​

NameRequiredValue
astruestring
depends_onfalse

List of object references

langtrue

Procedure language can be one of:

  1. string
  2. enum (SQL)
  3. enum (PLpgSQL)
schematrue

Object reference to schema

securityfalse

enum (DEFINER, INVOKER)

procedure blocks​

procedure.annotation​

procedure.annotation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Allow unknown blockstrue
Allow unknown attributestrue

procedure.arg​

procedure.arg attributes​
NameRequiredValue
modefalse

Procedure argument mode can be one of:

  1. string
  2. enum (IN, OUT, INOUT)
typetrue

Procedure argument type can be one of:

  1. Schema type
  2. Raw expression defined with sql("expr")
procedure.arg constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue

procedure constraints​

ConstraintValue
Requiredfalse
Require Name (e.g., procedure "name" )true
Allow Qualifier (e.g., procedure "schema" "name" )true
Repeatabletrue

role​

The role block describes a database role or group.

role "analysts" {
member_of = [role.readers]
comment = "Analytics team"
}

role attributes​

NameRequiredValue
commentfalsestring
conn_limitfalseint
create_dbfalsebool
externalfalsebool
groupfalsebool
member_offalse

List of object reference to role

namefalsestring
superuserfalsebool

role blocks​

role.membership​

The membership block describes a membership in a role, along with its options.

user "vault" {
membership {
role = role.reader
admin = true
}
}
role.membership attributes​
NameRequiredValue
adminfalsebool
roletrue

Object reference to role

role.membership constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue

role constraints​

ConstraintValue
Requiredfalse
Require Name (e.g., role "name" )true

schema​

The schema block describes a database schema.

schema "public" {
...
}

schema attributes​

NameRequiredValue
commentfalsestring
namefalsestring

schema blocks​

schema.annotation​

schema.annotation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Allow unknown blockstrue
Allow unknown attributestrue

schema.external.data_catalog​

schema.external.data_catalog attributes​
NameRequiredValue
catalog_rolefalsestring
databasefalsestring
iam_rolefalsestring
regionfalsestring

schema.external.hive_metastore​

schema.external.hive_metastore attributes​
NameRequiredValue
databasefalsestring
iam_rolefalsestring
portfalseint
urifalsestring

schema.external.kafka​

schema.external.kafka attributes​
NameRequiredValue
authenticationfalse

Streaming authentication type can be one of:

  1. string
  2. enum (NONE, IAM, MTLS)
authentication_arnfalsestring
iam_rolefalsestring
regionfalsestring
secret_arnfalsestring
urifalsestring

schema.external.kinesis​

schema.external.kinesis attributes​
NameRequiredValue
iam_rolefalsestring
regionfalsestring

schema.external.msk​

schema.external.msk attributes​
NameRequiredValue
authenticationfalse

Streaming authentication type can be one of:

  1. string
  2. enum (NONE, IAM, MTLS)
authentication_arnfalsestring
cluster_arnfalsestring
iam_rolefalsestring
regionfalsestring
secret_arnfalsestring
urifalsestring

schema.external.mysql​

schema.external.mysql attributes​
NameRequiredValue
databasefalsestring
iam_rolefalsestring
portfalseint
secret_arnfalsestring
urifalsestring

schema.external.postgres​

schema.external.postgres attributes​
NameRequiredValue
databasefalsestring
iam_rolefalsestring
portfalseint
schemafalsestring
secret_arnfalsestring
urifalsestring

schema.external.redshift​

schema.external.redshift attributes​
NameRequiredValue
databasefalsestring
schemafalsestring

schema constraints​

ConstraintValue
Requiredfalse
Require Name (e.g., schema "name" )true

table​

The table block describes a table in a database schema.

table "users" {
schema = schema.public
column "id" {
type = int
}
...
}

table attributes​

NameRequiredValue
commentfalsestring
schematrue

Object reference to schema

table blocks​

table.annotation​

table.annotation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Allow unknown blockstrue
Allow unknown attributestrue

table.column​

table.column attributes​
NameRequiredValue
commentfalsestring
defaultfalse

Column default value can be one of:

  1. bool
  2. string
  3. number
  4. Raw expression defined with sql("expr")
encodefalse

enum (RAW, AZ64, BYTEDICT, DELTA, DELTA32K, LZO, MOSTLY8, MOSTLY16, MOSTLY32, RUNLENGTH, TEXT255, TEXT32K, ZSTD)

nullfalsebool
typetrue

Column type can be one of:

  1. Schema type
  2. Raw expression defined with sql("expr")
table.column blocks​

table.column.annotation​

table.column.annotation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Allow unknown blockstrue
Allow unknown attributestrue

table.column.identity​

table.column.identity attributes​
NameRequiredValue
generatedfalse

enum (ALWAYS, BY_DEFAULT)

seedfalseint
stepfalseint
table.column constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., table.column "name" )true

table.distribution​

table.distribution attributes​
NameRequiredValue
columnfalse

Object reference

stylefalse

enum (EVEN, KEY, ALL, AUTO)

table.sort​

table.sort attributes​
NameRequiredValue
columnsfalse

List of object reference to column

stylefalse

enum (AUTO, COMPOUND, INTERLEAVED)

table constraints​

ConstraintValue
Requiredfalse
Require Name (e.g., table "name" )true
Allow Qualifier (e.g., table "schema" "name" )true

user​

The user block describes a database user.

user "app_user" {
password = "<sensitive>"
valid_until = "2025-12-31 23:59:59+00"
member_of = [role.analysts]
params = {
enable_case_sensitive_super_attribute = true
statement_timeout = 60000
}
}

user attributes​

NameRequiredValue
commentfalsestring
conn_limitfalseint
create_dbfalsebool
externalfalsebool
groupfalsebool
member_offalse

List of object reference to role

namefalsestring
paramsfalsemap
passwordfalsestring
superuserfalsebool
valid_untilfalsestring

user blocks​

user.membership​

The membership block describes a membership in a role, along with its options.

user "vault" {
membership {
role = role.reader
admin = true
}
}
user.membership attributes​
NameRequiredValue
adminfalsebool
roletrue

Object reference to role

user.membership constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Repeatabletrue

user constraints​

ConstraintValue
Requiredfalse
Require Name (e.g., user "name" )true

view​

The view block describes a view in a database schema.

view "clean_users" {
schema = schema.public
column "id" {
type = int
}
...
}

view attributes​

NameRequiredValue
astruestring
commentfalsestring
depends_onfalse

List of object references

schematrue

Object reference to schema

view blocks​

view.annotation​

view.annotation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Allow unknown blockstrue
Allow unknown attributestrue

view.column​

view.column attributes​
NameRequiredValue
commentfalsestring
nullfalsebool
typetrue

Column type can be one of:

  1. Schema type
  2. Raw expression defined with sql("expr")
view.column blocks​

view.column.annotation​

view.column.annotation constraints​
ConstraintValue
Requiredfalse
Require Namefalse
Allow unknown blockstrue
Allow unknown attributestrue
view.column constraints​
ConstraintValue
Requiredfalse
Require Name (e.g., view.column "name" )true

view constraints​

ConstraintValue
Requiredfalse
Require Name (e.g., view "name" )true
Allow Qualifier (e.g., view "schema" "name" )true