Validating a Cross-Account Amazon Redshift Data Sharing Governance Pattern with Amazon SageMaker Unified Studio
Key point
This presents the optimal governance pattern for securely sharing cross-account Redshift data in SageMaker Unified Studio while isolating source compute.
Details
Through the case of a major Korean retail group, a governance pattern was validated that enables group-wide integrated analytics while operating Amazon Redshift and ML workloads separately for each subsidiary.
The core requirements are isolation of source compute, secure querying from other accounts, asset management via SageMaker Catalog, and direct querying through the Amazon Redshift engine.
As a result of validation, the most recommended architecture places the Publisher project in the source account and the Consumer project in the domain account. For operational convenience in a multi-account environment, an Account-agnostic Project Profile is used together with this structure.
This structure satisfies the requirements through two mechanisms.
- Governance path: Completes the asset publishing and subscription workflow via SMUS cross-account subscription. Since the Publisher project resides in the same account as the source cluster, exercising permissions is straightforward.
- Compute isolation path: Leverages Redshift data sharing. Consumer queries run in their own workgroup, and only storage read load is generated on the source cluster.
On the other hand, the manual data sharing approach has the limitation that SMUS Data Source cannot recognize external objects as assets, making catalog functionality unusable, and the Federated Catalog approach does not support SageMaker Catalog's publishing function.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.