Skip to main content

The Datastrato Enterprise UI

The Datastrato Enterprise UI is where administrators and data owners connect sources, browse and classify metadata, grant access, and run jobs. It talks to the same Gravitino server as the REST API and the engines, so a change made in the UI is visible to every client at once, and the UI enforces the same privileges: a user sees and changes only what their roles allow.

Signing in​

The sign-in page offers Continue with single sign-on for users of your identity provider, and Sign in with a password for local users. The name and sign-on method of the current user show at the bottom of the navigation bar.

Layout​

The navigation bar on the left holds three things above the sections:

  • The metalake selector at the top. Everything below it works within the selected metalake.
  • Search, which also opens with Cmd+K or Ctrl+K.
  • The sections, described below.

Each section opens on its own page, and most are split into tabs.

SectionTabsWhat it is for
ExplorenoneBrowse catalogs, schemas, and the objects in them as a tree, see each object's tags, policies, and grants, and attach tags and policies. Create schemas from a catalog's page.
GovernOverview, Tags, Policies, Privileges, LineageCreate and manage tags and policies, review who holds which privileges, and follow lineage.
AutomateOverview, Jobs, TemplatesRegister job templates and run jobs.
ConnectCatalogsAdd catalogs, test their connections, and edit their connection settings.
AuthorizeOverview, Roles, Users, GroupsCreate roles, grant privileges to them, and assign them to users and groups.
MonitornoneRequest rates, p95 latency, heap use, and server errors for the Gravitino server and its Iceberg REST and Lance REST services.
ConfigureMetalakes, Identity provider, Directory, Events, Settings, Client accessServer-wide settings: metalakes, the identity provider and SCIM tokens, the user directory, event listeners, the server properties set by the Helm chart, and the endpoints and connector installs for clients.

Most lists select rows with a checkbox, and the buttons above the list act on the selected rows. Buttons that start with + add something, such as + Catalog on Connect or + Role on Authorize, and open a panel on the right. Nothing is saved until the panel's final button, such as Create catalog or Add role, is clicked.

Configure → Settings is read only. It shows the server properties set through the Helm chart, which are changed in my-values.yaml; see Install with Helm.

The sections​

Explore​

Explore, listing the catalogs of the acme metalake with their tags and policies

Govern​

Govern Overview, with asset, ownership, and policy counts and tag coverage by catalog and by type

Automate​

Automate Overview, with running, failed, and completed jobs and the recent runs

Connect​

Connect with the Create catalog panel open

Authorize​

Authorize Overview, with user, group, and role counts and access by catalog

Monitor​

Monitor, with request rate, latency, heap, errors, and traffic by service

Configure​

Configure on the Metalakes tab

Common tasks​

TaskWhereSee
Connect a catalogConnect → Catalogs → + CatalogCatalogs and schemas
Create a schemaExplore → the catalog → + SchemaCatalogs and schemas
Create a tagGovern → Tags → + TagTags
Tag objectsExplore → select the rows → + TagsTags
Create a role and grant privilegesAuthorize → Roles → + Role, then the role's Privileges tabRoles
Give a user or group accessThe role's Members tab → + MembersRoles
Create a policyGovern → Policies → + PolicyPolicies
Create a metalakeConfigure → Metalakes → + MetalakeMetalakes
Run a jobAutomate → Jobs → Run jobJobs
Add a job templateAutomate → Templates → + TemplateTemplates