• Projects
  • Service
  • About
  • branding.bz
  • Podcast
  • Tips
  • FAQ
  • Recruit
  • Download
  • Contact
  • branding.bz(ブランド構築SaaS)
  • DESIGN NOW(デザインメディア)
  • X
  • LinkedIn
  • Spotify
  • Facebook

213-0011 神奈川県川崎市高津区久本3-6-7-303

© 2026 ID INC. All rights reserved

claude-skills/スキル
SKILLOfficialdatabase

databricks-unity-catalog

プラグイン
databricks
ソース
GitHub で見る ↗
説明

Unity Catalogの管理、アクセス制御、および監視機能を提供します。 以下のような用途に使用: アクセス権の付与・取り消し(GRANT/REVOKE)、特定のユーザーが何にアクセスできるかを判断する、行レベルのセキュリティ(細粒度のアクセス制限)と列マスク(データの一部を隠す機能)を設定する、外部のデータ保存場所と保存認証情報を作成する、カタログ・スキーマ・テーブル・ボリューム(データ保管領域)を定義する、「このテーブルを読めるのは誰か」を確認する、監査ログや系統情報、請求関連のシステムテーブルに問い合わせる、または /Volumes/ 内のファイルを操作する。

原文を表示

Unity Catalog governance, access control, and observability. Use to grant or revoke access (GRANT/REVOKE), reason about the privilege model and ownership, set up row-level security and column masks, create external locations and storage credentials, define catalogs/schemas/tables/volumes, answer "who can read this table", and query system tables (audit, lineage, billing) or work with volume files in /Volumes/.

ユースケース
  • アクセス権の付与・取り消しを行う
  • ユーザーのアクセス可能範囲を判断するとき
  • 行レベルのセキュリティを設定するとき
  • データアクセスの監査ログを確認するとき
  • カタログやテーブルを定義するとき
本文(日本語訳)

Unity Catalog

Unity Catalog(データ管理・保護)の ガバナンス(データアクセス管理) に関するガイドです。アクセス制御、権限モデル、外部保存先、セキュリティ機能付きDDL(データ定義言語)、きめ細かいアクセス制御のほか、システムテーブルとボリュームファイル操作をカバーしています。

databricks CLIコマンド実行前に、CLIとサブコマンドが存在することを確認してください。 databricks --version を実行してください。このスキルは統合CLI(≥ v1.0.0)を想定しています。ここに示すいくつかのサブコマンド(experimental aitools、system-schemas、external-lineage、grants)はバージョンやワークスペース環境によって異なります。コマンドが見つからないか、フラグが使えない場合は、推測で別のフラグを試すのではなく、SQL形式またはPython SDKを代わりに使用してください。各リファレンスは関連するバージョン要件を個別に記載しています。

このスキルを使う場面

次のような場合に使用してください:

ガバナンス・アクセス制御(ここから始めましょう):

  • アクセス権の付与・取り消し — GRANT/REVOKE、UC権限モデル、所有権管理(ALTER … OWNER TO)、SHOW GRANTS、「誰がこのテーブルを読み書きできるのか」といった質問への対応
  • 行・列レベルのセキュリティ — 行フィルター、列マスク、current_user() / is_account_group_member() を使った動的ビュー
  • 外部保存先とストレージ認証情報 — CREATE STORAGE CREDENTIAL、CREATE EXTERNAL LOCATION、外部テーブル・ボリュームのバックアップ
  • セキュリティ機能付きDDLとメタデータ — カタログ・スキーマ・管理テーブル・外部テーブル・ビューの作成・変更、コメント、タグ、テーブルプロパティ、所有権管理

監視・ファイル管理:

  • ボリュームの操作(ファイルのアップロード・ダウンロード、/Volumes/ 内のファイル一覧表示)
  • **系統図(テーブル依存関係)**のクエリ、列レベルの系統図の確認
  • 監査ログの分析(誰が何にアクセスしたか、権限変更履歴)
  • 請求・使用状況の監視(DBU(処理単位)消費量、コスト分析)
  • コンピュートリソースの追跡(クラスター使用状況、ウェアハウスメトリクス)
  • ジョブ実行履歴の確認(実行履歴、成功率、失敗情報)
  • クエリ性能の分析(遅いクエリ、ウェアハウス使用率)
  • データ品質のプロファイリング(データプロファイリング、ドリフト検出、メトリクステーブル)

リファレンスファイル

トピック ファイル 説明
アクセス制御 references/1-access-control.md 権限モデル、セキュアな階層構造、GRANT/REVOKE、所有権、権限の継承、SHOW GRANTS
外部保存先 references/2-external-locations.md ストレージ認証情報(AWS/Azure/GCP)、外部保存先、検証
セキュリティ機能付きDDL references/3-securables-ddl.md カタログ・スキーマ・テーブル・ビューの作成・変更・削除、コメント、タグ、所有権
きめ細かいアクセス制御 references/4-fine-grained-access.md 行フィルター、列マスク、動的ビュー
システムテーブル references/5-system-tables.md 系統図、監査、請求、コンピュート、ジョブ、クエリ履歴
ボリューム references/6-volumes.md ボリュームファイル操作、権限管理、ベストプラクティス
データプロファイリング references/7-data-profiling.md データプロファイリング、ドリフト検出、プロファイルメトリクス

クイックスタート

Unity Catalogオブジェクトの作成(CLI)

create コマンドには --json を使用してください。 位置指定引数の順序はコマンドごとに異なり、CLIバージョン間で変わっています。そのため --json を使うと順序に依存しなくなり、バージョンで安定した形式となります。このスキル全体で --json を推奨しています。

# カタログを作成
databricks catalogs create --json '{"name": "my_catalog"}'

# スキーマを作成
databricks schemas create --json '{"name": "my_schema", "catalog_name": "my_catalog"}'

# 管理ボリュームを作成
databricks volumes create --json '{
  "catalog_name": "my_catalog",
  "schema_name": "my_schema",
  "name": "my_volume",
  "volume_type": "MANAGED"
}'

# カタログ・スキーマ・ボリュームをリスト表示(読み取りコマンドは単純な位置指定引数を使う)
databricks catalogs list
databricks schemas list my_catalog
databricks volumes list my_catalog.my_schema

位置指定の create 引数も使えますが、コマンド間で順序が 異なる ため、各コマンドごとの順序は以下のとおりです(このため --json を推奨します):

コマンド 位置指定 create の順序
databricks catalogs create NAME
databricks schemas create NAME CATALOG_NAME
databricks volumes create CATALOG_NAME SCHEMA_NAME NAME VOLUME_TYPE

CLIの仕様はバージョンによって異なります。 databricks サブコマンドや位置指定シグネチャがインストール環境にない場合は、推測でフラグを試すのではなく、--json、SQL形式、またはPython SDKを優先してください。

ボリュームファイル操作(CLI)

databricks fs は UC ボリュームパスでも dbfs: スキームプレフィックスが必要です。なければCLIはそのパスをローカルファイルシステムとして扱い、「ディレクトリなし」というエラーが発生します。

# ボリューム内のファイルをリスト表示
databricks fs ls dbfs:/Volumes/catalog/schema/volume/path/

# ディレクトリの内容をボリュームにアップロード(-r はディレクトリ自体でなく内容をコピー)
databricks fs cp -r --overwrite /tmp/data dbfs:/Volumes/catalog/schema/volume/dest

# ボリュームからファイルをダウンロード
databricks fs cp dbfs:/Volumes/catalog/schema/volume/file.csv /tmp/file.csv

# ボリューム内にディレクトリを作成
databricks fs mkdirs dbfs:/Volumes/catalog/schema/volume/new_folder

アクセス権の付与・取り消し

GRANT/REVOKE はガバナンスの中核操作です。完全な権限モデルは references/1-access-control.md を参照してください。

-- グループにスキーマの読み取り権を付与
GRANT USE CATALOG ON CATALOG analytics TO `data_readers`;
GRANT USE SCHEMA ON SCHEMA analytics.gold TO `data_readers`;
GRANT SELECT ON SCHEMA analytics.gold TO `data_readers`;

-- このテーブルには誰がアクセスできるか?
SHOW GRANTS ON TABLE analytics.gold.customers;

-- 権限を取り消す
REVOKE SELECT ON SCHEMA analytics.gold FROM `data_readers`;

システムテーブルへのアクセスを有効化

-- システムテーブルへのアクセス権を付与
GRANT USE CATALOG ON CATALOG system TO `data_engineers`;
GRANT USE SCHEMA ON SCHEMA system.access TO `data_engineers`;
GRANT SELECT ON SCHEMA system.access TO `data_engineers`;

よく使うクエリ

-- テーブル系統図:このテーブルに入力するテーブルは?
SELECT source_table_full_name, source_column_name
FROM system.access.table_lineage
WHERE target_table_full_name = 'catalog.schema.table'
  AND event_date >= current_date() - 7;

-- 監査:最近の権限変更
SELECT event_time, user_identity.email, action_name, request_params
FROM system.access.audit
WHERE action_name LIKE '%GRANT%' OR action_name LIKE '%REVOKE%'
ORDER BY event_time DESC
LIMIT 100;

-- 請求:ワークスペース別DBU使用量
SELECT workspace_id, sku_name, SUM(usage_quantity) AS total_dbus
FROM system.billing.usage
WHERE usage_date >= current_date() - 30
GROUP BY workspace_id, sku_name;

CLIからのSQL実行

databricks experimental aitools tools query は実験的なコマンドです。 experimental 名前空間はCLIバージョン間で安定保証されておらず、お使いのインストール環境に含まれない可能性があります。システムテーブルのSQLは、SQLウェアハウス(SQLエディタ、スケジュール済みクエリ)、Python SDK(w.statement_execution.execute_statement)、またはノートブックから実行することをお勧めします。実験的CLIは迅速なアドホックチェックにのみ使用してください。

これらの例で使うIDを取得する方法 — WAREHOUSE_ID:databricks warehouses list を実行(またはUIのSQLウェアハウスの接続詳細からコピー)。METASTORE_ID(references/5-system-tables.mdで使用):SDKで w.metastores.current().metastore_id、またはカタログUI → メタストア詳細。

実験的CLI形式(便利さのため):

databricks experimental aitools tools query --warehouse WAREHOUSE_ID "
  SELECT source_table_full_name, target_table_full_name
  FROM system.access.table_lineage
  WHERE event_date >= current_date() - 7
"

安定したSDK代替案(すべてのCLIバージョンで動作):

from databricks.sdk import WorkspaceClient

w = WorkspaceClient()
resp = w.statement_execution.execute_statement(
    warehouse_id="WAREHOUSE_ID",
    statement="""
        SELECT source_table_full_name, target_table_full_name
        FROM system.access.table_lineage
        WHERE event_date >= current_date() - 7
        LIMIT 100
    """,
)
for row in resp.result.data_array or []:
    print(row)

CLIの仕様はバージョンによって異なります。 databricks サブコマンド(実験的ツール、system-schemas、external-lineage など)が見つからない場合は、推測でフラグを試すのではなく、上記のSQL ウェアハウスまたはPython SDKにフォールバックしてください。

ベストプラクティス

  1. 最小限のアクセス権を付与 — 最小権限の原則を適用し、最も狭いセキュアレベルで権限を付与します
  2. 日付でフィルター — システムテーブルは大きいことがあるため、常に日付フィルターを使用します
  3. 適切な保持期間を設定 — ワークスペースの保持設定を確認します
  4. 定期的なレポートをスケジュール — 定期的な監視のため、スケジュール済みクエリを作成します
  5. 実験的CLIより SQL/SDK を優先 — 迅速なチェック以外は、SQL/SDK を使用します

関連スキル

このスキルは Unity Catalog の ガバナンス を担当します:アクセス制御、権限モデル、外部保存先・ストレージ認証情報、セキュリティ機能付きDDL、きめ細かいアクセス制御、システムテーブル、ボリュームです。関連する他の領域については、姉妹スキルを使用してください:

  • databricks-core(親スキル) — 認証、プロファイル選択、汎用CLI、カタログ・テーブルの 情報確認
  • databricks-metric-views — メトリクビュー定義・DDL(WITH METRICS LANGUAGE YAML)
  • databricks-iceberg — 管理 Iceberg、外部 Iceberg 読み込み(旧称 Uniform)、および Iceberg REST カタログ(IRC)認証情報供給 — UC ストレージ認証情報とは異なります(references/2-external-locations.md を参照)
原文(English)を表示

Unity Catalog

Guidance for Unity Catalog governance — access control, the privilege model, external locations, securable DDL, and fine-grained access — plus system tables and volume file operations.

Before running databricks CLI commands, confirm the CLI and the subcommand exist. Run databricks --version — this skill assumes the unified CLI (≥ v1.0.0). Several subcommands shown here (experimental aitools, system-schemas, external-lineage, grants) vary by version or workspace availability; if one is missing or rejects a flag, fall back to the SQL form or the Python SDK rather than guessing. Each reference notes its own version floor where relevant.

When to Use This Skill

Use this skill when:

Governance & access control (start here):

  • Granting or revoking access — GRANT/REVOKE, the UC privilege model, ownership (ALTER … OWNER TO), SHOW GRANTS, "who can read/write this table?"
  • Row- and column-level security — row filters, column masks, dynamic views with current_user() / is_account_group_member()
  • External locations & storage credentials — CREATE STORAGE CREDENTIAL, CREATE EXTERNAL LOCATION, backing external tables/volumes
  • Securable DDL & metadata — creating/altering catalogs, schemas, managed vs external tables, views; comments, tags, table properties, ownership

Observability & files:

  • Working with volumes (upload, download, list files in /Volumes/)
  • Querying lineage (table dependencies, column-level lineage)
  • Analyzing audit logs (who accessed what, permission changes)
  • Monitoring billing and usage (DBU consumption, cost analysis)
  • Tracking compute resources (cluster usage, warehouse metrics)
  • Reviewing job execution (run history, success rates, failures)
  • Analyzing query performance (slow queries, warehouse utilization)
  • Profiling data quality (data profiling, drift detection, metric tables)

Reference Files

Topic File Description
Access Control references/1-access-control.md Privilege model, securable hierarchy, GRANT/REVOKE, ownership, inheritance, SHOW GRANTS
External Locations references/2-external-locations.md Storage credentials (AWS/Azure/GCP), external locations, validation
Securables DDL references/3-securables-ddl.md CREATE/ALTER/DROP catalogs/schemas/tables/views, comments, tags, ownership
Fine-Grained Access references/4-fine-grained-access.md Row filters, column masks, dynamic views
System Tables references/5-system-tables.md Lineage, audit, billing, compute, jobs, query history
Volumes references/6-volumes.md Volume file operations, permissions, best practices
Data Profiling references/7-data-profiling.md Data profiling, drift detection, profile metrics

Quick Start

Create Unity Catalog Objects (CLI)

Use --json for create commands. Positional argument order differs per command and has changed across CLI versions, so --json is the order-independent, version-stable form shown throughout this skill.

# Create a catalog
databricks catalogs create --json '{"name": "my_catalog"}'

# Create a schema
databricks schemas create --json '{"name": "my_schema", "catalog_name": "my_catalog"}'

# Create a managed volume
databricks volumes create --json '{
  "catalog_name": "my_catalog",
  "schema_name": "my_schema",
  "name": "my_volume",
  "volume_type": "MANAGED"
}'

# List catalogs, schemas, volumes (read commands take simple positional args)
databricks catalogs list
databricks schemas list my_catalog
databricks volumes list my_catalog.my_schema

Positional create args still work if you prefer them, but the order is not uniform across commands — this is the per-command order (and the reason --json is recommended):

Command Positional create order
databricks catalogs create NAME
databricks schemas create NAME CATALOG_NAME
databricks volumes create CATALOG_NAME SCHEMA_NAME NAME VOLUME_TYPE

CLI surface varies by version. If a databricks subcommand or positional signature is missing in your install, prefer --json, the SQL form, or the Python SDK rather than guessing flags.

Volume File Operations (CLI)

databricks fs requires the dbfs: scheme prefix even for UC Volume paths — without it the CLI treats the path as local filesystem and errors with no such directory.

# List files in a volume
databricks fs ls dbfs:/Volumes/catalog/schema/volume/path/

# Upload a directory's contents to a volume (-r copies contents, not the directory itself)
databricks fs cp -r --overwrite /tmp/data dbfs:/Volumes/catalog/schema/volume/dest

# Download a file from a volume
databricks fs cp dbfs:/Volumes/catalog/schema/volume/file.csv /tmp/file.csv

# Create a directory in a volume
databricks fs mkdirs dbfs:/Volumes/catalog/schema/volume/new_folder

Grant & Revoke Access

GRANT/REVOKE is the core governance operation. See references/1-access-control.md for the full privilege model.

-- Grant read access on a schema to a group
GRANT USE CATALOG ON CATALOG analytics TO `data_readers`;
GRANT USE SCHEMA ON SCHEMA analytics.gold TO `data_readers`;
GRANT SELECT ON SCHEMA analytics.gold TO `data_readers`;

-- Who can access this table?
SHOW GRANTS ON TABLE analytics.gold.customers;

-- Revoke
REVOKE SELECT ON SCHEMA analytics.gold FROM `data_readers`;

Enable System Tables Access

-- Grant access to system tables
GRANT USE CATALOG ON CATALOG system TO `data_engineers`;
GRANT USE SCHEMA ON SCHEMA system.access TO `data_engineers`;
GRANT SELECT ON SCHEMA system.access TO `data_engineers`;

Common Queries

-- Table lineage: What tables feed into this table?
SELECT source_table_full_name, source_column_name
FROM system.access.table_lineage
WHERE target_table_full_name = 'catalog.schema.table'
  AND event_date >= current_date() - 7;

-- Audit: Recent permission changes
SELECT event_time, user_identity.email, action_name, request_params
FROM system.access.audit
WHERE action_name LIKE '%GRANT%' OR action_name LIKE '%REVOKE%'
ORDER BY event_time DESC
LIMIT 100;

-- Billing: DBU usage by workspace
SELECT workspace_id, sku_name, SUM(usage_quantity) AS total_dbus
FROM system.billing.usage
WHERE usage_date >= current_date() - 30
GROUP BY workspace_id, sku_name;

Running SQL from the CLI

databricks experimental aitools tools query is an experimental command. The experimental namespace is not guaranteed to be stable across CLI versions and may be absent in your install. Prefer running system-table SQL from a SQL warehouse (SQL editor, scheduled query) or the Python SDK (w.statement_execution.execute_statement), or a notebook. Use the experimental CLI only for quick ad-hoc checks.

Getting the IDs these examples use. WAREHOUSE_ID — run databricks warehouses list (or copy it from a SQL warehouse's Connection details in the UI). METASTORE_ID (used in references/5-system-tables.md) — w.metastores.current().metastore_id via the SDK, or the Catalog UI → metastore details.

Experimental CLI form (convenience only):

databricks experimental aitools tools query --warehouse WAREHOUSE_ID "
  SELECT source_table_full_name, target_table_full_name
  FROM system.access.table_lineage
  WHERE event_date >= current_date() - 7
"

Stable SDK fallback (works on any CLI version):

from databricks.sdk import WorkspaceClient

w = WorkspaceClient()
resp = w.statement_execution.execute_statement(
    warehouse_id="WAREHOUSE_ID",
    statement="""
        SELECT source_table_full_name, target_table_full_name
        FROM system.access.table_lineage
        WHERE event_date >= current_date() - 7
        LIMIT 100
    """,
)
for row in resp.result.data_array or []:
    print(row)

CLI surface varies by version. If a databricks subcommand (e.g. an experimental tool, system-schemas, or external-lineage) is missing, fall back to the SQL warehouse or the Python SDK shown above rather than guessing flags.

Best Practices

  1. Grant minimal access - Apply least privilege; grant at the narrowest securable that works
  2. Filter by date - System tables can be large; always use date filters
  3. Use appropriate retention - Check your workspace's retention settings
  4. Schedule reports - Create scheduled queries for regular monitoring
  5. Prefer SQL/SDK over experimental CLI - For anything beyond quick checks

Related Skills

This skill owns Unity Catalog governance: access control, the privilege model, external locations / storage credentials, securable DDL, fine-grained access, system tables, and volumes. For adjacent concerns, use the sibling skill instead:

  • databricks-core (declared parent) — auth, profile selection, generic CLI, and catalog/table exploration
  • databricks-metric-views — metric view definitions / DDL (WITH METRICS LANGUAGE YAML)
  • databricks-iceberg — Managed Iceberg, External Iceberg Reads (fka Uniform), and Iceberg REST Catalog (IRC) credential vending for external engines — distinct from UC storage credentials (see references/2-external-locations.md)
  • databricks-ml-training — UC model registration and @prod/@challenger aliases
  • databricks-vector-search — Vector Search indexes
  • databricks-pipelines, databricks-jobs, databricks-lakeflow-connect — producing tables via pipelines/jobs/managed ingestion
  • databricks-lakebase — Lakebase / synced tables (OLTP)
  • databricks-ai-functions — AI functions such as ai_mask / ai_classify (AI transforms, not access control — see references/4-fine-grained-access.md)
  • databricks-aibi-dashboards — AI/BI dashboards on UC data
  • databricks-synthetic-data-gen — generating data stored in UC volumes

Roadmap (not yet covered — deferred to a later version)

These governance areas are intentionally out of scope for v0.3.0 and planned for later:

  • Delta Sharing / Marketplace / Clean Rooms
  • Lakehouse Federation (connections + foreign catalogs)
  • ABAC / governed tags as policy

Resources

  • Unity Catalog Privileges & Securable Objects
  • Unity Catalog System Tables
  • Audit Log Reference
  • Manage External Locations and Storage Credentials

原文・著作権は Anthropic および各プラグイン作者に帰属します。日本語訳は Claude API による自動翻訳です。