Executing the Sample Script
Execute the Python Iceberg Protector Sample Script on Snowflake.
This product is currently in Tech Preview and is not available for General Availability (GA). It should not be used in production environments, as features and functionality may change before the final GA release.
./PyIcebergProtector-Snowflake-Configurator_Linux-ALL-64_x86-64_Snowflake-SPCS-Python-3.12_<Protector_version>.sh
Prerequisites:
1. Snowflake CLI installed.
2. A Snowflake CLI connection configured with either:
a. key-pair authentication
b. external-browser authentication
3. An encrypted static policy exported from ESA as rps.json.
4. The private key matching the public key used for the ESA static policy export.
5. Docker installed and running.
6. openssl, zip, and unzip utilities installed.
Are these prerequisites met? ("yes" or "no"):
yes.Specify ESA-exported static policy's absolute path (example: /tmp/rps.json):
Specify ESA static policy decryption private key's absolute path (example: /tmp/private_key.pem):
Specify Snowflake CLI connection (default: protegrity_keypair):
Specify browser command if the connection uses external-browser authentication (optional):
Specify Snowflake image registry (example: account.registry.snowflakecomputing.com):
Specify Snowflake image repository (example: database/schema/repository):
Specify image tag:
Preparing Snowflake image with an ESA static policy...
Login Succeeded
[+] Building 5.0s (16/16) FINISHED
docker:default
=> [internal] load build definition from Dockerfile 0.0s
=> => transferring dockerfile: 1.89kB 0.0s
=> [internal] load metadata for protegritypartner-aws-bigdata.registry.snowflakecomputing.com/snowflake/images/snowflake_images/container_runtime/cpu_x86_64:2.8.1-py312 0.0s
=> [internal] load .dockerignore 0.0s
=> => transferring context: 2B 0.0s
=> CACHED [ 1/11] FROM protegritypartner-aws-bigdata.registry.snowflakecomputing.com/snowflake/images/snowflake_images/container_runtime/cpu_x86_64:2.8.1-py312 0.0s
=> [internal] load build context 0.6s
=> => transferring context: 64.26MB 0.6s
=> [ 2/11] COPY pyiceberg-0.11.0-cp312-cp312-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl /tmp/wheels/ 0.1s
=> [ 3/11] COPY pyarrow-24.0.0+g090aba87f-cp312-cp312-manylinux_2_28_x86_64.whl /tmp/wheels/ 0.1s
=> [ 4/11] RUN uv pip install --system --break-system-packages --no-deps /tmp/wheels/pyiceberg-0.11.0-cp312-cp312-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl /t 3.0s
=> [ 5/11] COPY csdk.tgz /tmp/csdk.tgz 0.0s
=> [ 6/11] RUN mkdir --parents /opt/protegrity/sdk/c && tar --extract --file /tmp/csdk.tgz --gzip --directory /opt/protegrity/sdk/c && rm --force /tmp/csdk.tgz 0.3s
=> [ 7/11] COPY libs/ /opt/protegrity/libs/ 0.1s
=> [ 8/11] COPY libstaticPolicyDecryptionProgram.so /opt/protegrity/sdk/c/lib/libstaticPolicyDecryptionProgram.so 0.0s
=> [ 9/11] COPY private_key.pem /opt/protegrity/sdk/c/lib/static_policy_decryption_key.key 0.0s
=> [10/11] COPY rps.json /opt/protegrity/sdk/c/data/policy.json 0.0s
=> [11/11] RUN cp /opt/protegrity/sdk/c/lib/xcpep.plm /opt/protegrity/sdk/c/lib/libxcpep.so && sed --in-place 's/\[protector\]/[protector]\nuser = root/' /opt/protegrity/sdk/c/data/config.ini && 0.2s
=> exporting to image 0.5s
=> => exporting layers 0.4s
=> => writing image sha256:75186efe31540a3c5ca82ed61d784f7f6209c450e515c93b270e7db1bbc44fbe 0.0s
=> => naming to docker.io/library/pyiceberg-protector:v1 0.0s
The push refers to repository [protegritypartner-aws-bigdata.registry.snowflakecomputing.com/iceberg_tutorial_db/public/pyiceberg_images/pyiceberg-protector]
42ed636049e4: Pushed
8ff292ef175c: Pushed
b3e78f588f4c: Pushed
64a4292cd305: Pushed
69d3f57f53d9: Pushed
14e602bb9494: Pushed
77fe202deebe: Pushed
9705eb8ab870: Pushed
f2991fa3f517: Pushed
5f4af0ec4ca3: Pushed
v1: digest: sha256:5ca92074258c5f35a42841c32b3278cc020a54b0710c8c63d5c8377b69a212e5 size: 8485
Pushed Snowflake image: protegritypartner-aws-bigdata.registry.snowflakecomputing.com/iceberg_tutorial_db/public/pyiceberg_images/pyiceberg-protector:v1
Next steps:
1. Create a Snowflake custom runtime environment for this image.
Use this image path: /iceberg_tutorial_db/public/pyiceberg_images/pyiceberg-protector:v50
-- CUSTOM RUNTIME ENVIRONMENT
CREATE OR REPLACE CUSTOM RUNTIME ENVIRONMENT <name>
IMAGE_PATH = '<path>'
BASE_IMAGE_TYPE = CPU;
2. Configure the Snowflake service that runs your notebook to use this custom image.
3. Run the following sample from a Snowflake notebook attached to that service:
# %% [CELL 1] -- Install/imports
# The notebook must run on a service that uses the custom image created above.
# %% [CELL 2] -- Config
ACCOUNT_URL = "https://<account_identifier>.snowflakecomputing.com"
ROLE = "<snowflake_role>"
DATABASE = "<database_name>"
TABLE_NAME = "<schema_name>.<table_name>"
PAT = open("/secrets/<database_name>/<schema_name>/<secret_name>/secret_string").read().strip()
if not PAT:
raise RuntimeError("Set PAT with a Snowflake secret mounted in the notebook service.")
print("Config OK.")
Note: The complete script will be displayed in the logs.
Execute the Python Iceberg Protector Sample Script on Snowflake.
Was this page helpful?