This product is currently in Tech Preview and is not available for General Availability (GA). It should not be used in production environments, as features and functionality may change before the final GA release.

Installing the Protector

Install the Python Iceberg Protector on Snowflake.
  1. Log in to the Linux instance.
  2. Navigate to the directory where the installation files are available.
  3. To install the protector, run the following command:
    ./PyIcebergProtector-Snowflake-Configurator_Linux-ALL-64_x86-64_Snowflake-SPCS-Python-3.12_<Protector_version>.sh
    
  4. Press ENTER. The prompt to confirm the prerequisites appears.
     Prerequisites:
     1. Snowflake CLI installed.
     2. A Snowflake CLI connection configured with either:
         a. key-pair authentication
         b. external-browser authentication
     3. An encrypted static policy exported from ESA as rps.json.
     4. The private key matching the public key used for the ESA static policy export.
     5. Docker installed and running.
     6. openssl, zip, and unzip utilities installed.
     Are these prerequisites met? ("yes" or "no"):
    
  5. To confirm the availability of prerequisites, type yes.
  6. Press ENTER. The prompt to enter the absolute path of the policy appears.
    Specify ESA-exported static policy's absolute path (example: /tmp/rps.json):
    
  7. Enter the absolute path of the policy.
  8. Press ENTER. The prompt to enter the absolute path for the policy decryption key appears.
    Specify ESA static policy decryption private key's absolute path (example: /tmp/private_key.pem):
    
  9. Enter the static policy decryption private key’s absolute path.
  10. Press ENTER. The prompt to enter the Snowflake CLI connection appears.
    Specify Snowflake CLI connection (default: protegrity_keypair):
    
  11. Enter the Snowflake CLI connection details.
  12. Press ENTER. The prompt to enter the browser command if the connection uses external-browser authentication appears.
    Specify browser command if the connection uses external-browser authentication (optional):
    
  13. Enter the browser command if the connection uses external-browser authentication.
  14. Press ENTER. The prompt to enter the Snowflake image registry appears.
    Specify Snowflake image registry (example: account.registry.snowflakecomputing.com):
    
  15. Enter the Snowflake image registry path.
  16. Press ENTER. The prompt to enter the Snowflake image repository appears.
    Specify Snowflake image repository (example: database/schema/repository):
    
  17. Enter the Snowflake image repository path.
  18. Press ENTER. The prompt to enter the image tag appears.
    Specify image tag:
    
  19. Enter the image tag.
  20. Press ENTER. The script completes the installation.
    Preparing Snowflake image with an ESA static policy...
    Login Succeeded
    [+] Building 5.0s (16/16) FINISHED
    docker:default
    => [internal] load build definition from Dockerfile 0.0s
    => => transferring dockerfile: 1.89kB  0.0s
    => [internal] load metadata for protegritypartner-aws-bigdata.registry.snowflakecomputing.com/snowflake/images/snowflake_images/container_runtime/cpu_x86_64:2.8.1-py312         0.0s
    => [internal] load .dockerignore                                  0.0s
    => => transferring context: 2B                                    0.0s
    => CACHED [ 1/11] FROM protegritypartner-aws-bigdata.registry.snowflakecomputing.com/snowflake/images/snowflake_images/container_runtime/cpu_x86_64:2.8.1-py312         0.0s
    => [internal] load build context                                  0.6s
    => => transferring context: 64.26MB                               0.6s
    => [ 2/11] COPY pyiceberg-0.11.0-cp312-cp312-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl /tmp/wheels/                                                  0.1s
    => [ 3/11] COPY pyarrow-24.0.0+g090aba87f-cp312-cp312-manylinux_2_28_x86_64.whl /tmp/wheels/    0.1s
    => [ 4/11] RUN uv pip install --system --break-system-packages --no-deps         /tmp/wheels/pyiceberg-0.11.0-cp312-cp312-manylinux2014_x86_64.manylinux_2_17_x86_64.manylinux_2_28_x86_64.whl         /t  3.0s
    => [ 5/11] COPY csdk.tgz /tmp/csdk.tgz                             0.0s
    => [ 6/11] RUN mkdir --parents /opt/protegrity/sdk/c &&     tar --extract --file /tmp/csdk.tgz --gzip --directory /opt/protegrity/sdk/c &&     rm --force /tmp/csdk.tgz  0.3s
    => [ 7/11] COPY libs/ /opt/protegrity/libs/                        0.1s
    => [ 8/11] COPY libstaticPolicyDecryptionProgram.so /opt/protegrity/sdk/c/lib/libstaticPolicyDecryptionProgram.so                                                                 0.0s
    => [ 9/11] COPY private_key.pem /opt/protegrity/sdk/c/lib/static_policy_decryption_key.key                                                                0.0s
    => [10/11] COPY rps.json /opt/protegrity/sdk/c/data/policy.json                                                               0.0s
    => [11/11] RUN cp /opt/protegrity/sdk/c/lib/xcpep.plm /opt/protegrity/sdk/c/lib/libxcpep.so &&     sed --in-place 's/\[protector\]/[protector]\nuser = root/' /opt/protegrity/sdk/c/data/config.ini &&     0.2s
    => exporting to image                                               0.5s
    => => exporting layers                                              0.4s
    => => writing image sha256:75186efe31540a3c5ca82ed61d784f7f6209c450e515c93b270e7db1bbc44fbe     0.0s
    => => naming to docker.io/library/pyiceberg-protector:v1            0.0s
    The push refers to repository [protegritypartner-aws-bigdata.registry.snowflakecomputing.com/iceberg_tutorial_db/public/pyiceberg_images/pyiceberg-protector]
    42ed636049e4: Pushed
    8ff292ef175c: Pushed
    b3e78f588f4c: Pushed
    64a4292cd305: Pushed
    69d3f57f53d9: Pushed
    14e602bb9494: Pushed
    77fe202deebe: Pushed
    9705eb8ab870: Pushed
    f2991fa3f517: Pushed
    5f4af0ec4ca3: Pushed
    v1: digest: sha256:5ca92074258c5f35a42841c32b3278cc020a54b0710c8c63d5c8377b69a212e5 size: 8485
    Pushed Snowflake image: protegritypartner-aws-bigdata.registry.snowflakecomputing.com/iceberg_tutorial_db/public/pyiceberg_images/pyiceberg-protector:v1
    
    Next steps:
    1. Create a Snowflake custom runtime environment for this image.
       Use this image path: /iceberg_tutorial_db/public/pyiceberg_images/pyiceberg-protector:v50
    
    -- CUSTOM RUNTIME ENVIRONMENT
    CREATE OR REPLACE CUSTOM RUNTIME ENVIRONMENT <name>
            IMAGE_PATH = '<path>'
            BASE_IMAGE_TYPE = CPU;
    
    2. Configure the Snowflake service that runs your notebook to use this custom image.
    
    3. Run the following sample from a Snowflake notebook attached to that service:
    
    # %% [CELL 1] -- Install/imports
    # The notebook must run on a service that uses the custom image created above.
    
    # %% [CELL 2] -- Config
    ACCOUNT_URL = "https://<account_identifier>.snowflakecomputing.com"
    ROLE = "<snowflake_role>"
    DATABASE = "<database_name>"
    TABLE_NAME = "<schema_name>.<table_name>"
    PAT = open("/secrets/<database_name>/<schema_name>/<secret_name>/secret_string").read().strip()
    if not PAT:
            raise RuntimeError("Set PAT with a Snowflake secret mounted in the notebook service.")
    print("Config OK.")
    

    Note: The complete script will be displayed in the logs.


Executing the Sample Script

Execute the Python Iceberg Protector Sample Script on Snowflake.

Last modified : September 17, 2026