Refer to the exhibit. An administrator is configuring a Unity Catalog access policy to restrict experiment deletion. Given the JSON snippet provided, what is the impact of this policy configuration?
Exhibit
JSON: { "policy": "deny", "actions": ["mlflow:DeleteExperiment"], "effect": "allow" }Trap 1: It denies users the ability to delete experiments.
The 'effect' key is set to 'allow', which explicitly grants permission to perform the listed action. The policy name 'deny' is just a label or description and does not override the operational logic defined within the JSON structure. Therefore, the policy effectively permits the deletion action for authorized users.
Trap 2: It restricts the policy only to the 'mlflow' namespace.
While it references 'mlflow:DeleteExperiment', the policy's primary impact is on the permission to delete experiments, not the namespace itself. The policy effectively authorizes the deletion action within the scope defined by the policy engine, regardless of how the namespace is structured or accessed in the workspace.
Trap 3: The policy is invalid and will be rejected by Databricks.
The JSON syntax is valid for policy definition. While the naming might be confusing, the engine will parse the key-value pairs according to standard policy logic. Therefore, the policy will be accepted and applied, potentially creating unintended access if the administrator did not intend to grant deletion permissions.
- A
It denies users the ability to delete experiments.
Why it fails: The 'effect' key is set to 'allow', which explicitly grants permission to perform the listed action. The policy name 'deny' is just a label or description and does not override the operational logic defined within the JSON structure. Therefore, the policy effectively permits the deletion action for authorized users.
- B
It allows users to delete experiments.
The JSON explicitly lists the 'DeleteExperiment' action and sets the effect to 'allow'. This means any principal attached to this policy will be permitted to delete MLflow experiments. In a production environment, this could be a security risk if not scoped specifically to administrators or lead data scientists.
- C
It restricts the policy only to the 'mlflow' namespace.
Why it fails: While it references 'mlflow:DeleteExperiment', the policy's primary impact is on the permission to delete experiments, not the namespace itself. The policy effectively authorizes the deletion action within the scope defined by the policy engine, regardless of how the namespace is structured or accessed in the workspace.
- D
The policy is invalid and will be rejected by Databricks.
Why it fails: The JSON syntax is valid for policy definition. While the naming might be confusing, the engine will parse the key-value pairs according to standard policy logic. Therefore, the policy will be accepted and applied, potentially creating unintended access if the administrator did not intend to grant deletion permissions.