GCP lineage integration preflight checks

To ensure successful metadata ingestion and lineage generation, complete the following preflight checks.

In your GCP environment

Collibra Data Lineage harvests technical lineage for Google Cloud Platform (GCP) by leveraging the Data Lineage API in GCP. Be sure to review the supported transformation details to determine whether to create technical lineage for GCP or Google BigQuery.

Ensure that your GCP service account used to create a GCP connection has the following roles and permissions depending on your chosen lineage granularity. You can choose to create table-level lineage or column-level lineage for GCP when yousynchronize the capability.

The permissions your GCP service account needs depend on whether you create table-level or column-level lineage:

Lineage type Role or permission Purpose
Table-level Enable the Data Lineage API in GCP

Enables Collibra Data Lineage to retrieve table-level lineage from the selected GCP projects.

For more information, go to Data Lineage API in Google Cloud documentation.

The Data Lineage Viewer role

Grants access table-level lineage
The BigQuery Admin role Grants access to lineage from stored procedures created by you and other GCP users.
The bigquery.jobs.get permission

Enables retrieval of SQL transformation code from BigQuery jobs.

For more information, go to IAM basic and predefined roles reference in the Google Cloud documentation.

Column-level Enable the exportMetadata API, which is in Preview.

Enables export of column-level lineage metadata.

To enable the API , contact Google by following the steps in the article How to Request Access to Google Column Level Lineage (preview) export API.

Create a Google Cloud Storage (GCS) bucket with the following permissions:

  • storage.objects.create (Storage Object Creator)

  • storage.objects.list, storage.objects.get(Storage Object Viewer)
Provides storage for exported column-level lineage metadata, and allows Collibra Data Lineage to write and read the exported files.

One of the following permissions:

  • datacatalog.entries.exportAll (Data Catalog Admin)
  • roles/datacatalog.metadataExporter permission

Grants permission to export column-level lineage metadata.

Note Google currently classifies the datacatalog.entries.exportAll permission as Testing. Permissions at this level may be subject to change or deprecation.
The bigquery.jobs.get permission

Enables retrieval of SQL transformation code from BigQuery jobs.

For more information, go to IAM basic and predefined roles reference in the Google Cloud documentation.

Synchronization The resourcemanager.projects.get permission (optional) Enables automatic discovery of Project IDs during synchronization.

The following permissions:

  • bigquery.jobs.create
  • bigquery.jobs.listAll

Enables SQL code extraction through INFORMATION_SCHEMA queries.

You can set the SQL code extraction method on the synchronization page.

In your Collibra environment

Lineage enablement

Edge

Network and proxy configuration

Collibra permissions

You can connect to Collibra Data Lineage by using the basic or OAuth authentication method. The following permissions are required only if you use the basic authentication method. 

To connect to Collibra Data Lineage service instances via OAuth authentication:

To add an Edge capability:

To synchronize technical lineage: