Import Listing

snowform_import_listing imports Snowflake shares from other accounts as databases, and grants IMPORTED PRIVILEGES on them to the roles you list. Every role gets access to every imported database.

Usage

module "shared_databases" {
  source = "github.com/inovex/snowform_import_listing.git?ref=0.0.1"

  snowflake_shares = [
    {
      database_name = "CUSTOMER_LEADS_IMPORTED_DB"
      share_name    = "PROVIDER_ORG.PROVIDER_ACCOUNT.CUSTOMER_LEADS_SHARE"
    },
  ]
  account_roles = ["DATA_ENGINEER_ROLE"]

  providers = {
    snowflake.sysadmin = snowflake.sysadmin
  }
}

Finding the Share Name

Before you can import a share, the provider has to approve your request:

  1. In Snowsight, open Data Products > Private Sharing, find the listing and click Request.

  2. Wait until the request shows Approved under Requests > Outbound.

  3. Run SHOW SHARES;. The share name is <owner_account>.<name> from the result, for example ACME_ORG.XY12345.SALES_DATA_SHARE.

Inputs and Outputs

Name

Description

snowflake_shares (input)

List of { database_name, share_name }. At least one. database_name may only contain uppercase letters, digits and underscores.

account_roles (input)

Roles that get IMPORTED PRIVILEGES on every imported database. At least one.

shared_databases (output)

The snowflake_shared_database resources, keyed by database name.

database_names (output)

List of the imported database names.

granted_privileges (output)

The grant resources, keyed by <database>_<role>.

The module only uses the sysadmin provider, so SYSADMIN owns the imported databases.