Skip to main content

Data Sharing

Gnok enables zero-copy data sharing between accounts. Data stays in the provider's storage -- consumers query shared tables directly through Gnok's access layer without any data replication. Shares operate on Iceberg metadata references, so consumers always see the latest version of the data.

How It Works​

Data sharing uses Iceberg's metadata layer to grant read access to specific tables, views, and functions. The provider creates a share, adds objects to it, and grants access to one or more consumer accounts. Consumers mount the share as a read-only database and query it like any other database in their account.

No data is copied. The consumer's queries read directly from the provider's storage using short-lived, scoped credentials vended at query time.

Share Lifecycle​

The typical workflow for setting up a data share:

  1. Create a share -- the provider creates a named share object.
  2. Add objects -- the provider adds tables, views, or functions to the share.
  3. Grant access -- the provider grants the share to one or more consumer accounts.
  4. Consumer mounts -- the consumer creates a database from the share.
  5. Consumer queries -- the consumer queries shared tables directly.

Creating a Share​

-- Create a new share
CREATE SHARE revenue_share;

-- Create a share with a description
CREATE SHARE revenue_share COMMENT = 'Daily and monthly revenue data for partner reporting';

Adding Objects to a Share​

Shares can include tables, views, and user-defined functions. Each object type provides different levels of data exposure.

Tables​

-- Add a table to the share
ALTER SHARE revenue_share ADD TABLE analytics.daily_revenue;
ALTER SHARE revenue_share ADD TABLE analytics.monthly_summary;

-- Add a table with row-level filtering (consumers see only matching rows)
ALTER SHARE revenue_share ADD TABLE analytics.daily_revenue
WITH FILTER (region = 'US');

-- Add a table with column filtering (consumers see only specified columns)
ALTER SHARE revenue_share ADD TABLE analytics.customers
WITH COLUMNS (customer_id, name, region);

-- Combine row and column filtering
ALTER SHARE revenue_share ADD TABLE analytics.orders
WITH COLUMNS (order_id, order_date, total, region)
WITH FILTER (region IN ('US', 'EU'));

Views​

Sharing views lets you expose computed or aggregated data without revealing the underlying tables:

-- Create a view designed for sharing
CREATE VIEW analytics.partner_revenue_view AS
SELECT region, product_category, SUM(revenue) AS total_revenue, COUNT(*) AS order_count
FROM analytics.daily_revenue
GROUP BY region, product_category;

-- Add the view to the share
ALTER SHARE revenue_share ADD VIEW analytics.partner_revenue_view;

Functions​

Share user-defined functions to let consumers use your computation logic:

ALTER SHARE revenue_share ADD FUNCTION analytics.calculate_margin(DOUBLE, DOUBLE);

Granting Access to Consumers​

-- Grant the share to a specific consumer account
GRANT SHARE revenue_share TO ACCOUNT 'partner-org';

-- Grant to multiple accounts
GRANT SHARE revenue_share TO ACCOUNT 'partner-org';
GRANT SHARE revenue_share TO ACCOUNT 'analytics-vendor';

Access Control​

Row and Column Filtering​

Row filters and column subsets specified when adding objects to a share are enforced at query time. Different consumers can see different subsets of the same table by adding the table multiple times with different filters and granting to different accounts.

Rate Limiting​

Control how frequently consumers can query shared data:

-- Limit a consumer to 1000 queries per hour on this share
ALTER SHARE revenue_share SET RATE_LIMIT = 1000 PER HOUR
FOR ACCOUNT 'partner-org';

Time-Based Access​

Restrict share access to a specific time window:

ALTER SHARE revenue_share SET
VALID_FROM = '2026-01-01'::DATE,
VALID_UNTIL = '2026-12-31'::DATE
FOR ACCOUNT 'partner-org';

Consumer Perspective​

Mounting a Share​

The consumer mounts a share as a read-only database:

-- Mount the share as a local database
CREATE DATABASE partner_data FROM SHARE 'provider-org'.revenue_share;

Querying Shared Data​

Once mounted, shared tables are queried like any other tables:

-- Query a shared table
SELECT * FROM partner_data.daily_revenue
WHERE revenue_date >= '2026-01-01';

-- Join shared data with local data
SELECT
s.region,
s.total_revenue,
l.target_revenue,
s.total_revenue / l.target_revenue AS attainment
FROM partner_data.monthly_summary s
JOIN local_analytics.targets l ON s.region = l.region AND s.month = l.month;

-- Use a shared function
SELECT partner_data.calculate_margin(revenue, cost) AS margin
FROM partner_data.daily_revenue;

Limitations for Consumers​

  • All shared objects are read-only. Consumers cannot insert, update, or delete data in shared tables.
  • Consumers cannot create indexes, materialized views, or other derived objects on shared tables.
  • Shared databases cannot be renamed or cloned.

Audit​

All access to shared data is logged on both the provider and consumer sides. Audit entries include:

FieldDescription
share_nameName of the share
consumer_accountAccount that executed the query
table_nameShared table that was accessed
query_idUnique query identifier
rows_returnedNumber of rows returned to the consumer
timestampWhen the access occurred

Providers can view access logs for their shares:

-- View access history for a specific share
SELECT * FROM TABLE(INFORMATION_SCHEMA.SHARE_ACCESS_HISTORY('revenue_share'))
ORDER BY timestamp DESC
LIMIT 50;

Revocation​

Share access can be revoked at any time. Revocation takes effect immediately -- any in-progress queries from the revoked consumer will fail.

-- Revoke access for a specific consumer
REVOKE SHARE revenue_share FROM ACCOUNT 'partner-org';

After revocation, the consumer's mounted database becomes inaccessible. Queries against it will return an error indicating that share access has been revoked.

Managing Shares​

-- List all shares you have created (provider view)
SHOW SHARES;

-- List all shares granted to your account (consumer view)
SHOW SHARES INBOUND;

-- List grants on a specific share
SHOW GRANTS ON SHARE revenue_share;

-- List objects in a share
SHOW OBJECTS IN SHARE revenue_share;

-- Remove a table from a share
ALTER SHARE revenue_share REMOVE TABLE analytics.monthly_summary;

-- Drop a share (revokes all consumer access)
DROP SHARE revenue_share;

Limitations​

  • Shared data is read-only for consumers. Write access is not supported.
  • Cross-region sharing is not yet available. The provider and consumer must be in the same cloud region.
  • Share metadata updates (adding/removing objects) propagate to consumers within a few seconds but are not instantaneous.
  • Consumers cannot reshare data that was shared with them.

Summary​

Data sharing in Gnok enables secure, zero-copy access to tables, views, and functions across accounts. Providers control what data is exposed through row and column filtering, rate limits, and time-based access windows. Consumers mount shares as read-only databases and query them like local tables. All access is audited, and revocation is immediate.