Skip to main content
Starburst access management is currently only supported with the Polaris catalog. RBAC is defined and enforced at the catalog level in Polaris - Starburst acts as a query engine that forwards user identity, while Polaris evaluates the access policies.

Setup

Starburst supports per-user identity forwarding to the Iceberg REST catalog via OAuth2 passthrough (see Starburst OAuth2 passthrough docs). Two configuration files need to be updated. First, enable delegated OAuth2 authentication in config.properties:
Then configure the Polaris catalog properties file: