Does anyone know how access control works to the underlying s3 objects? I didn’t see anything regarding grants in the docs.
I'll see if we can improve the docs or highlight that part better, if it is already documented—we did move some things around prior to release.
For the postgres grants themselves, we provide privs to allow read/write to the remote tables, which is done via granting the `pg_lake_read`, `pg_lake_write` or `pg_lake_read_write` grants. This is a blanket all-or-nothing grant, however, so would need some design work/patching to support per-relation grants, say.
(You could probably get away with making roles in postgres that have the appropriate read/write grant, then only granting those specific roles to a given relation, so it's probably doable though a little clunky at the moment.)