Configure a Google Cloud Storage Data Connection (Customer-Hosted)
LiveRamp Clean Room’s application layer enables companies to securely connect distributed datasets with full control and flexibility while protecting the privacy of consumers and the rights of data owners.
To configure a customer-hosted Google Cloud Storage (GCS) data connection, see the instructions below.
Note
You can connect GCS to LiveRamp Clean Room using a LiveRamp-hosted GCS instance instead of using your own. For more information, see "Configure a Google Cloud Storage Data Connection (LiveRamp-Hosted)".
Overall Steps
Perform the following overall steps in Google Cloud Platform to configure a customer-hosted GCS data connection:
Once the above steps have been performed in Google Cloud Platform, perform the following overall steps in LiveRamp Clean Room:
For information on performing these steps, see the sections below.
Perform Steps in Google Cloud Platform
Perform the steps in the sections below in Google Cloud Platform to configure a customer-hosted GCS data connection.
Create a Google Service Account
To create a Google service account in Google Cloud Platform:
From the Google Cloud Platform main menu, select IAM & Admin → Service Accounts.
Click
. Save the service account email because you will need it in later steps.Enter a name for the service account.
Click
.Configure roles and additional user access as needed.
Click
.
Create a Google Service Account Key
After you've created a Google service account, create a Google service account key:
From the Google Cloud Platform main menu, select IAM & Admin → Service Accounts.
Select the check box for the service account you created in the previous procedure.
From the More Options menu for the service account's row, select Manage keys.
Click
.For the key type, select JSON and then click CREATE.
The private key will be stored in your Download folder (it will look similar to the following example). Save this for use in the “Add the Credentials in LiveRamp Clean Room” section below.
Grant the Service Account Permissions to Access Bucket Objects
To grant bucket objects permissions to the service account:
Note
If you haven’t already created a bucket, create a bucket by following these Google instructions.
From the Google Cloud Platform main menu, select IAM & Admin → Service Accounts.
Select CREATE ROLE.
Enter a title, description, and ID for the custom role.
Select Add permissions.
Enter "Storage Admin" in the filter.
Add the following permissions:
storage.buckets.get
storage.objects.get
storage.objects.list
Click
.
Assign the Custom Role to the Cloud Storage Service Account
To assign the custom role to the cloud storage service account:
From the Google Cloud Platform console, search for "Cloud Storage".
From the navigation menu, select Buckets.
Click the bucket name for the bucket you want to configure for access.
Select the Permissions tab.
Click
.Select SHOW INFO PANEL in the upper-right corner. The information panel for the bucket displays.
From the information panel, click
.In the Add members field, add the service account.
From the Select a role dropdown, select Custom → role (where "role" is the custom Cloud Storage role you created in the previous procedure).
Click
.Confirm the custom role and service account are now associated with the bucket.
Capture the Data Location
During the process of creating the data connection, you will need to enter the data location in the form of the GCS bucket file path.
From the Google Cloud Platform console, search for "Cloud Storage".
From the navigation menu, select Buckets.
Select the Objects tab.
From the More Options menu (the three dots) in the row for the bucket, select Copy gsutil URL.
Save the bucket file path for use in the “Create the Data Connection” section below.
Perform Steps in LiveRamp Clean Room
Once the above steps have been performed in Google Cloud Platform, perform the overall steps in the sections below in LiveRamp Clean Room.
Add the Credentials in LiveRamp Clean Room
To add credentials:
From the LiveRamp Clean Room navigation pane, select Data Management → Credentials.
Click
.Enter a descriptive name for the credential.
For the Credentials Type, select "Google Service Account".
For the Project ID, enter the project ID.
Enter the Credential JSON you stored in the "Create a Google Service Account Key" procedure above.
Click
.
Create the Data Connection
To create the data connection:
From the LiveRamp Clean Room navigation pane, select Data Management → Data Connections.
From the Data Connections page, click
.From the New Data Connection screen, select "Google Cloud Storage (with SA)".
Select the credentials created in the previous procedure from the list.
Configure the data connection:
Name: Enter a name of your choice.
Category: Enter a category of your choice.
Dataset Type: Select Generic.
File Format: Select CSV.
Note
All files must have a header in the first row. Headers should not have any spaces or special characters and should not exceed 50 characters. An underscore can be used in place of a space.
If you are uploading a CSV file, avoid double quotes in your data (such as "First Name" or "Country").
Quote Character: If you are uploading CSV files, enter the quote character you'll be using (if any).
Field Delimiter: If you are uploading CSV files, select the delimiter to use (comma, semicolon, pipe, or tab).
Data Location: Enter the GCS bucket location captured in the “Capture the Data Location” section above, including the date macro and refresh type. For example, "gs://habu-client-org-123ab456-7d89-10e1-a234-567b891c0123/purchase_events/{yyyy-MM-dd}/incremental" (remove the brackets from the date shown in the example).
Sample File Path: Do not enter anything in this field. We will use the data location specified above to locate the file.
Review the data connection details and click
.All configured data connections can be seen on the Data Connections page.
Upload your data files to your specified location.
When a connection is initially configured, it will show "Verifying Access" as the configuration status. Once the connection is confirmed and the status has changed to "Mapping Required", map the table's fields.
You will receive file processing notifications via email.
Map the Fields
Once the connection is confirmed and the status has changed to "Mapping Required", map the table's fields and add metadata:
From the row for the newly-created data connection, click the More Options menu (the three dots) and then click
.The Map Fields screen opens and the file column names auto-populate.
For any columns that you do not want to be queryable, slide the Include toggle to the left.
If needed, update any column labels.
Note
Ignore the field delimiter fields because this was defined in a previous step.
Click
.The Add Metadata screen opens.
For any column that contains PII data, slide the PII toggle to the right.
Select the data type for each column.
If a column contains PII, slide the User Identifiers toggle to the right and then select the user identifier that defines the PII data.
Click
.
Your data connection configuration is now complete and the status changes to "Completed".