How Twilio secured their multi-engine query platform with AWS Lake Formation
Big Data Blog
This article describes how Twilio secured their multi-engine query platform using AWS Lake Formation for unified access control across multiple AWS accounts and query engines.
- Migrated to AWS Glue Data Catalog as managed metastore for enterprise data mesh architecture
- Implemented AWS Lake Formation Tag-Based Access Control (LF-TBAC) for fine-grained permissions
- Built Odin gateway with unified authentication layer supporting LDAP and future Okta integration
- Created custom authorization layer matching user tags with Lake Formation resource tags
- Automated data sharing workflows using Git, Terraform, and ServiceNow integration
- Reduced authorization overhead to 6-10 milliseconds through strategic caching and ALB target group separation
- Enabled self-service data access provisioning across multiple Lines of Business
Twilio successfully built a scalable governance framework supporting secure cross-account data sharing while maintaining compliance requirements through Lake Formation's tag-based access control and automated provisioning workflows.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
2025
2026
2026
2026
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.