---
title: Charmhub | Deploy DataHub using Charmhub - The Open Operator Collection
description: Deploy the latest version of DataHub as a Kubernetes Operator on any
  cloud.
url: https://charmhub.io/datahub-k8s/libraries/datahub_client
---

# DataHub

[Business Data](https://charmhub.io/publisher/businessdata "View all packages from Business Data")

* [Business Data](https://charmhub.io/publisher/businessdata "View all packages from Business Data")

Platform:

stable 1efadd36

```
juju deploy datahub-k8s
```

[Learn to deploy on juju >](https://juju.is/docs/juju/manage-applications)

[Toggle side navigation](https://charmhub.io/datahub-k8s/libraries/datahub_client#drawer)

## charms.datahub\_k8s.v0.datahub\_client

* [*Docstrings*Docstrings](https://charmhub.io/datahub-k8s/libraries/datahub_client)
  [*Code*Source code](https://charmhub.io/datahub-k8s/libraries/datahub_client/source-code)
* + Download

    Fetch library

    ```
    charmcraft fetch-lib charms.datahub_k8s.v0.datahub_client
    ```

    [Download datahub\_client.py](https://charmhub.io/datahub-k8s/libraries/datahub_client/download)
  + *Last updated* 11 Aug 2026
  + *Revision* Library version 0.2

Library for the datahub\_client relation.

This library provides the DatahubClientProvider and DatahubClientRequirer classes that
handle the provider and the requirer sides of the datahub\_client interface.

The interface lets a charm consume the DataHub GMS API as a dedicated DataHub service
account. The provider (datahub-k8s) creates the service account, mints a Personal
Access Token for it, stores the token in a Juju secret granted to the relation, and
publishes the GMS URL alongside the secret ID. The requirer reads both and configures
its workload.

Provider application databag (every field is a string):

```
gms-url               URL of the GMS API, reachable from the requirer.
                      "http://datahub-k8s.datahub-k8s.svc.cluster.local:8080"
secret-id             ID of a Juju secret whose `token` key holds the PAT.
                      "secret://3a214b83-9add-45e4-83af-665104bec574/akrgmperhr88jppn48ug"
service-account-urn   URN of the DataHub service account the token acts as.
                      "urn:li:corpuser:service_cb8b10ee-6bb0-4db6-9fc3-337eb588cc2c"
```

Token lifetime: the PAT does not expire and is not rotated on a schedule. It is
tied to the service account, so removing the relation deletes the account and
invalidates the token with it. The provider also re-mints a token whenever the
service account it belongs to is gone, which is what makes revoking an account
in DataHub a working way to force a new one.

---

Index

* [class DatahubConnection](https://charmhub.io/datahub-k8s/libraries/datahub_client#datahubconnection)
* [class DatahubClientProvider](https://charmhub.io/datahub-k8s/libraries/datahub_client#datahubclientprovider)
* + [def \_\_init\_\_(
    self,
    charm,
    relation\_name)](https://charmhub.io/datahub-k8s/libraries/datahub_client#datahubclientprovider-__init__)
* + [def get\_service\_account\_urn(
    self,
    relation)](https://charmhub.io/datahub-k8s/libraries/datahub_client#datahubclientprovider-get_service_account_urn)
* + [def get\_secret\_id(
    self,
    relation)](https://charmhub.io/datahub-k8s/libraries/datahub_client#datahubclientprovider-get_secret_id)
* + [def publish\_connection(
    self,
    relation,
    gms\_url,
    secret\_id,
    service\_account\_urn)](https://charmhub.io/datahub-k8s/libraries/datahub_client#datahubclientprovider-publish_connection)
* [class DatahubClientRequirer](https://charmhub.io/datahub-k8s/libraries/datahub_client#datahubclientrequirer)
* + [def \_\_init\_\_(
    self,
    charm,
    relation\_name)](https://charmhub.io/datahub-k8s/libraries/datahub_client#datahubclientrequirer-__init__)
* + [def is\_related(
    self)](https://charmhub.io/datahub-k8s/libraries/datahub_client#datahubclientrequirer-is_related)
* + [def get\_connection(
    self)](https://charmhub.io/datahub-k8s/libraries/datahub_client#datahubclientrequirer-get_connection)

#### class DatahubConnection

Everything a requirer needs to talk to DataHub GMS.

Attributes

gms\_url

URL of the GMS API.

token

DataHub Personal Access Token to authenticate with.

service\_account\_urn

URN of the service account the token acts as.

#### class DatahubClientProvider

Provider side of the datahub\_client relation.

Description

The library owns the databag layout; the charm owns the DataHub-side
resources (service account, access token) and the Juju secret.

Methods

DatahubClientProvider.
\_\_init\_\_(

*self*

,
charm: CharmBase

,
relation\_name: str
)

Construct.

Arguments

charm

The charm instance.

relation\_name

Name of the relation.

DatahubClientProvider.
get\_service\_account\_urn(

*self*

,
relation: Relation
)

Return the service account URN previously published on a relation.

Arguments

relation

The relation to read.

Returns

The URN, or None if nothing has been published yet.

DatahubClientProvider.
get\_secret\_id(

*self*

,
relation: Relation
)

Return the token secret ID previously published on a relation.

Arguments

relation

The relation to read.

Returns

The Juju secret ID, or None if nothing has been published yet.

DatahubClientProvider.
publish\_connection(

*self*

,
relation: Relation

,
gms\_url: str

,
secret\_id: str

,
service\_account\_urn: str
)

Publish the connection details on a relation.

Arguments

relation

The relation to update.

gms\_url

URL of the GMS API reachable from the requirer.

secret\_id

ID of the Juju secret holding the access token.

service\_account\_urn

URN of the DataHub service account.

#### class DatahubClientRequirer

Description

Requirer side of the datahub\_client relation. None

Methods

DatahubClientRequirer.
\_\_init\_\_(

*self*

,
charm: CharmBase

,
relation\_name: str
)

Construct.

Arguments

charm

The charm instance.

relation\_name

Name of the relation.

DatahubClientRequirer.
is\_related(

*self*
)

Description

Return whether the relation currently exists. None

DatahubClientRequirer.
get\_connection(

*self*
)

Return the current DataHub connection details.

Returns

A DatahubConnection, or None while the provider has not published
complete details or the token secret is not readable yet.
