---
title: "Backstage with Lakebase, part 2"
description: "Part 2 shows how moving Backstage’s operational Postgres database to Databricks Lakebase brings security, auditing, masking, and cost controls under Unity Catalog. The proof of concept used Lakehouse Federation to expose the catalog as the lakebase_bs foreign catalog, replacing cross-service RDS investigations with Unity Catalog grants and system.access.audit records. Audit events identify OAuth users and source IPs, while billing attributed 31.6130 DBU to production and 0.0107 DBU to a dropped test branch. Branch-level attribute masking propagates automatically to feature, CI, and QA copies, while the post cites a Perforce report stating that 60% of organizations experienced breaches or theft in non-production environments. It also introduces LakebaseOps, with three agents and seven scheduled jobs, and Lakebase MCP, exposing 46 governed tools across four profiles, so DBAs can design policies and workflows instead of handling repetitive provisioning."
---

# Backstage with Lakebase, part 2

[Databricks](https://yomu.fyi/company/databricks) · Cameron Casher, Kevin Hartman, Surya Sai Turaga · May 15, 2026

**Type:** Explainer

## Summary

Part 2 shows how moving Backstage’s operational Postgres database to Databricks Lakebase brings security, auditing, masking, and cost controls under Unity Catalog. The proof of concept used Lakehouse Federation to expose the catalog as the lakebase\_bs foreign catalog, replacing cross-service RDS investigations with Unity Catalog grants and system.access.audit records. Audit events identify OAuth users and source IPs, while billing attributed 31.6130 DBU to production and 0.0107 DBU to a dropped test branch. Branch-level attribute masking propagates automatically to feature, CI, and QA copies, while the post cites a Perforce report stating that 60% of organizations experienced breaches or theft in non-production environments. It also introduces LakebaseOps, with three agents and seven scheduled jobs, and Lakebase MCP, exposing 46 governed tools across four profiles, so DBAs can design policies and workflows instead of handling repetitive provisioning.

## Context

Backstage’s operational database and the data lake traditionally use separate security paradigms, requiring multiple services, query languages, and access policies to investigate activity. Frequent development branching can also create many copies of production data containing sensitive fields, making manual masking and provisioning difficult to scale.

## Approach / What changed

The proof of concept placed Backstage on Databricks Lakebase, exposed its catalog through Lakehouse Federation in Unity Catalog, and used Unity Catalog grants, audit records, branch-level masking, and system billing tables for governance. It also presented LakebaseOps and Lakebase MCP as governed tools for automation and DBA workflows.

## Takeaways

- Lakehouse Federation exposed the Backstage catalog as the lakebase\_bs foreign catalog, enabling Unity Catalog grants instead of Postgres-level role management.
- Lakebase audit and billing data recorded branch activity and attributed 31.6130 DBU to production versus 0.0107 DBU to a dropped test branch.
- Unity Catalog attribute-level masking propagates to new Lakebase branches, and Lakebase MCP provides 46 tools controlled by four access profiles.

**Tags:** [Lakebase](https://yomu.fyi/topic/lakebase), [Postgres](https://yomu.fyi/topic/postgres), [Unity Catalog](https://yomu.fyi/topic/unity-catalog)

- Source: [Databricks](https://www.databricks.com/blog/backstage-lakebase-part-2)
- Source URL: https://www.databricks.com/blog/backstage-lakebase-part-2
- Ingested by Yomu: 2026-08-31T03:34:30.890Z

[Read original post](https://www.databricks.com/blog/backstage-lakebase-part-2)
