Ranger Admin 의 기본 포트는 HTTP 6080, HTTPS 6182 다. 정책 관련 API 는 /service/public/v2/api/ 아래에 있다.
| 목적 | 메서드와 경로 |
|---|---|
| 정책 목록 조회 | GET /service/public/v2/api/policy |
| 서비스별 정책 조회 | GET /service/public/v2/api/service/{service-name}/policy |
| 정책 생성 | POST /service/public/v2/api/policy |
| 정책 수정 | PUT /service/public/v2/api/policy/{id} |
| 정책 삭제 | DELETE /service/public/v2/api/policy/{id} |
| 전체 내보내기 | GET /service/plugins/policies/exportJson?serviceName={name} |
| 전체 들여오기 | POST /service/plugins/policies/importPoliciesFromFile |
RANGER=https://ranger-host:6182
SVC=cm_hive
curl -sk -u "${RANGER_USER}:${RANGER_PASSWORD}" \
"${RANGER}/service/public/v2/api/service/${SVC}/policy" \
-o policies_${SVC}.json
curl -sk -u "${RANGER_USER}:${RANGER_PASSWORD}" \
"${RANGER}/service/plugins/policies/exportJson?serviceName=${SVC}&checkPoliciesExists=false" \
-o export_${SVC}.json
exportJson 쪽 결과는 들여오기 API 가 그대로 받는 형식이라 백업·이관에 쓴다. public/v2 쪽은 정책 객체 배열이라 스크립트로 가공하기 쉽다.
curl -sk -u "${RANGER_USER}:${RANGER_PASSWORD}" \
-X POST "${RANGER}/service/public/v2/api/policy" \
-H "Content-Type: application/json" \
-d @policy.json
같은 이름의 정책이 이미 있으면 실패한다. 갱신하려면 정책 ID 를 찾아 PUT 을 쓴다.
ID=$(curl -sk -u "${RANGER_USER}:${RANGER_PASSWORD}" \
"${RANGER}/service/public/v2/api/service/${SVC}/policy" \
| jq -r '.[] | select(.name=="my_policy") | .id')
curl -sk -u "${RANGER_USER}:${RANGER_PASSWORD}" \
-X PUT "${RANGER}/service/public/v2/api/policy/${ID}" \
-H "Content-Type: application/json" -d @policy.json
curl -sk -u "${RANGER_USER}:${RANGER_PASSWORD}" \
-X POST "${RANGER}/service/plugins/policies/importPoliciesFromFile?isOverride=true" \
-H "Content-Type: multipart/form-data" \
-F "file=@export_${SVC}.json"
서비스 이름이 원본과 다른 클러스터로 옮길 때는 이름 매핑 파일을 함께 올린다. 매핑 없이 넣으면 존재하지 않는 서비스를 참조해 실패한다.
-F "servicesMapJson=@service_map.json"
{ "cm_hive_src": "cm_hive_dst", "cm_hdfs_src": "cm_hdfs_dst" }
#!/bin/bash
set -euo pipefail
RANGER="${RANGER:-https://ranger-host:6182}"
SVC="${1:?service name}"
FILE="${2:?policy json}"
[ -f "$FILE" ] || { echo "no such file: $FILE" >&2; exit 1; }
code=$(curl -sk -u "${RANGER_USER}:${RANGER_PASSWORD}" \
-o /tmp/ranger_resp.json -w '%{http_code}' \
-X POST "${RANGER}/service/public/v2/api/policy" \
-H "Content-Type: application/json" -d @"$FILE")
case "$code" in
200|201) echo "imported: $FILE" ;;
*) echo "failed (${code})" >&2; cat /tmp/ranger_resp.json >&2; exit 1 ;;
esac
자격 증명은 인자나 스크립트 안에 두지 말고 환경 변수로 주입한다. 명령행에 적으면 프로세스 목록과 셸 이력에 남는다.
Ranger Admin 이 Kerberos(SPNEGO)로 보호돼 있으면 기본 인증 대신 티켓을 쓴다.
kinit -kt /path/to/rangeradmin.keytab rangeradmin@REALM
curl -sk --negotiate -u : "${RANGER}/service/public/v2/api/policy"
Ranger 는 플러그인이 쓰는 비밀번호(LDAP 바인드 등)를 자바 키스토어에 넣어 두는 도구를 함께 제공한다. cred.jceks 같은 파일을 만드는 유틸리티이며, 배포판에 따라 클래스 경로와 실행 방식이 다르다.
find /opt/cloudera/parcels -name "ranger*credential*jar" 2>/dev/null
find /opt/cloudera/parcels -name "ranger*plugin*install*" 2>/dev/null
Cloudera 배포판에서는 플러그인 설치 스크립트가 이 과정을 대신 수행하므로 직접 호출할 일이 거의 없다. 클래스 이름으로 직접 실행하려다 찾지 못하는 경우, 대부분 해당 배포판이 그 경로를 노출하지 않기 때문이다. (확인 필요 — 직접 실행이 필요하면 설치된 배포판의 문서를 확인한다.)
isOverride=true 로 들여오면 대상 서비스의 기존 정책이 지워진다. 실행 전에 반드시 현재 상태를 내보내 둔다.