Configuring Kudu's integration with Apache Ranger
Apache Ranger has wider adoption and provides a more comprehensive security features (such as attribute based access control, audit, etc) than Sentry. This topic provides information to configure Kudu with Apache Ranger.
Note
Ranger is often configured with Kerberos authentication.
Sentry integration can not be enabled at the same time with Ranger integration.
After building Kudu from source, find the kudu-subprocess.jar under the build directory, for example build/release/bin.
Note its path, as it is the one to the JAR file containing the Ranger subprocess, which houses the Ranger client that Kudu will use to communicate with the Ranger server.
Use the kudu table list tool to find any table names in the cluster that are not Ranger-compatible, which are names that begin or end with a period (.). Also check that there are no two table names that only differ by case, since authorization is case-insensitive.
For those tables that do not comply with the requirements, use the kudu table rename_table tool to rename the tables.
Create a Ranger client ranger-kudu-security.xml configuration file, and note down the directory containing this file.
<property>
<name>ranger.plugin.kudu.policy.cache.dir</name>
<value>policycache</value>
<description>Directory where Ranger policies are cached after successful retrieval from the Ranger service</description>
</property>
<property>
<name>ranger.plugin.kudu.service.name</name>
<value>kudu</value>
<description>Name of the Ranger service repository storing policies for this Kudu cluster</description>
</property>
<property>
<name>ranger.plugin.kudu.policy.rest.url</name>
<value>http://host:port</value>
<description>Ranger Admin URL</description>
</property>
<property>
<name>ranger.plugin.kudu.policy.source.impl</name>
<value>org.apache.ranger.admin.client.RangerAdminRESTClient</value>
<description>Ranger client implementation to retrieve policies from the Ranger service</description>
</property>
<property>
<name>ranger.plugin.kudu.policy.rest.ssl.config.file</name>
<value>ranger-kudu-policymgr-ssl.xml</value>
<description>Path to the file containing SSL details to connect Ranger Admin</description>
</property>
<property>
<name>ranger.plugin.kudu.policy.pollIntervalMs</name>
<value>30000</value>
<description>Ranger client policy polling interval</description>
</property>
When Secure Socket Layer (SSL) is enabled for Ranger Admin, add the ranger-kudu-policymgr-ssl.xml file to the Ranger client configuration directory with the following configurations:
<property>
<name>xasecure.policymgr.clientssl.keystore</name>
<value>[/path/to/keystore].jks</value>
<description>Java keystore files</description>
</property>
<property>
<name>xasecure.policymgr.clientssl.keystore.credential.file</name>
<value>jceks://file/[path/to/credentials].jceks</value>
<description>Java keystore credential file</description>
</property>
<property>
<name>xasecure.policymgr.clientssl.truststore</name>
<value>[/path/to/truststore].jks</value>
<description>Java truststore file</description>
</property>
<property>
<name>xasecure.policymgr.clientssl.truststore.credential.file</name>
<value>jceks://file/[path/to/credentials].jceks</value>
<description>Java truststore credential file</description>
</property>
Set the following configurations on the Kudu master:
<property>
<name>policy.download.auth.users</name>
<value>kudu</value>
</property>
Parent topic: Fine-grained authorization