HetuEngine Ranger-based Permission Control
By default, Ranger authentication is used for newly installed clusters. For clusters upgraded from earlier versions or clusters where Ranger authentication is manually disabled, you can enable Ranger authentication again by referring to Enabling Ranger Authentication. For a cluster with Ranger authentication enabled, cluster administrators can use Ranger to configure the permissions to manage databases, tables, and columns of data sources for HetuEngine users. For details, see Adding a Ranger Access Permission Policy for HetuEngine.
Enabling Ranger Authentication
- Log in to FusionInsight Manager.
- If Kerberos authentication is disabled for the cluster (the cluster is in normal mode), add the ranger.usersync.sync.source parameter. If Kerberos authentication is enabled for the cluster (the cluster is in security mode), skip this step.
- Choose Cluster > Services > Ranger. Click Configurations then All Configurations.
- Search for the ranger.usersync.config.expandor parameter, set its name to ranger.usersync.sync.source, set its value to ldap, and save the settings.
- On the Dashboard page, click More > Restart Service in the upper right corner, enter the password, and restart Ranger.
- Choose Cluster > Services > HetuEngine > More > Enable Ranger.
- Choose Cluster > Services > HetuEngine > More > Restart Service.
- Restart the compute instance on HSConsole. For details, see Managing HetuEngine Compute Instances.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot