Details
-
Bug
-
Status: Resolved
-
Major
-
Resolution: Fixed
-
2.2.0
-
None
Description
Currently, "USE" permission for users + groups needs to manually mapped by an Ambari Admin for each view instance.
In cases where a view can be auto-configured for a locally managed cluster and we expect that view to be available to that same users that have Cluster Operator or other role access to that cluster, we need to provide an option for Ambari Admins to inherit USE permission on view instances from the cluster permissions. This means:
- Any user or group with different role on the cluster will also get USE access on the view instance.
- This should be available in-addition-to specific view USE permission mapping
- This should be available from Ambari Administration interface and optional set during <auto-create>
- Views like Capacity Scheduler and Tez UI should be adjusted to use this feature for their auto-create instances
Attachments
Attachments
Issue Links
- blocks
-
AMBARI-16246 Allow roles to be treated like principals in Ambari DB
- Resolved
-
AMBARI-16247 Authorizations given to role-based principals must be dereferenced upon user login
- Resolved
- links to