Uploaded image for project: 'Apache Ozone'
  1. Apache Ozone
  2. HDDS-4944 Multi-Tenant Support in Ozone
  3. HDDS-6576

[Multi-Tenant] Update documentation around Ranger policy creation on bucket sharing

    XMLWordPrintableJSON

Details

    • Sub-task
    • Status: Resolved
    • Major
    • Resolution: Fixed
    • None
    • HDDS-4944
    • None

    Description

      If a cluster admin or tenant admin wants the bucket owner (who is a regular tenant user without superuser privileges) to be able to edit their own bucket's policy, an admin needs to manually create a new Ozone policy in Ranger for that bucket, explicitly granting the bucket owner ALL permission on the bucket and making the bucket owner a "delegated admin" for that policy. (Note: the flexible OWNER tag cannot be used in this policy.)
      With this new policy, as long as the bucket owner can log in to the Ranger Web UI, he/she could edit this bucket policy on his own, for example, to share the bucket with others without an admin's manual intervention.

      We are not providing a dedicated multi-tenancy CLI for that.

      CC ppogde

      Attachments

        Issue Links

          Activity

            People

              smeng Siyao Meng
              smeng Siyao Meng
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: