Uploaded image for project: 'Oozie'
  1. Oozie
  2. OOZIE-3196

Authorization: restrict world readability by user

Add voteVotersWatch issueWatchersCreate sub-taskLinkCloneUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • New Feature
    • Status: Patch Available
    • Major
    • Resolution: Unresolved
    • 5.0.0b1, 5.0.0
    • 5.3.0
    • bundle, coordinator, workflow
    • None

    Description

      The current authorization model does not fit the enterprise requirements as everything is readable and writable by everyone by default.

      Write access can be restricted using authorization but restricting read rights is only possible via Yarn ACLs and HDFS rights which still does not prevent accessing the workflow, coordinator or bundle job’s configurations for everyone.

      Improve authorization so it’s possible to configure read/write access for workflows, coordinators, and bundles in a more granular way. Could involve Sentry during implementation or create and design a new system that fits the needs.

      Attachments

        1. OOZIE-3196.001.patch
          56 kB
          Peter Orova

        Issue Links

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            matijhs Mate Juhasz
            andras.piros Andras Piros

            Dates

              Created:
              Updated:

              Slack

                Issue deployment