Uploaded image for project: 'Ranger'
  1. Ranger
  2. RANGER-1974

Ranger Authorizer and Audits for AWS S3

    XMLWordPrintableJSON

Details

    • New Feature
    • Status: Open
    • Blocker
    • Resolution: Unresolved
    • None
    • None
    • Ranger
    • None

    Description

      As an enterprise security admin, I need to be able to define and manage authorization policies for data stored in AWS S3 so that I can manage my access control and authorization entitlements in hybrid and cloud environments along with other data in platforms that Ranger currently authorizes. This feature will should allow interoperability with AWS IAM policies and be able to gather audits from the native cloud audit capabilities such as via AWS CloudTrail.

      Implementation considerations:

      1. AWS S3 IAM  information: https://aws.amazon.com/documentation/iam/
      2. AWS CloudTrail information: https://aws.amazon.com/documentation/cloudtrail/
      3. This could be a policy mapping or sync mechanism (either online or offline) that will allow Ranger policy conditions, and user/group/role or other policy elements to be mapped to what is available in AWS IAM. This might entail having a different model where the Ranger plugin might not be running in the cloud native service and might require a proxy or other paradigms to be effective.

      Attachments

        Activity

          People

            bosco Bosco
            srikvenk Srikanth Venkat
            Votes:
            4 Vote for this issue
            Watchers:
            16 Start watching this issue

            Dates

              Created:
              Updated: