You are viewing a plain text version of this content. The canonical link for it is here.
Posted to user@ranger.apache.org by Lune Silver <lu...@gmail.com> on 2016/06/24 10:01:07 UTC

About the usage of the property Policy user for

Hello !

I have an HDP 2.3.4.7 with Ambari 2.2.1.

I enabled ranger for three plugins :
- HDFS
- HBase
- Kafka.

For each one of these plugins, in their configuration in Ambari, in the
paragraph Advanced ranger-<plugin name>-plugin-properties, there is a
property called :
###
Policy user for <NAME OF THE PLUGIN>
###

And it it set to ambari-qa by default.

The thing is, when Ambari creates the repository for the specific plugin
(this is now called service if I remember well), then it creates a policy
with all the rights for the user ambari-qa.

In the comment of the property Policy user for <NAME OF THE PLUGIN>, it
said the following :
###
This user must be system user and also present at ranger admin portal
###

Do you know guys if it would not be better to set this property to the
super admin of each of the plugin ? I mean for example, hdfs for the plugin
hdfs, hbase for the plugin hbase, kafka for the plugin kafka.

BR.

Lune.