ranger-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Madhan Neethiraj (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (RANGER-812) ranger policies malfunctioned
Date Tue, 12 Jan 2016 17:23:39 GMT

    [ https://issues.apache.org/jira/browse/RANGER-812?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15094333#comment-15094333

Madhan Neethiraj commented on RANGER-812:

[~fantastic340] In YARN, if no Ranger policy exists to make authorization decision, Ranger
plugin checks YARN ACLs for authorization. Please check YARN ACLs in your environment (in
capacity-scheduler.xml). Details of the setting up YARN ACLs can be found here:  http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.3.2/bk_yarn_resource_mgt/content/controlling_access_to_queues_with_acls.html.

About Kafka, do you see this behavior only for create-topic? Do operations like produce, consume
get a deny when all Ranger policies are disabled? 

> ranger policies malfunctioned
> -----------------------------
>                 Key: RANGER-812
>                 URL: https://issues.apache.org/jira/browse/RANGER-812
>             Project: Ranger
>          Issue Type: Bug
>          Components: plugins
>    Affects Versions: 0.5.0
>            Reporter: bensonshih
>            Priority: Minor
> After I enable ranger for yarn and kafka, then I disabled all the policies of ranger.
however, I still can execute commands like create topic(kafka) or do some mapreduce job(yarn),it
didn`t show any permission denied message

This message was sent by Atlassian JIRA

View raw message