<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ranger should support column based ACL in case &amp;quot;Run as end user instead of Hive user = true&amp;quot; in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-should-support-column-based-ACL-in-case-quot-Run-as/m-p/102738#M15171</link>
    <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/790/joda.html" nodeid="790"&gt;@Junichi Oda&lt;/A&gt; - This is expected behaviour and it is the reason why it is recommended to have all hive processes run as hive user when you secure Hive with ranger.&lt;/P&gt;&lt;P&gt;There are two options in order to secure access to hive with Ranger :&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Solution 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Use both a repository HDFS and Hive to handle rights &lt;/P&gt;&lt;P&gt;
Keep "run as end user instead of hive" (hive.server2.enable.doAs=true) &lt;/P&gt;&lt;P&gt;This means the dual maintenance that you describe&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Solution 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Give rights to the hive user on the /apps/hive/warehouse arborescence in Ranger HDFS repository &lt;/P&gt;&lt;P&gt;Lock down filesystem permissions on HDFS (for example, chmod 750) &lt;/P&gt;&lt;P&gt;Use the Ranger Hive repository to handle rights on Hive tables &lt;/P&gt;&lt;P&gt;Run as hive instead of end user (hive.server2.enable.doAs=false)&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Solution 2 is the way to go. You may be concerned about auditability, but the Hive audits in Ranger will show the correct user. The HDFS audits and the YARN audits will still show "hive" yes, but you will be able to tell who ran the query.&lt;/P&gt;</description>
    <pubDate>Fri, 15 Jan 2016 17:38:58 GMT</pubDate>
    <dc:creator>agillan</dc:creator>
    <dc:date>2016-01-15T17:38:58Z</dc:date>
    <item>
      <title>Ranger should support column based ACL in case "Run as end user instead of Hive user = true"</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-should-support-column-based-ACL-in-case-quot-Run-as/m-p/102737#M15170</link>
      <description>&lt;P&gt;When I allow user1 to read the col1 column in the table on Hive, I will add the following policy to Hive service in Ranger.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1381-スクリーンショット-2016-01-15-165038.png" style="width: 902px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/23690iD39A08661B6086B2/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1381-スクリーンショット-2016-01-15-165038.png" alt="1381-スクリーンショット-2016-01-15-165038.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;However, this is not enough in case "Run as end user instead of Hive user = true".&lt;/P&gt;&lt;P&gt;I have to add the policy to HDFS service in Ranger.&lt;/P&gt;&lt;P&gt;The following table shows the policies at each ACL layer.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1382-スクリーンショット-2016-01-15-165544.png" style="width: 1776px;"&gt;&lt;img src="https://community.cloudera.com/t5/image/serverpage/image-id/23691iC1AB906509C15A70/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1382-スクリーンショット-2016-01-15-165544.png" alt="1382-スクリーンショット-2016-01-15-165544.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In this case, user1 can access to the entire table data by hdfs command or hive command without hiveserver2.&lt;/P&gt;&lt;P&gt;I think that Ranger support column based ACL in case when "Run as end user instead of Hive user" is true.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2019 12:13:24 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-should-support-column-based-ACL-in-case-quot-Run-as/m-p/102737#M15170</guid>
      <dc:creator>joda</dc:creator>
      <dc:date>2019-08-19T12:13:24Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger should support column based ACL in case "Run as end user instead of Hive user = true"</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-should-support-column-based-ACL-in-case-quot-Run-as/m-p/102738#M15171</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/790/joda.html" nodeid="790"&gt;@Junichi Oda&lt;/A&gt; - This is expected behaviour and it is the reason why it is recommended to have all hive processes run as hive user when you secure Hive with ranger.&lt;/P&gt;&lt;P&gt;There are two options in order to secure access to hive with Ranger :&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Solution 1&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Use both a repository HDFS and Hive to handle rights &lt;/P&gt;&lt;P&gt;
Keep "run as end user instead of hive" (hive.server2.enable.doAs=true) &lt;/P&gt;&lt;P&gt;This means the dual maintenance that you describe&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Solution 2&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Give rights to the hive user on the /apps/hive/warehouse arborescence in Ranger HDFS repository &lt;/P&gt;&lt;P&gt;Lock down filesystem permissions on HDFS (for example, chmod 750) &lt;/P&gt;&lt;P&gt;Use the Ranger Hive repository to handle rights on Hive tables &lt;/P&gt;&lt;P&gt;Run as hive instead of end user (hive.server2.enable.doAs=false)&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;Solution 2 is the way to go. You may be concerned about auditability, but the Hive audits in Ranger will show the correct user. The HDFS audits and the YARN audits will still show "hive" yes, but you will be able to tell who ran the query.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jan 2016 17:38:58 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-should-support-column-based-ACL-in-case-quot-Run-as/m-p/102738#M15171</guid>
      <dc:creator>agillan</dc:creator>
      <dc:date>2016-01-15T17:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger should support column based ACL in case "Run as end user instead of Hive user = true"</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-should-support-column-based-ACL-in-case-quot-Run-as/m-p/102739#M15172</link>
      <description>&lt;P&gt;Thank you very much for your reply and very helpful solutions.&lt;/P&gt;&lt;P&gt;I'd rather not manage both a repository HDFS and Hive if I can avoid it.&lt;/P&gt;&lt;P&gt;However, we manage Hadoop resources by the YARN queue assigned to each user.&lt;/P&gt;&lt;P&gt;For this reason I would like to keep "run as end user instead of hive"(hive.server2.enable.doAs=true).&lt;/P&gt;</description>
      <pubDate>Sat, 16 Jan 2016 20:23:59 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-should-support-column-based-ACL-in-case-quot-Run-as/m-p/102739#M15172</guid>
      <dc:creator>joda</dc:creator>
      <dc:date>2016-01-16T20:23:59Z</dc:date>
    </item>
  </channel>
</rss>

