<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Ranger Admin - Role Seperation in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155046#M20712</link>
    <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/1486/smanjee.html" nodeid="1486"&gt;@Sunile Manjee&lt;/A&gt; &lt;A rel="user" href="https://community.cloudera.com/users/2820/shishirsaxena3.html" nodeid="2820"&gt;@Shishir Saxena&lt;/A&gt;&lt;/P&gt;&lt;P&gt;ADMIN user creates policies based on departments "policy at root level" and delegate admin to particular user or groups to manage the policies and that's how you seggrate the admin roles&lt;/P&gt;</description>
    <pubDate>Thu, 25 Feb 2016 07:31:13 GMT</pubDate>
    <dc:creator>nsabharwal</dc:creator>
    <dc:date>2016-02-25T07:31:13Z</dc:date>
    <item>
      <title>Ranger Admin - Role Seperation</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155040#M20706</link>
      <description>&lt;P&gt;Currently on ranger UI service manager a user has access to all available services. Screen shot:&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cloudera.com/legacyfs/online/attachments/2357-2016-02-23-14-45-51.jpg"&gt;2016-02-23-14-45-51.jpg&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It is possible user only have access to certain services.  Example DBA only have access to HBASE security control and not other services exposed on ranger ie yarn, hdfs, solr, hive, etc.  &lt;/P&gt;&lt;P&gt;Rephrasing the question:&lt;/P&gt;&lt;P&gt;Role based access to users&lt;STRONG&gt; with admin roles&lt;/STRONG&gt;. Currently any user with admin role will have access to all policy repos. Is there is way to control access to policies for users with admin role.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 04:47:52 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155040#M20706</guid>
      <dc:creator>sunile_manjee</dc:creator>
      <dc:date>2016-02-24T04:47:52Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger Admin - Role Seperation</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155041#M20707</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/1486/smanjee.html" nodeid="1486"&gt;@Sunile Manjee&lt;/A&gt;, your screenshot is for the admin user. admin will be always able to see and change them all. For other users you control their access using Ranger -&amp;gt; Settings -&amp;gt; Permissions. If you remove a user from the "Resource Based Policy" list of users he will be able to see a read-only list of policies, but only those in which he was given "Delegate admin" permission (available on each policy to the right of basic permissions), see my screenshot. If he is in the "Resource Based Policy" list he will be presented with a top-level menu like in your screenshot but will be able to interact (edit) only his "Delegate admin" policies. By the way, the above applies to HDP-2.3.4, in earlier versions it might be somewhat different.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cloudera.com/legacyfs/online/attachments/2368-screen-shot-2016-02-24-at-80537-am.png"&gt;screen-shot-2016-02-24-at-80537-am.png&lt;/A&gt;
&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 07:11:08 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155041#M20707</guid>
      <dc:creator>pminovic</dc:creator>
      <dc:date>2016-02-24T07:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger Admin - Role Seperation</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155042#M20708</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/1486/smanjee.html" nodeid="1486"&gt;@Sunile Manjee&lt;/A&gt;&lt;P&gt;See this thread and a demo&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.hortonworks.com/questions/17782/about-delegate-admin-in-ranger.html" target="_blank"&gt;https://community.hortonworks.com/questions/17782/about-delegate-admin-in-ranger.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Demo: &lt;A href="http://i.giphy.com/l4Ki1Ng3uxdTnUTra.gif" target="_blank"&gt;http://i.giphy.com/l4Ki1Ng3uxdTnUTra.gif&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 07:23:19 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155042#M20708</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-02-24T07:23:19Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger Admin - Role Seperation</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155043#M20709</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/1486/smanjee.html" nodeid="1486"&gt;@Sunile Manjee&lt;/A&gt; &lt;A rel="user" href="https://community.cloudera.com/users/140/nsabharwal.html" nodeid="140"&gt;@Neeraj Sabharwal&lt;/A&gt; &lt;A rel="user" href="https://community.cloudera.com/users/177/pminovic.html" nodeid="177"&gt;@Predrag Minovic&lt;/A&gt; I think Sunile's question is role based access to users&lt;STRONG&gt; with admin roles&lt;/STRONG&gt;. Currently any user with admin role will have access to all policy repos. There is no way to control access to policies for users with admin role. &lt;/P&gt;&lt;P&gt;That should be high on enhancement list for Ranger to support role based access to policy repos.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 21:25:03 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155043#M20709</guid>
      <dc:creator>shishir_saxena4</dc:creator>
      <dc:date>2016-02-24T21:25:03Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger Admin - Role Seperation</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155044#M20710</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2820/shishirsaxena3.html" nodeid="2820"&gt;@Shishir Saxena&lt;/A&gt; &lt;A rel="user" href="https://community.cloudera.com/users/140/nsabharwal.html" nodeid="140"&gt;@Neeraj Sabharwal&lt;/A&gt; &lt;A rel="user" href="https://community.cloudera.com/users/177/pminovic.html" nodeid="177"&gt;@Predrag Minovic&lt;/A&gt; &lt;/P&gt;&lt;P&gt;That is exactly my question. Ok so it is not a supported feature.  We need to vote this up.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 04:34:21 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155044#M20710</guid>
      <dc:creator>sunile_manjee</dc:creator>
      <dc:date>2016-02-25T04:34:21Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger Admin - Role Seperation</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155045#M20711</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/140/nsabharwal.html" nodeid="140"&gt;@Neeraj Sabharwal&lt;/A&gt; &lt;/P&gt;&lt;P&gt;Great demo!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 04:36:51 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155045#M20711</guid>
      <dc:creator>sunile_manjee</dc:creator>
      <dc:date>2016-02-25T04:36:51Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger Admin - Role Seperation</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155046#M20712</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/1486/smanjee.html" nodeid="1486"&gt;@Sunile Manjee&lt;/A&gt; &lt;A rel="user" href="https://community.cloudera.com/users/2820/shishirsaxena3.html" nodeid="2820"&gt;@Shishir Saxena&lt;/A&gt;&lt;/P&gt;&lt;P&gt;ADMIN user creates policies based on departments "policy at root level" and delegate admin to particular user or groups to manage the policies and that's how you seggrate the admin roles&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 07:31:13 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155046#M20712</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-02-25T07:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger Admin - Role Seperation</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155047#M20713</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/140/nsabharwal.html" nodeid="140"&gt;@Neeraj Sabharwal&lt;/A&gt; &lt;A rel="user" href="https://community.cloudera.com/users/1486/smanjee.html" nodeid="1486"&gt;@Sunile Manjee&lt;/A&gt; Are you suggesting one default policy at root level per repo with delegated admin rights and then individual users in group managing additional policies ?&lt;/P&gt;&lt;P&gt;e.g. We can create one hive policy with root privileges and assign it to dba group with delegated admin rights ? Then DBA group can create any further Hive policies. &lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 09:10:15 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155047#M20713</guid>
      <dc:creator>shishir_saxena4</dc:creator>
      <dc:date>2016-02-25T09:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger Admin - Role Seperation</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155048#M20714</link>
      <description>&lt;P&gt;&lt;A rel="user" href="https://community.cloudera.com/users/2820/shishirsaxena3.html" nodeid="2820"&gt;@Shishir Saxena&lt;/A&gt;  As DBA lead, I would the same. &lt;/P&gt;&lt;P&gt;I will create policies and I will define the root and then delegate admins to those policies and other admins based on the role that I defined will manage particular policies... &lt;A rel="user" href="https://community.cloudera.com/users/1486/smanjee.html" nodeid="1486"&gt;@Sunile Manjee&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2016 09:13:50 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155048#M20714</guid>
      <dc:creator>nsabharwal</dc:creator>
      <dc:date>2016-02-25T09:13:50Z</dc:date>
    </item>
    <item>
      <title>Re: Ranger Admin - Role Seperation</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155049#M20715</link>
      <description>&lt;A rel="user" href="https://community.cloudera.com/users/140/nsabharwal.html" nodeid="140"&gt;@Neeraj Sabharwal&lt;/A&gt;&lt;P&gt;I am unclear about the direction.  I need to create a user in ranger which only does admin for hbase (for example).  right now it seems admin delegation is per policy.  Lets say As a hadoop admin i want to provide my dba team access &lt;STRONG&gt;only&lt;/STRONG&gt; to hbase admin rights.  I don't believe this is possible.  If so could you provide steps.  Seems others in this post are as confused as I am.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2016 12:02:33 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Ranger-Admin-Role-Seperation/m-p/155049#M20715</guid>
      <dc:creator>sunile_manjee</dc:creator>
      <dc:date>2016-03-02T12:02:33Z</dc:date>
    </item>
  </channel>
</rss>

