<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>question Re: Quickly secure the access to the cluster via http in Archives of Support Questions (Read Only)</title>
    <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Quickly-secure-the-access-to-the-cluster-via-http/m-p/164701#M29450</link>
    <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/5134/kaliyugantagonist.html" nodeid="5134"&gt;@Kaliyug Antagonist&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;I would suggest implementing Knox, with a restricted set of users allowing access to only the set of services you want to expose to those users.&lt;/P&gt;&lt;P&gt;Both &lt;A target="_blank" href="http://hortonworks.com/apache/knox-gateway/"&gt;http://hortonworks.com/apache/knox-gateway/&lt;/A&gt; and &lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.4.2/bk_Security_Guide/content/perimeter_security_with_apache_knox.html"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.4.2/bk_Security_Guide/content/perimeter_security_with_apache_knox.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;... should get you started.&lt;/P&gt;&lt;P&gt;Hope that helps.
&lt;A target="_blank" href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.4.2/bk_Security_Guide/content/perimeter_security_with_apache_knox.html"&gt;&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 24 May 2016 18:01:46 GMT</pubDate>
    <dc:creator>drussell</dc:creator>
    <dc:date>2016-05-24T18:01:46Z</dc:date>
    <item>
      <title>Quickly secure the access to the cluster via http</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Quickly-secure-the-access-to-the-cluster-via-http/m-p/164700#M29449</link>
      <description>&lt;P&gt;Stack : Installed HDP-2.3.2.0-2950 using Ambari 2.1&lt;/P&gt;&lt;P&gt;The cluster is having 1NN + 8 DN = 9 nodes.&lt;/P&gt;&lt;P&gt;Some business sensitive data has been loaded onto HDFS via Sqoop.&lt;/P&gt;&lt;P&gt;While access to the Ambari URL at &lt;A href="http://NN:8080" target="_blank"&gt;http://NN:8080&lt;/A&gt; is acceptable, the access to the &lt;A href="http://NN:50070/" target="_blank"&gt;http://NN:50070/&lt;/A&gt; and further utilities like 'Browsing the file system' &lt;STRONG&gt;should be restricted to only 2-3 selected users&lt;/STRONG&gt;. Right now, anyone can browse the hdfs contents via the browser.&lt;/P&gt;&lt;P&gt;How to do it, preferably via Ambari ?&lt;/P&gt;&lt;P&gt;Note : The access to different components(Hive, HDFS) etc. role wise is a later part, right now, just hiding the data is the concern&lt;/P&gt;</description>
      <pubDate>Fri, 16 Sep 2022 10:21:30 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Quickly-secure-the-access-to-the-cluster-via-http/m-p/164700#M29449</guid>
      <dc:creator>kaliyugantagoni</dc:creator>
      <dc:date>2022-09-16T10:21:30Z</dc:date>
    </item>
    <item>
      <title>Re: Quickly secure the access to the cluster via http</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Quickly-secure-the-access-to-the-cluster-via-http/m-p/164701#M29450</link>
      <description>&lt;P&gt;Hi &lt;A rel="user" href="https://community.cloudera.com/users/5134/kaliyugantagonist.html" nodeid="5134"&gt;@Kaliyug Antagonist&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;I would suggest implementing Knox, with a restricted set of users allowing access to only the set of services you want to expose to those users.&lt;/P&gt;&lt;P&gt;Both &lt;A target="_blank" href="http://hortonworks.com/apache/knox-gateway/"&gt;http://hortonworks.com/apache/knox-gateway/&lt;/A&gt; and &lt;/P&gt;&lt;P&gt;&lt;A target="_blank" href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.4.2/bk_Security_Guide/content/perimeter_security_with_apache_knox.html"&gt;http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.4.2/bk_Security_Guide/content/perimeter_security_with_apache_knox.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;... should get you started.&lt;/P&gt;&lt;P&gt;Hope that helps.
&lt;A target="_blank" href="http://docs.hortonworks.com/HDPDocuments/HDP2/HDP-2.4.2/bk_Security_Guide/content/perimeter_security_with_apache_knox.html"&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 18:01:46 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Quickly-secure-the-access-to-the-cluster-via-http/m-p/164701#M29450</guid>
      <dc:creator>drussell</dc:creator>
      <dc:date>2016-05-24T18:01:46Z</dc:date>
    </item>
    <item>
      <title>Re: Quickly secure the access to the cluster via http</title>
      <link>https://community.cloudera.com/t5/Archives-of-Support-Questions/Quickly-secure-the-access-to-the-cluster-via-http/m-p/164702#M29451</link>
      <description>&lt;P&gt;Alternatively use kerberos and kerberize the HDFS UI. In this case only SPNEGO enabled browsers will be able to access the ui and you will have the same filesystem access restrictions as users have when directly accessing hdfs.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2016 19:48:06 GMT</pubDate>
      <guid>https://community.cloudera.com/t5/Archives-of-Support-Questions/Quickly-secure-the-access-to-the-cluster-via-http/m-p/164702#M29451</guid>
      <dc:creator>bleonhardi</dc:creator>
      <dc:date>2016-05-24T19:48:06Z</dc:date>
    </item>
  </channel>
</rss>

