Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]

Archives of Support Questions (Read Only)

This is an archived board for historical reference. Information and links may no longer be available or relevant
Announcements
This board is archived and read-only for historical reference. To ask a new question, please post a new topic on the appropriate active board.

Beeline Authentication with Ranger vs. Hive CLI

avatar

I can setup a policy in Ranger for a certain Hive table so that only certain users can SELECT from the table.

When I use the Beeline command-line interface and login as a user that DOES NOT have SELECT access to that table, then I will get an error, as expected, indicating permission denied.

It's my understanding that Beeline communicates with HiveServer2 using HiveServer2’s Thrift APIs.

However, if I am logged into a terminal as that same user who DOES NOT have SELECT access, and I launch the Hive CLI, then I am able to read from the table.

I'm guessing this has to due with the Hive CLI not interacting with HiveServer 2? Is this the reason why I am able to SELECT from the table via Hive CLI, whereas through Beeline I am not able to SELECT from the table. My Ranger policy is set so that only certain users should be able to SELECT from the table. Beeline enforces this policy, whereas Hive CLI does not.

1 ACCEPTED SOLUTION

avatar
Master Guru

@Binu Mathew

Hive CLI bypasses all the security policies.

Please find answer to your question here - https://community.hortonworks.com/questions/10760/how-to-disable-hive-shell-for-all-users.html

View solution in original post

1 REPLY 1

avatar
Master Guru

@Binu Mathew

Hive CLI bypasses all the security policies.

Please find answer to your question here - https://community.hortonworks.com/questions/10760/how-to-disable-hive-shell-for-all-users.html