Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]
Created on 05-24-2016 10:44 AM - edited 09-16-2022 03:21 AM
Stack : Installed HDP-2.3.2.0-2950 using Ambari 2.1
The cluster is having 1NN + 8 DN = 9 nodes.
Some business sensitive data has been loaded onto HDFS via Sqoop.
While access to the Ambari URL at http://NN:8080 is acceptable, the access to the http://NN:50070/ and further utilities like 'Browsing the file system' should be restricted to only 2-3 selected users. Right now, anyone can browse the hdfs contents via the browser.
How to do it, preferably via Ambari ?
Note : The access to different components(Hive, HDFS) etc. role wise is a later part, right now, just hiding the data is the concern
Created 05-24-2016 11:01 AM
I would suggest implementing Knox, with a restricted set of users allowing access to only the set of services you want to expose to those users.
Both http://hortonworks.com/apache/knox-gateway/ and
... should get you started.
Created 05-24-2016 11:01 AM
I would suggest implementing Knox, with a restricted set of users allowing access to only the set of services you want to expose to those users.
Both http://hortonworks.com/apache/knox-gateway/ and
... should get you started.
Created 05-24-2016 12:48 PM
Alternatively use kerberos and kerberize the HDFS UI. In this case only SPNEGO enabled browsers will be able to access the ui and you will have the same filesystem access restrictions as users have when directly accessing hdfs.