Our Community is getting an upgrade! To get everything ready for the relaunch, we’ll be placing the site in read-only mode starting September 21st.
We really appreciate your understanding while we get things set up behind the scenes. Catch up on all the exciting details about the move here.
Need help or have questions? Drop us a line at [email protected]

Community Articles

Find and share helpful community-sourced technical articles.
Announcements
Share your experience with Cloudera on G2 and get a $25 Amazon Gift card.
Hi, I'm CLEO! Something exciting is coming to the Community. Stay Tuned!
avatar
Cloudera Employee

In this article, the requirement is to have simple tag names that will be applied to attributes in a Hive table.

Here, tags such as “Hashed” and “Masked” will be used in many tables. Different groups may need access to the data in the clear, while others will not be granted access. The opposite may apply for a different table.

 

Table name atlas_tag_test has the columns ssn that will be shown for hr_users and masked for power_users.

 

  • The value will be a comma-separated list of groups, in this case, we only have a single group.
    001.png
  • Now in Ranger, we have a policy for masked.
    002.png
  • For each group we are adding a condition, we check if power_users are set in the group's attribute like the following:
    if ( ctx.getAttributeValue("Masked","groups").indexOf("power_users") !== -1 )
    { ctx.result = false; } else { ctx.result = true; }

 

 

  • If it is, the data will be available to the user to see in the clear. It is not, the users will not be able to see the data.
    003.png

 

  • We will add another row for hr_users like the following:
    if ( ctx.getAttributeValue("Masked","groups").indexOf("hr_users") !== -1 )
    { ctx.result = false; } else { ctx.result = true; }
    004.png

 

  • When selecting the data with a power_users, the data is masked:
    005.png

    006.png
  • When executing with hr_users, the data is displayed as un-masked:007.png
    008.png
  • We can see for the power_users that the masked policy was applied to matching number 85:009.png

 

 To dig deeper into it what additional functions are available you could also review the source code in GIT.

1,121 Views
0 Kudos