Support Questions

Find answers, ask questions, and share your expertise
Announcements
Welcome to the upgraded Community! Read this blog to see What’s New!

Is it possible to manage multiple clusters using one ranger instance?

avatar

Is it possible to manage multiple clusters using one ranger instance?

1 ACCEPTED SOLUTION

avatar
Contributor

The primary limitation is wrt to UserSync. If there are multiple clusters, but using the same AD/LDAP, then you can use the same the Ranger instance to manage all of them.

View solution in original post

9 REPLIES 9

avatar

No I don't think it's possible.

Admin Authentication is only for one cluster. We would need to specify when we authenticate which cluster we are authenticating for.

Security Policies and configuration is on a cluster basis in the Ranger Admin database.

avatar

avatar

No, This is not supported.

avatar
Contributor

The primary limitation is wrt to UserSync. If there are multiple clusters, but using the same AD/LDAP, then you can use the same the Ranger instance to manage all of them.

avatar

@bdurai What challenges do you see from the Ambari side?

avatar
Contributor

There is no native support from Ambari to do this. If you are using Ambari in all env, then the Ambari which is hosting the main Ranger instance is oblivious of the clusters Ranger is supporting. The Ambari which is hosting Ranger will automatically configure Ranger for the components within it's cluster. For the other clusters, you have to go to each component and modify Ranger properties. E.g. you will have to set ranger.plugin.hbase.policy.rest.url property and few others. You also need to add all the services/repo using Ranger Admin UI.

avatar

@bdurai Based on this, I believe it's a good idea to have one to one relationship i,e Each cluster will have it's own ranger install.

avatar
Contributor

I agree, just because we can do it doesn't mean we should do it. From operation point of view, it is better to have one ranger per ambari cluster. This makes management very simple. Also, when it comes to upgrade, it will cause less headache.

avatar
New Contributor

Do you have any reference on how to enable ranger for kafka sitting in a separate cluster in CDP?

Labels