Support Questions

Find answers, ask questions, and share your expertise
Announcements
Celebrating as our community reaches 100,000 members! Thank you!

When is new CDH bundle with impala version 3.3.0 going to release?

avatar
Contributor

Hello Team,

 

 

We were planning to implement Role-Based-Access-Control(RBAC) for our impala tables we tried Sentry but there is a prerequisite of installing Kerberos which we don't want to use. So Apache Ranger is the other option we have but the latest CDH version 6.3 has Impala 3.2 which does not support Ranger. So just wanted to if there is going to be release of new CDH bundle which will have Impala 3.3.0 and support for ranger? What will be approximate release date of the new CDH bundle?

 

 

 

Regards

Parth

1 ACCEPTED SOLUTION

avatar
Super Guru
@parthk ,

There is no current date locked in for the new impala release that will support Ranger at the moment.

However, I would like to ask why you do not want to have kerberos? Authorization does not work properly without Authentication in the front. Think about an online application, you surely want users to be able to login first, before you can say what level of access they should have. Same applies in CDH world. Kerberos acts as the front end login, and Sentry/Ranger acts as the backend authorization control. So without Kerberos, you are allowing everyone to be able to access CDH.

I strongly suggest you to implement Kerberos first before Sentry, Ranger is the same story regardless.

Cheers
Eric

View solution in original post

3 REPLIES 3

avatar
Super Guru
@parthk ,

There is no current date locked in for the new impala release that will support Ranger at the moment.

However, I would like to ask why you do not want to have kerberos? Authorization does not work properly without Authentication in the front. Think about an online application, you surely want users to be able to login first, before you can say what level of access they should have. Same applies in CDH world. Kerberos acts as the front end login, and Sentry/Ranger acts as the backend authorization control. So without Kerberos, you are allowing everyone to be able to access CDH.

I strongly suggest you to implement Kerberos first before Sentry, Ranger is the same story regardless.

Cheers
Eric

avatar
Contributor

Hey @EricL 

 

Apologies for terribly delayed response. The reason why we don't want to install kerberos is that we are using a third party BI tool which connect to our DW Infrastucture(consisting of Kudu, Hive Metastore and Impala) and the tool does not support kerberos authentication. We are heavily dependent on the on the BI tool which we use and cannot do away with it. Sentry enforces to use kerberos for authentication while Ranger does not enforce this as it supports other authentication mechanisms as well. That's why we are waiting eagerly for cloudera to release a version of Impala(supported by 3.3 latest released by cloudera is 3.2) which supports Ranger. Also it will be great if you can suggest any other solution enforcing the Access controls which does not involve kerberos.

 

Regards

Parth

 

avatar
Super Guru
Hi @parthk,

No problems. Impala + Ranger is under construction for CDP release. From what I can see Phase one is done and there are a few more phases to go through. So it is still early stage and I do not have ETA.

You probably just have to wait and ask the question again a few months down the track.

Cheers
Eric