Configure Ranger for Impala on Kubernetes using CLI

Prerequisites

  • An ADPS cluster (2.0.0 or later) is installed and running.

  • An ADH cluster (4.2.0 or later) is installed and running.

  • Impala is installed according to the instruction.

Step 1. Create a service in Ranger

This guide describes how to create a service via Ranger REST API. Alternatively, you can create a service in the Ranger web UI.

  1. Define a service in a JSON file:

    ranger-impala-k8s.json
    {
      "isEnabled": true,
      "type": "hive",
      "name": "impala_k8s", (1)
      "displayName": "impala_k8s",
      "description": "Service for Kubernetes Impala",
      "configs": {
        "username": "impala", (2)
        "password": "bigdata",  (3)
        "ranger.plugin.audit.filters": "[ {'accessResult': 'DENIED', 'isAudited': true}, {'actions':['METADATA OPERATION'], 'isAudited': false}, {'users':['hive','hue'],'actions':['SHOW_ROLES'],'isAudited':false} ]",
        "jdbc.driverClassName": "org.apache.hive.jdbc.HiveDriver",
        "jdbc.url": "jdbc:impala://10.92.41.149:21050" (4)
      }
    }
    1 A name of the Impala service in Ranger. Must be unique.
    2 A username for the service.
    3 A password for the service.
    4 A JDBC string for connecting to Impala that is exposed by load balancer.
  2. Push the defined service to Ranger:

    $ curl -u admin:<admin_pwd> -H "Content-Type: application/json" -X POST -d @ranger-impala-k8s.json http://<ranger-admin>:6080/service/public/v2/api/service

Step 2. Update the Impala cluster configuration

  1. Edit the impala-cluster.yaml configuration file by adding the Ranger configuration block:

    impala-cluster.yaml
    apiVersion: adc.arenadata.io/v1alpha1
    kind: ImpalaCluster
    metadata:
      name: impala
      namespace: impala (1)
    spec:
      image: hub.arenadata.io/adc-enterprise/impala:<tag> (2)
    
      ## Image pull secret for a private registry.
      ## Set 'externalSecretName' to reference an existing Secret,
      ## or set 'credentials' and optionally 'secretName' to let the CLI create one.
      #imagePullSecret:
      #  # Use a Secret managed outside ADC.
      #  externalSecretName: existing-registry-secret
      #
      #  ## Or let ADC create the Secret.
      #  #secretName: custom-registry-secret
      #
      #  #credentials:
      #  #  registry: registry.example.com
      #  #  username: user
      #  #  password: pass
    
      hadoop: (3)
        core:
          dfs.client.failover.proxy.provider.adh: org.apache.hadoop.hdfs.server.namenode.ha.ObserverReadProxyProvider
          dfs.ha.namenodes.adh: nn_tsn-adh-k8s-1,nn_tsn-adh-k8s-3
          dfs.namenode.rpc-address.adh.nn_tsn-adh-k8s-1: tsn-adh-k8s-1.ru-central1.internal:8020
          dfs.namenode.rpc-address.adh.nn_tsn-adh-k8s-3: tsn-adh-k8s-3.ru-central1.internal:8020
          dfs.nameservices: adh
          fs.defaultFS: hdfs://adh
          hadoop.security.authentication: simple
        hdfs:
          dfs.client.read.shortcircuit: "false"
        hive:
          hive.metastore.sasl.enabled: "false"
          hive.metastore.uris: thrift://tsn-adh-k8s-1.ru-central1.internal:9083
          metastore.use.SSL: "false"
        ozone:
          ozone.om.address.adh.om_tsn-adh-k8s-1: tsn-adh-k8s-1.ru-central1.internal:9862
          ozone.om.address.adh.om_tsn-adh-k8s-2: tsn-adh-k8s-2.ru-central1.internal:9862
          ozone.om.address.adh.om_tsn-adh-k8s-3: tsn-adh-k8s-3.ru-central1.internal:9862
          ozone.om.nodes.adh: om_tsn-adh-k8s-1,om_tsn-adh-k8s-2,om_tsn-adh-k8s-3
          ozone.om.service.ids: adhom
    
      ## Kerberos configuration for authentication.
      #kerberos:
      #  realm: EXAMPLE.COM
      #
      #  # Service name in the Kerberos principal. Defaults to the product name.
      #  service: impala
      #
      #  # Hostname in the Kerberos principal.
      #  # Required for a fixed service principal; leave it empty only to derive one principal per pod from the cluster domain.
      #  hostname: kerberos.example.com
      #  keytab:
      #    # true - kerberos-operator creates the keytab Secret.
      #    # false (default) - reference an existing keytab Secret with name keytab.secretName.
      #    create: false
      #
      #    # Name of the keytab Secret.
      #    # Optional when create: true - names the generated Secret (default: <name>-keytab).
      #    # Required when create: false - must reference an existing Secret.
      #    secretName: kerberos-secret
      #
      #    # Label selector for the Pod that generates the keytab.
      #    # Required when create: true; ignored when create: false.
      #    labelSelector:
      #      env: prod
      #    #additionalPrincipals:
      #    #  - HTTP/kerberos.example.com
      #
      #    clusterDomain: cluster.local
      #    rotation:
      #      interval: 24h
      #      checkInterval: 1h
    
      ## LDAP authentication configuration.
      ## Uncomment and fill url and userBindPattern.
      ## For ldaps:// URLs the ssl: or ca: section must also be configured (depends on product)
      #ldap:
      #  # LDAP service url.
      #  url: ldaps://ldap.example.com:636
      #
      #  # LDAP user Bind pattern.
      #  userBindPattern: uid=#UID,cn=users,dc=example,dc=com
    
      ## Ranger plugin configuration.
      ## Uncomment and fill the lines below. adc apply derives the rest.
      ranger: (4)
      #  # fill ranger.plugin.impala.policy.rest.url below with Ranger endpoint, e.g. https://adps-adc.ru-central1.internal:6182
      #  # fill ranger.plugin.impala.service.name below with Ranger service name you want to use for product, e.g. adc_impala_id_1
        security:
          ranger.plugin.impala.policy.rest.url: "<ranger-admin>:6080"
          ranger.plugin.impala.service.name: "impala_k8s"
          ranger.plugin.impala.use.rangerGroups: "True"
          ranger.plugin.impala.use.only.rangerGroups: "True"
      #
      #  # fill xasecure.audit.destination.solr.zookeepers below with Zookeepers endpoints to resolve solr service, e.g. adps-adc.ru-central1.internal:2181/Arenadata.Hadoop-2.solr.server
        audit:
          xasecure.audit.destination.solr.zookeepers: "tsn-adps2-1.ru-central1.internal:2181/Arenadata.Hadoop-3.solr.server"
      #
      #  # Local Ranger files 'adc apply' writes into the configs Secret.
      #  # Relative paths are resolved against the config file.
        files: (5)
          jceksStorePath: /tmp/impala_minimal/ranger-impala.jceks
    
      ## Java KeyStore/TrustStore certificate configuration.
      ## Set externalSecretName to reference an existing Secret,
      ## or set files and optional secretName to have ADC create it.
      #ssl:
      #  ## Name of the Secret containing Java keystores.
      #  #secretName: custom-ssl-secret
      #  externalSecretName: existing-ssl-secret
      #
      #  # Key in the Secret containing the truststore file.
      #  trustStoreKey: truststore.jks
      #
      #  ## Password for the truststore (optional).
      #  #trustStorePassword: bigdata
      #
      #  ## Key in the Secret containing the keystore file (optional).
      #  #keyStoreKey: keystore.jks
      #
      #  ## Password for the keystore (optional).
      #  #keyStorePassword: bigdata
      #
      #  ## Local files 'adc apply' puts into the Secret named by ssl.secretName.
      #  ## Relative paths are resolved against the config file.
      #  #files:
      #  #  trustStorePath: /path/to/truststore.jks
      #  #  #keyStorePath: /path/to/keystore.jks
    
      ## Use an external complete configs Secret instead of the one rendered by ADC.
      #configsSecret:
      #  # Use a Secret managed outside ADC.
      #  externalSecretName: existing-impala-configs
      #
      #  ## Or let ADC create the Secret.
      #  #secretName: custom-impala-configs
    
      catalog:
        replicas: 1
        #resources:
        #  limits:
        #    cpu: "2"
        #    memory: 8Gi
        #  requests:
        #    cpu: 300m
        #    memory: 384Mi
    
        ## Component arguments. Key-value pairs passed to the component configuration.
        #args:
        #  redirect_stdout_stderr: "false"
    
        ## Environment variables passed to the component container.
        #envs:
        #  - name: JAVA_TOOL_OPTIONS
        #    value: |-
        #      -Djavax.net.ssl.trustStore=/etc/ssl/truststore.jks
        #      -Djavax.net.ssl.trustStorePassword=bigdata
      coordinator:
        replicas: 1
        #resources:
        #  limits:
        #    cpu: "2"
        #    memory: 8Gi
        #  requests:
        #    cpu: 300m
        #    memory: 384Mi
    
        ## Component arguments. Key-value pairs passed to the component configuration.
        #args:
        #  redirect_stdout_stderr: "false"
    
        ## Environment variables passed to the component container.
        #envs:
        #  - name: JAVA_TOOL_OPTIONS
        #    value: |-
        #      -Djavax.net.ssl.trustStore=/etc/ssl/truststore.jks
        #      -Djavax.net.ssl.trustStorePassword=bigdata
      executor:
        replicas: 1
        #resources:
        #  limits:
        #    cpu: "2"
        #    memory: 8Gi
        #  requests:
        #    cpu: 300m
        #    memory: 384Mi
    
        ## Component arguments. Key-value pairs passed to the component configuration.
        #args:
        #  redirect_stdout_stderr: "false"
    
        ## Environment variables passed to the component container.
        #envs:
        #  - name: JAVA_TOOL_OPTIONS
        #    value: |-
        #      -Djavax.net.ssl.trustStore=/etc/ssl/truststore.jks
        #      -Djavax.net.ssl.trustStorePassword=bigdata
      statestore:
        replicas: 1
        #resources:
        #  limits:
        #    cpu: "2"
        #    memory: 8Gi
        #  requests:
        #    cpu: 300m
        #    memory: 384Mi
    
        ## Component arguments. Key-value pairs passed to the component configuration.
        #args:
        #  redirect_stdout_stderr: "false"
    
        ## Environment variables passed to the component container.
        #envs:
        #  - name: JAVA_TOOL_OPTIONS
        #    value: |-
        #      -Djavax.net.ssl.trustStore=/etc/ssl/truststore.jks
        #      -Djavax.net.ssl.trustStorePassword=bigdata
    
      ## Monitoring configuration.
      #monitoring:
      #  # Enables Prometheus metrics export from this product's pods.
      #  exportMetrics: true
    
      ## Admission-control resource pools. Rendered into a coordinator-only Secret (fair-scheduler.xml and optional llama-site.xml) mounted at /opt/impala/resource-pools.
      #resourcePools:
      #  # Fair-scheduler queue tree and placement policy, rendered to fair-scheduler.xml.
      #  allocations:
      #    # Queue tree, rooted at a single queue.
      #    queues:
      #      - aclSubmitApps: ' '
      #        name: root
      #        queues:
      #        - aclSubmitApps: '*'
      #          maxResources:
      #            memory: 50000
      #            vcores: 0
      #          name: default
      #          type: leaf
      #        type: parent
      #
      #    # Rules that route an incoming query to a queue.
      #    queuePlacementPolicy:
      #      rules:
      #        - create: false
      #          name: specified
      #        - name: default
      #
      #  # Raw llama-site.xml properties, rendered verbatim in list order.
      #  llamaProperties:
      #    # List of name/value pairs written to llama-site.xml.
      #    properties:
      #      - name: llama.am.throttling.maximum.placed.reservations.root.default
      #        value: "10"
    
      ## TLS certificate configuration.
      ## Set externalSecretName to reference an existing Secret,
      ## or set files and optional secretName to have ADC create it.
      #tls:
      #  ## Optional name of the Secret ADC creates from local files.
      #  #secretName: custom-tls-secret
      #  externalSecretName: existing-tls-secret
      #
      #  # Key in the Secret containing the TLS certificate.
      #  certificateKey: tls.crt
      #
      #  # Key in the Secret containing the TLS private key.
      #  privateKey: tls.key
      #
      #  ## Key in the Secret containing the client CA certificate.
      #  #clientCaCertificate: ca.crt
      #
      #  ## Local files 'adc apply' puts into the Secret named by tls.secretName.
      #  ## Relative paths are resolved against the config file.
      #  #files:
      #  #  certificatePath: /path/to/tls.crt
      #  #  privateKeyPath: /path/to/tls.key
      #  #  #clientCaCertificatePath: /path/to/ca.crt
    
      ## TLS certificate configuration for web UI and HTTP endpoints.
      ## Set externalSecretName to reference an existing Secret,
      ## or set files and optional secretName to have ADC create it.
      #webTLS:
      #  ## Optional name of the Secret ADC creates from local files.
      #  #secretName: custom-web-tls-secret
      #  externalSecretName: existing-web-tls-secret
      #
      #  # Key in the Secret containing the web TLS certificate.
      #  certificateKey: tls.crt
      #
      #  # Key in the Secret containing the web TLS private key.
      #  privateKey: tls.key
      #
      #  ## Local files 'adc apply' puts into the Secret named by webTLS.secretName.
      #  ## Relative paths are resolved against the config file.
      #  #files:
      #  #  certificatePath: /path/to/tls.crt
      #  #  privateKeyPath: /path/to/tls.key
    
      ## CA certificate configuration for Impala.
      ## Set externalSecretName, or let ADC create a Secret from files.
      #ca:
      #  ## Optional name of the Secret ADC creates from a local file.
      #  #secretName: custom-ca-secret
      #  externalSecretName: existing-ca-secret
      #
      #  # Key in the Secret containing the CA certificate.
      #  certificateKey: ca.crt
      #
      #  ## Local files 'adc apply' puts into the Secret named by ca.secretName.
      #  ## Relative paths are resolved against the config file.
      #  #files:
      #  #  certificatePath: /path/to/ca.pem
    
      ## Controls whether Secret/ConfigMap changes restart pods.
      ## Set enabled: false to update referenced Secrets without restarting
      ## the workload; pods keep running the previous configuration until
      ## the policy is re-enabled. Defaults to enabled.
      #configurationRollout:
      #  enabled: false
    1 Namespace that the Impala cluster will use.
    2 Settings for pulling the Impala cluster image.
    3 Hadoop settings that were taken from the previously created hadoop_conf.yaml.
    4 Ranger configuration.
    5 Additional JCEKS file if Ranger is used along with SSL.

    To generate the JCEKS file, run the following command on a host with Ranger Admin:

    $ java -cp "/usr/lib/ranger-admin/cred/lib/*" org.apache.ranger.credentialapi.buildks create sslTrustStore -value bigdata -provider jceks://file$(pwd)/ranger-impala-gen.jceks
  2. Apply the configuration and deploy the Impala cluster:

    $ ./adc apply -f impala-cluster.yaml

    The expected output contains a confirmation of success:

    time="20260518133858UTC" level="info" msg="cluster impala applied to namespace impala"
  3. Delete old pods so that Impala operator creates new ones from an updated config:

    $ kubectl delete pods -n <impala-cluster-ns> -l app.kubernetes.io/instance=impala-cluster
  4. Verify the Impala cluster pods:

    $ kubectl get pods -n impala

    The expected output is:

    NAME                   READY   STATUS    RESTARTS   AGE
    impala-catalog-0       1/1     Running   0          70m
    impala-coordinator-0   1/1     Running   0          70m
    impala-executor-0      1/1     Running   0          70m
    impala-statestore-0    1/1     Running   0          70m
Found a mistake? Seleсt text and press Ctrl+Enter to report it