Настройка Ranger для Impala в Kubernetes с помощью CLI
Требования
-
Установленный и функционирующий кластер ADPS версии 2.0.0 или более поздней.
-
Установленный и функционирующий кластер ADH версии 4.2.0 или более поздней.
-
Кластер Impala, установленный согласно инструкции.
Шаг 1. Создание сервиса в Ranger
На данном шаге описывается создание сервиса с помощью REST API Ranger. Вы также можете создать сервис в веб-интерфейсе Ranger.
-
Создайте конфигурацию сервиса в JSON-файле:
ranger-impala-k8s.json{ "isEnabled": true, "type": "hive", "name": "impala_k8s", (1) "displayName": "impala_k8s", "description": "Service for Kubernetes Impala", "configs": { "username": "impala", (2) "password": "bigdata", (3) "ranger.plugin.audit.filters": "[ {'accessResult': 'DENIED', 'isAudited': true}, {'actions':['METADATA OPERATION'], 'isAudited': false}, {'users':['hive','hue'],'actions':['SHOW_ROLES'],'isAudited':false} ]", "jdbc.driverClassName": "org.apache.hive.jdbc.HiveDriver", "jdbc.url": "jdbc:impala://10.92.41.149:21050" (4) } }1 Наименование сервиса Impala в Ranger. Данное имя должно быть уникальным. 2 Имя пользователя для сервиса. 3 Пароль для сервиса. 4 JDBC-строка подключения к Impala, предоставляемая балансировщиком нагрузки. -
Загрузите конфигурацию сервиса в Ranger:
$ curl -u admin:<admin_pwd> -H "Content-Type: application/json" -X POST -d @ranger-impala-k8s.json http://<ranger-admin>:6080/service/public/v2/api/service
Шаг 2. Обновление конфигурации кластера Impala
-
Отредактируйте конфигурационный файл impala-cluster.yaml, добавив блок настроек Ranger:
impala-cluster.yamlapiVersion: adc.arenadata.io/v1alpha1 kind: ImpalaCluster metadata: name: impala namespace: impala (1) spec: image: hub.arenadata.io/adc-enterprise/impala:<tag> (2) ## Image pull secret for a private registry. ## Set 'externalSecretName' to reference an existing Secret, ## or set 'credentials' and optionally 'secretName' to let the CLI create one. #imagePullSecret: # # Use a Secret managed outside ADC. # externalSecretName: existing-registry-secret # # ## Or let ADC create the Secret. # #secretName: custom-registry-secret # # #credentials: # # registry: registry.example.com # # username: user # # password: pass hadoop: (3) core: dfs.client.failover.proxy.provider.adh: org.apache.hadoop.hdfs.server.namenode.ha.ObserverReadProxyProvider dfs.ha.namenodes.adh: nn_tsn-adh-k8s-1,nn_tsn-adh-k8s-3 dfs.namenode.rpc-address.adh.nn_tsn-adh-k8s-1: tsn-adh-k8s-1.ru-central1.internal:8020 dfs.namenode.rpc-address.adh.nn_tsn-adh-k8s-3: tsn-adh-k8s-3.ru-central1.internal:8020 dfs.nameservices: adh fs.defaultFS: hdfs://adh hadoop.security.authentication: simple hdfs: dfs.client.read.shortcircuit: "false" hive: hive.metastore.sasl.enabled: "false" hive.metastore.uris: thrift://tsn-adh-k8s-1.ru-central1.internal:9083 metastore.use.SSL: "false" ozone: ozone.om.address.adh.om_tsn-adh-k8s-1: tsn-adh-k8s-1.ru-central1.internal:9862 ozone.om.address.adh.om_tsn-adh-k8s-2: tsn-adh-k8s-2.ru-central1.internal:9862 ozone.om.address.adh.om_tsn-adh-k8s-3: tsn-adh-k8s-3.ru-central1.internal:9862 ozone.om.nodes.adh: om_tsn-adh-k8s-1,om_tsn-adh-k8s-2,om_tsn-adh-k8s-3 ozone.om.service.ids: adhom ## Kerberos configuration for authentication. #kerberos: # realm: EXAMPLE.COM # # # Service name in the Kerberos principal. Defaults to the product name. # service: impala # # # Hostname in the Kerberos principal. # # Required for a fixed service principal; leave it empty only to derive one principal per pod from the cluster domain. # hostname: kerberos.example.com # keytab: # # true - kerberos-operator creates the keytab Secret. # # false (default) - reference an existing keytab Secret with name keytab.secretName. # create: false # # # Name of the keytab Secret. # # Optional when create: true - names the generated Secret (default: <name>-keytab). # # Required when create: false - must reference an existing Secret. # secretName: kerberos-secret # # # Label selector for the Pod that generates the keytab. # # Required when create: true; ignored when create: false. # labelSelector: # env: prod # #additionalPrincipals: # # - HTTP/kerberos.example.com # # clusterDomain: cluster.local # rotation: # interval: 24h # checkInterval: 1h ## LDAP authentication configuration. ## Uncomment and fill url and userBindPattern. ## For ldaps:// URLs the ssl: or ca: section must also be configured (depends on product) #ldap: # # LDAP service url. # url: ldaps://ldap.example.com:636 # # # LDAP user Bind pattern. # userBindPattern: uid=#UID,cn=users,dc=example,dc=com ## Ranger plugin configuration. ## Uncomment and fill the lines below. adc apply derives the rest. ranger: (4) # # fill ranger.plugin.impala.policy.rest.url below with Ranger endpoint, e.g. https://adps-adc.ru-central1.internal:6182 # # fill ranger.plugin.impala.service.name below with Ranger service name you want to use for product, e.g. adc_impala_id_1 security: ranger.plugin.impala.policy.rest.url: "<ranger-admin>:6080" ranger.plugin.impala.service.name: "impala_k8s" ranger.plugin.impala.use.rangerGroups: "True" ranger.plugin.impala.use.only.rangerGroups: "True" # # # fill xasecure.audit.destination.solr.zookeepers below with Zookeepers endpoints to resolve solr service, e.g. adps-adc.ru-central1.internal:2181/Arenadata.Hadoop-2.solr.server audit: xasecure.audit.destination.solr.zookeepers: "tsn-adps2-1.ru-central1.internal:2181/Arenadata.Hadoop-3.solr.server" # # # Local Ranger files 'adc apply' writes into the configs Secret. # # Relative paths are resolved against the config file. files: (5) jceksStorePath: /tmp/impala_minimal/ranger-impala.jceks ## Java KeyStore/TrustStore certificate configuration. ## Set externalSecretName to reference an existing Secret, ## or set files and optional secretName to have ADC create it. #ssl: # ## Name of the Secret containing Java keystores. # #secretName: custom-ssl-secret # externalSecretName: existing-ssl-secret # # # Key in the Secret containing the truststore file. # trustStoreKey: truststore.jks # # ## Password for the truststore (optional). # #trustStorePassword: bigdata # # ## Key in the Secret containing the keystore file (optional). # #keyStoreKey: keystore.jks # # ## Password for the keystore (optional). # #keyStorePassword: bigdata # # ## Local files 'adc apply' puts into the Secret named by ssl.secretName. # ## Relative paths are resolved against the config file. # #files: # # trustStorePath: /path/to/truststore.jks # # #keyStorePath: /path/to/keystore.jks ## Use an external complete configs Secret instead of the one rendered by ADC. #configsSecret: # # Use a Secret managed outside ADC. # externalSecretName: existing-impala-configs # # ## Or let ADC create the Secret. # #secretName: custom-impala-configs catalog: replicas: 1 #resources: # limits: # cpu: "2" # memory: 8Gi # requests: # cpu: 300m # memory: 384Mi ## Component arguments. Key-value pairs passed to the component configuration. #args: # redirect_stdout_stderr: "false" ## Environment variables passed to the component container. #envs: # - name: JAVA_TOOL_OPTIONS # value: |- # -Djavax.net.ssl.trustStore=/etc/ssl/truststore.jks # -Djavax.net.ssl.trustStorePassword=bigdata coordinator: replicas: 1 #resources: # limits: # cpu: "2" # memory: 8Gi # requests: # cpu: 300m # memory: 384Mi ## Component arguments. Key-value pairs passed to the component configuration. #args: # redirect_stdout_stderr: "false" ## Environment variables passed to the component container. #envs: # - name: JAVA_TOOL_OPTIONS # value: |- # -Djavax.net.ssl.trustStore=/etc/ssl/truststore.jks # -Djavax.net.ssl.trustStorePassword=bigdata executor: replicas: 1 #resources: # limits: # cpu: "2" # memory: 8Gi # requests: # cpu: 300m # memory: 384Mi ## Component arguments. Key-value pairs passed to the component configuration. #args: # redirect_stdout_stderr: "false" ## Environment variables passed to the component container. #envs: # - name: JAVA_TOOL_OPTIONS # value: |- # -Djavax.net.ssl.trustStore=/etc/ssl/truststore.jks # -Djavax.net.ssl.trustStorePassword=bigdata statestore: replicas: 1 #resources: # limits: # cpu: "2" # memory: 8Gi # requests: # cpu: 300m # memory: 384Mi ## Component arguments. Key-value pairs passed to the component configuration. #args: # redirect_stdout_stderr: "false" ## Environment variables passed to the component container. #envs: # - name: JAVA_TOOL_OPTIONS # value: |- # -Djavax.net.ssl.trustStore=/etc/ssl/truststore.jks # -Djavax.net.ssl.trustStorePassword=bigdata ## Monitoring configuration. #monitoring: # # Enables Prometheus metrics export from this product's pods. # exportMetrics: true ## Admission-control resource pools. Rendered into a coordinator-only Secret (fair-scheduler.xml and optional llama-site.xml) mounted at /opt/impala/resource-pools. #resourcePools: # # Fair-scheduler queue tree and placement policy, rendered to fair-scheduler.xml. # allocations: # # Queue tree, rooted at a single queue. # queues: # - aclSubmitApps: ' ' # name: root # queues: # - aclSubmitApps: '*' # maxResources: # memory: 50000 # vcores: 0 # name: default # type: leaf # type: parent # # # Rules that route an incoming query to a queue. # queuePlacementPolicy: # rules: # - create: false # name: specified # - name: default # # # Raw llama-site.xml properties, rendered verbatim in list order. # llamaProperties: # # List of name/value pairs written to llama-site.xml. # properties: # - name: llama.am.throttling.maximum.placed.reservations.root.default # value: "10" ## TLS certificate configuration. ## Set externalSecretName to reference an existing Secret, ## or set files and optional secretName to have ADC create it. #tls: # ## Optional name of the Secret ADC creates from local files. # #secretName: custom-tls-secret # externalSecretName: existing-tls-secret # # # Key in the Secret containing the TLS certificate. # certificateKey: tls.crt # # # Key in the Secret containing the TLS private key. # privateKey: tls.key # # ## Key in the Secret containing the client CA certificate. # #clientCaCertificate: ca.crt # # ## Local files 'adc apply' puts into the Secret named by tls.secretName. # ## Relative paths are resolved against the config file. # #files: # # certificatePath: /path/to/tls.crt # # privateKeyPath: /path/to/tls.key # # #clientCaCertificatePath: /path/to/ca.crt ## TLS certificate configuration for web UI and HTTP endpoints. ## Set externalSecretName to reference an existing Secret, ## or set files and optional secretName to have ADC create it. #webTLS: # ## Optional name of the Secret ADC creates from local files. # #secretName: custom-web-tls-secret # externalSecretName: existing-web-tls-secret # # # Key in the Secret containing the web TLS certificate. # certificateKey: tls.crt # # # Key in the Secret containing the web TLS private key. # privateKey: tls.key # # ## Local files 'adc apply' puts into the Secret named by webTLS.secretName. # ## Relative paths are resolved against the config file. # #files: # # certificatePath: /path/to/tls.crt # # privateKeyPath: /path/to/tls.key ## CA certificate configuration for Impala. ## Set externalSecretName, or let ADC create a Secret from files. #ca: # ## Optional name of the Secret ADC creates from a local file. # #secretName: custom-ca-secret # externalSecretName: existing-ca-secret # # # Key in the Secret containing the CA certificate. # certificateKey: ca.crt # # ## Local files 'adc apply' puts into the Secret named by ca.secretName. # ## Relative paths are resolved against the config file. # #files: # # certificatePath: /path/to/ca.pem ## Controls whether Secret/ConfigMap changes restart pods. ## Set enabled: false to update referenced Secrets without restarting ## the workload; pods keep running the previous configuration until ## the policy is re-enabled. Defaults to enabled. #configurationRollout: # enabled: false1 Пространство имен, используемое кластером Impala. 2 Настройки для загрузки образа кластера Impala. 3 Настройки Hadoop, взятые из ранее созданного файла hadoop_conf.yaml. 4 Настройки Ranger. 5 JCEKS-файл, если Ranger используется вместе с SSL. Чтобы сгенерировать JCEKS-файл, запустите следующую команду на хосте с Ranger Admin:
$ java -cp "/usr/lib/ranger-admin/cred/lib/*" org.apache.ranger.credentialapi.buildks create sslTrustStore -value bigdata -provider jceks://file$(pwd)/ranger-impala-gen.jceks -
Примените конфигурацию и разверните кластер Impala:
$ ./adc apply -f impala-cluster.yamlОжидаемый вывод содержит сообщение с подтверждением успеха:
time="20260518133858UTC" level="info" msg="cluster impala applied to namespace impala"
-
Удалите старые поды кластера, чтобы оператор Impala создал новые с обновленной конфигурацией:
$ kubectl delete pods -n <impala-cluster-ns> -l app.kubernetes.io/instance=impala-cluster -
Проверьте работоспособность подов кластера Impala:
$ kubectl get pods -n impalaОжидаемый вывод должен быть похож на следующий:
NAME READY STATUS RESTARTS AGE impala-catalog-0 1/1 Running 0 70m impala-coordinator-0 1/1 Running 0 70m impala-executor-0 1/1 Running 0 70m impala-statestore-0 1/1 Running 0 70m