Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

[Feature] Apache Ranger Authorization Plugin for HugeGraph

Abierto
#3,272 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

@vaijosh ya está trabajando en esto.

Desde el 5/10/2026.

  • #3273 de @vaijosh — abierto

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
25/100
Tipo de issue
Nueva funcionalidad
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
java

Línea de trabajo

Start with the linked design document and the working RangerPlugin branch, then trace HugeGraphAuthProxy and AuthManager to understand the proposed authorization hook. The issue leaves dependency packaging and hook placement open, so those decisions need resolution before implementation; done would include the optional plugin, Ranger policy checks and audit behavior, and Maven-profile packaging described here.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

feature
Feature Description (功能描述)
Summary

This issue proposes the addition of an optional hugegraph-ranger-plugin module that allows HugeGraph to delegate authorization decisions to [Apache Ranger](https://github.com/apache/hugegraph/discussions/3240) while continuing to use HugeGraph's native store for user identity and credentials.


Motivation

Currently, authorization in HugeGraph is enforced by HugeGraphAuthProxy, which checks operations against a RolePermission object produced by AuthManager (StandardAuthManager or StandardAuthManagerV2).

However, organizations using Apache Ranger to centralize access control across their Hadoop and data infrastructure (HDFS, Hive, HBase, Kafka, Solr) lack a supported way to bring HugeGraph under the same policy umbrella. Ranger provides attribute- and tag-based policies, group-based grants, explicit deny overrides, and centralized auditing.


Non-Goals
  • No Authentication Changes: Does not alter StandardAuthenticator or password/JWT authentication (matchUser, loginUser).
  • No Ranger UI Replication: Existing auth-entity REST APIs (createAccess, createBelong, createTarget, etc.) remain the local record-keeping path.
  • No Sub-Resource Masking: Does not introduce granularity beyond HugeGraph's ResourceObject model (graph space / graph / resource type / label).

Architecture & Design Highlights
  1. Two-Tier Enforcement Model:
  • Tier 1 (Login Level - Coarse): RangerAuthManager.authenticate() delegates credential validation to the local store and merges Ranger grants into RolePermission so per-session caching works unmodified.
  • Tier 2 (Per-Request Level - Fine-Grained): Introduces a ResourceAuthorizer interface hook in hugegraph-core. When registered, verifyResPermission() evaluates requests against live Ranger policies.
  • Tier 2 can only narrow access already granted by Tier 1 local checks—never expand it.
  • Admin requests bypass denial checks (maintaining trust boundaries) but are still recorded in Ranger's audit log.
  • Bulk-Read Sampling: Iterator-based reads are rate-limited per (username, graphSpace, graph, resourceType) to avoid excessive policy calls and log volume.
  1. Ranger Resource Hierarchy:
    A 4-level resource hierarchy is introduced in Ranger for HugeGraph:
    graphspace (e.g., "DEFAULT", "")
    └─ graph (e.g., "hugegraph", "
    ")
    └─ resource-type (VERTEX, EDGE, SCHEMA, GREMLIN, …)
    └─ label (vertex/edge label name, "*")
    Access types directly map to HugeGraph's HugePermission enum (read, write, delete, execute, admin).
  2. Plugin Components (hugegraph-ranger-plugin):
  • RangerHugeGraphAuthenticator: Drop-in auth.authenticator implementation.
  • RangerAuthManager: Delegates identity operations and merges Ranger grants.
  • RangerHugeGraphPlugin: Translates HugeGraph resource requests to Ranger access requests.
  • RangerHugeGraphService: Runs inside Ranger Admin's JVM to power connectivity testing and autocomplete in the policy editor.

Configuration & Packaging
  • Configuration (rest-server.properties):
auth.authenticator = org.apache.hugegraph.ranger.RangerHugeGraphAuthenticator
auth.ranger.service_name = hugegraph
auth.ranger.config = /etc/ranger/hugegraph/ranger-hugegraph-security.xml

  • Build Integration: Opt-in via a Maven profile (-Dwith-ranger-plugin) in hugegraph-dist.

References
Open Questions
  1. Dependency Packaging: Is embedding ranger-plugins-common (and its Hadoop dependency tree) as an opt-in Maven profile (-Dwith-ranger-plugin) acceptable, or should this plugin be maintained in a separate downstream repository?
  2. Hook Placement: Should ResourceAuthorizer live in hugegraph-core (as implemented) or be moved to hugegraph-api alongside HugeGraphAuthProxy?
Lenguaje dominante
Java
Estrellas
3.2k
Forks
641
Merge medio
2 d 9 h
PR fusionados (30 d)
26

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de apache/hugegraph

Todos los issues de apache/hugegraph

Issues similares

Más issues de Java

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.