[Feature] Apache Ranger Authorization Plugin for HugeGraph
Los mantenedores suelen responder en 1 día
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 25/100
- Tipo de issue
- Nueva funcionalidad
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- java
- Área
- authorization, database
Línea de trabajo
Start with the linked design document and the working RangerPlugin branch, then trace HugeGraphAuthProxy and AuthManager to understand the proposed authorization hook. The issue leaves dependency packaging and hook placement open, so those decisions need resolution before implementation; done would include the optional plugin, Ranger policy checks and audit behavior, and Maven-profile packaging described here.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Feature Description (功能描述)
Summary
This issue proposes the addition of an optional hugegraph-ranger-plugin module that allows HugeGraph to delegate authorization decisions to [Apache Ranger](https://github.com/apache/hugegraph/discussions/3240) while continuing to use HugeGraph's native store for user identity and credentials.
Motivation
Currently, authorization in HugeGraph is enforced by HugeGraphAuthProxy, which checks operations against a RolePermission object produced by AuthManager (StandardAuthManager or StandardAuthManagerV2).
However, organizations using Apache Ranger to centralize access control across their Hadoop and data infrastructure (HDFS, Hive, HBase, Kafka, Solr) lack a supported way to bring HugeGraph under the same policy umbrella. Ranger provides attribute- and tag-based policies, group-based grants, explicit deny overrides, and centralized auditing.
Non-Goals
- No Authentication Changes: Does not alter
StandardAuthenticatoror password/JWT authentication (matchUser,loginUser). - No Ranger UI Replication: Existing auth-entity REST APIs (
createAccess,createBelong,createTarget, etc.) remain the local record-keeping path. - No Sub-Resource Masking: Does not introduce granularity beyond HugeGraph's
ResourceObjectmodel (graph space / graph / resource type / label).
Architecture & Design Highlights
- Two-Tier Enforcement Model:
- Tier 1 (Login Level - Coarse):
RangerAuthManager.authenticate()delegates credential validation to the local store and merges Ranger grants intoRolePermissionso per-session caching works unmodified. - Tier 2 (Per-Request Level - Fine-Grained): Introduces a
ResourceAuthorizerinterface hook inhugegraph-core. When registered,verifyResPermission()evaluates requests against live Ranger policies. - Tier 2 can only narrow access already granted by Tier 1 local checks—never expand it.
- Admin requests bypass denial checks (maintaining trust boundaries) but are still recorded in Ranger's audit log.
- Bulk-Read Sampling: Iterator-based reads are rate-limited per
(username, graphSpace, graph, resourceType)to avoid excessive policy calls and log volume.
- Ranger Resource Hierarchy:
A 4-level resource hierarchy is introduced in Ranger for HugeGraph:
graphspace(e.g., "DEFAULT", "")
└─graph(e.g., "hugegraph", "")
└─resource-type(VERTEX, EDGE, SCHEMA, GREMLIN, …)
└─label(vertex/edge label name, "*")
Access types directly map to HugeGraph'sHugePermissionenum (read,write,delete,execute,admin). - Plugin Components (
hugegraph-ranger-plugin):
RangerHugeGraphAuthenticator: Drop-inauth.authenticatorimplementation.RangerAuthManager: Delegates identity operations and merges Ranger grants.RangerHugeGraphPlugin: Translates HugeGraph resource requests to Ranger access requests.RangerHugeGraphService: Runs inside Ranger Admin's JVM to power connectivity testing and autocomplete in the policy editor.
Configuration & Packaging
- Configuration (
rest-server.properties):
auth.authenticator = org.apache.hugegraph.ranger.RangerHugeGraphAuthenticator
auth.ranger.service_name = hugegraph
auth.ranger.config = /etc/ranger/hugegraph/ranger-hugegraph-security.xml
- Build Integration: Opt-in via a Maven profile (
-Dwith-ranger-plugin) inhugegraph-dist.
References
- Design Document: [Google Document](https://docs.google.com/document/d/1j-OITmUTVrsMjTNiUuQVXCyt213lSkdevA50rj5xDr8/edit?usp=sharing)
- Working Implementation: [GitHub Branch - RangerPlugin](https://github.com/vaijosh/hugegraph/tree/RangerPlugin)
Open Questions
- Dependency Packaging: Is embedding
ranger-plugins-common(and its Hadoop dependency tree) as an opt-in Maven profile (-Dwith-ranger-plugin) acceptable, or should this plugin be maintained in a separate downstream repository? - Hook Placement: Should
ResourceAuthorizerlive inhugegraph-core(as implemented) or be moved tohugegraph-apialongsideHugeGraphAuthProxy?
- Lenguaje dominante
- Java
- Estrellas
- 3.2k
- Forks
- 641
- Merge medio
- 2 d 9 h
- PR fusionados (30 d)
- 26
Preparar el entorno
- Sin Dockerfile ni archivo de Docker Compose
- Tiene una plantilla de pull request
- Leer la guía de contribución
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de apache/hugegraph
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 70/100
apache/hugegraph#3231 · 1 comentario ·
Los mantenedores suelen responder en 1 día
-
[Bug] Prometheus metrics format bugQuizá libre de nuevo @cui2022 la tomó hace 60 días y no hay ningún pull request abierto. Abiertobug
Dificultad 2/5 1-3 horas Aptitud para principiantes 64/100
apache/hugegraph#3142 · 7 comentarios ·
Los mantenedores suelen responder en 1 día
-
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
Los mantenedores suelen responder en 1 día
-
[Feature] Let the Server take the initial admin password without a properties-file round tripAbierto
Dificultad 5/5 Más de una semana Aptitud para principiantes 45/100
Los mantenedores suelen responder en 1 día
-
[Bug] Basic auth decodes the credential as ASCII and splits on every colon: a non-ASCII password answers 401, a password with ':' answers 400Posiblemente ocupada @arshilkxwork la tomó hace 1 día. Abierto
Dificultad 1/5 Menos de una hora Aptitud para principiantes 35/100
apache/hugegraph#3284 · 1 comentario ·
Los mantenedores suelen responder en 1 día
Todos los issues de apache/hugegraph
Issues similares
-
[Bug] AI unread message badge counts a batch of new bubbles as one messagePosiblemente ocupada Un pull request vinculado a esta issue está abierto o ya se fusionó. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
apache/rocketmq-dashboard#5784 ·
Los mantenedores suelen responder en 3 días
-
[i18n] 安装实例完成后的成功提示未正确本地化Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
PCL-Community/PCL-CE#3658 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
apache/skywalking#14127 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
Los mantenedores suelen responder en 1 día
-
Team/Identity Server Core Type/Improvement U2
Dificultad 2/5 1-3 horas Aptitud para principiantes 62/100
wso2/product-is#28553 ·
Los mantenedores suelen responder en 1 día