[Feature] Apache Ranger Authorization Plugin for HugeGraph
I maintainer di solito rispondono entro 1 giorno
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 25/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- java
- Ambito
- authorization, database
Direzione di ricerca
Start with the linked design document and the working RangerPlugin branch, then trace HugeGraphAuthProxy and AuthManager to understand the proposed authorization hook. The issue leaves dependency packaging and hook placement open, so those decisions need resolution before implementation; done would include the optional plugin, Ranger policy checks and audit behavior, and Maven-profile packaging described here.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Feature Description (功能描述)
Summary
This issue proposes the addition of an optional hugegraph-ranger-plugin module that allows HugeGraph to delegate authorization decisions to [Apache Ranger](https://github.com/apache/hugegraph/discussions/3240) while continuing to use HugeGraph's native store for user identity and credentials.
Motivation
Currently, authorization in HugeGraph is enforced by HugeGraphAuthProxy, which checks operations against a RolePermission object produced by AuthManager (StandardAuthManager or StandardAuthManagerV2).
However, organizations using Apache Ranger to centralize access control across their Hadoop and data infrastructure (HDFS, Hive, HBase, Kafka, Solr) lack a supported way to bring HugeGraph under the same policy umbrella. Ranger provides attribute- and tag-based policies, group-based grants, explicit deny overrides, and centralized auditing.
Non-Goals
- No Authentication Changes: Does not alter
StandardAuthenticatoror password/JWT authentication (matchUser,loginUser). - No Ranger UI Replication: Existing auth-entity REST APIs (
createAccess,createBelong,createTarget, etc.) remain the local record-keeping path. - No Sub-Resource Masking: Does not introduce granularity beyond HugeGraph's
ResourceObjectmodel (graph space / graph / resource type / label).
Architecture & Design Highlights
- Two-Tier Enforcement Model:
- Tier 1 (Login Level - Coarse):
RangerAuthManager.authenticate()delegates credential validation to the local store and merges Ranger grants intoRolePermissionso per-session caching works unmodified. - Tier 2 (Per-Request Level - Fine-Grained): Introduces a
ResourceAuthorizerinterface hook inhugegraph-core. When registered,verifyResPermission()evaluates requests against live Ranger policies. - Tier 2 can only narrow access already granted by Tier 1 local checks—never expand it.
- Admin requests bypass denial checks (maintaining trust boundaries) but are still recorded in Ranger's audit log.
- Bulk-Read Sampling: Iterator-based reads are rate-limited per
(username, graphSpace, graph, resourceType)to avoid excessive policy calls and log volume.
- Ranger Resource Hierarchy:
A 4-level resource hierarchy is introduced in Ranger for HugeGraph:
graphspace(e.g., "DEFAULT", "")
└─graph(e.g., "hugegraph", "")
└─resource-type(VERTEX, EDGE, SCHEMA, GREMLIN, …)
└─label(vertex/edge label name, "*")
Access types directly map to HugeGraph'sHugePermissionenum (read,write,delete,execute,admin). - Plugin Components (
hugegraph-ranger-plugin):
RangerHugeGraphAuthenticator: Drop-inauth.authenticatorimplementation.RangerAuthManager: Delegates identity operations and merges Ranger grants.RangerHugeGraphPlugin: Translates HugeGraph resource requests to Ranger access requests.RangerHugeGraphService: Runs inside Ranger Admin's JVM to power connectivity testing and autocomplete in the policy editor.
Configuration & Packaging
- Configuration (
rest-server.properties):
auth.authenticator = org.apache.hugegraph.ranger.RangerHugeGraphAuthenticator
auth.ranger.service_name = hugegraph
auth.ranger.config = /etc/ranger/hugegraph/ranger-hugegraph-security.xml
- Build Integration: Opt-in via a Maven profile (
-Dwith-ranger-plugin) inhugegraph-dist.
References
- Design Document: [Google Document](https://docs.google.com/document/d/1j-OITmUTVrsMjTNiUuQVXCyt213lSkdevA50rj5xDr8/edit?usp=sharing)
- Working Implementation: [GitHub Branch - RangerPlugin](https://github.com/vaijosh/hugegraph/tree/RangerPlugin)
Open Questions
- Dependency Packaging: Is embedding
ranger-plugins-common(and its Hadoop dependency tree) as an opt-in Maven profile (-Dwith-ranger-plugin) acceptable, or should this plugin be maintained in a separate downstream repository? - Hook Placement: Should
ResourceAuthorizerlive inhugegraph-core(as implemented) or be moved tohugegraph-apialongsideHugeGraphAuthProxy?
- Lingua principale
- Java
- Stelle
- 3.2k
- Fork
- 640
- Merge medio
- 3g 9h
- PR unite (30g)
- 22
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di apache/hugegraph
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 70/100
apache/hugegraph#3231 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 64/100
apache/hugegraph#3142 · 7 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
[Bug] HStore Server image (`hugegraph/server`) keeps crash diagnostics only inside the container, so a restart on Kubernetes loses themForse già presa Una pull request collegata a questa issue è aperta o già unita. Aperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
I maintainer di solito rispondono entro 1 giorno
-
[Bug] Store IpUtil.getNearestAddress logs ERROR for hostname addresses and can return 127.0.0.1Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 52/100
apache/hugegraph#3254 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di apache/hugegraph
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 83/100
jenkinsci/gitlab-plugin#1950 ·
-
It's not necessary to copy the memory block in the readWrite() of org.h2.store.fs.mem.FileMemDataAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
h2database/h2database#4435 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
micronaut-projects/micronaut-core#13717 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
ADORSYS-GIS/token-status-link#145 ·
I maintainer di solito rispondono entro 3 giorni
-
enhancement
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 88/100
helidon-io/helidon#12721 ·
I maintainer di solito rispondono entro 1 giorno