Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

[Feature] Apache Ranger Authorization Plugin for HugeGraph

Aperta
#3,272 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

@vaijosh ci sta già lavorando.

Dal 5/10/2026.

  • #3273 di @vaijosh — aperta

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
25/100
Tipo di issue
Funzionalità
Chiarezza
Abbastanza chiara
Stato di attività
Attiva
Stack tecnologico
java

Direzione di ricerca

Start with the linked design document and the working RangerPlugin branch, then trace HugeGraphAuthProxy and AuthManager to understand the proposed authorization hook. The issue leaves dependency packaging and hook placement open, so those decisions need resolution before implementation; done would include the optional plugin, Ranger policy checks and audit behavior, and Maven-profile packaging described here.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

feature
Feature Description (功能描述)
Summary

This issue proposes the addition of an optional hugegraph-ranger-plugin module that allows HugeGraph to delegate authorization decisions to [Apache Ranger](https://github.com/apache/hugegraph/discussions/3240) while continuing to use HugeGraph's native store for user identity and credentials.


Motivation

Currently, authorization in HugeGraph is enforced by HugeGraphAuthProxy, which checks operations against a RolePermission object produced by AuthManager (StandardAuthManager or StandardAuthManagerV2).

However, organizations using Apache Ranger to centralize access control across their Hadoop and data infrastructure (HDFS, Hive, HBase, Kafka, Solr) lack a supported way to bring HugeGraph under the same policy umbrella. Ranger provides attribute- and tag-based policies, group-based grants, explicit deny overrides, and centralized auditing.


Non-Goals
  • No Authentication Changes: Does not alter StandardAuthenticator or password/JWT authentication (matchUser, loginUser).
  • No Ranger UI Replication: Existing auth-entity REST APIs (createAccess, createBelong, createTarget, etc.) remain the local record-keeping path.
  • No Sub-Resource Masking: Does not introduce granularity beyond HugeGraph's ResourceObject model (graph space / graph / resource type / label).

Architecture & Design Highlights
  1. Two-Tier Enforcement Model:
  • Tier 1 (Login Level - Coarse): RangerAuthManager.authenticate() delegates credential validation to the local store and merges Ranger grants into RolePermission so per-session caching works unmodified.
  • Tier 2 (Per-Request Level - Fine-Grained): Introduces a ResourceAuthorizer interface hook in hugegraph-core. When registered, verifyResPermission() evaluates requests against live Ranger policies.
  • Tier 2 can only narrow access already granted by Tier 1 local checks—never expand it.
  • Admin requests bypass denial checks (maintaining trust boundaries) but are still recorded in Ranger's audit log.
  • Bulk-Read Sampling: Iterator-based reads are rate-limited per (username, graphSpace, graph, resourceType) to avoid excessive policy calls and log volume.
  1. Ranger Resource Hierarchy:
    A 4-level resource hierarchy is introduced in Ranger for HugeGraph:
    graphspace (e.g., "DEFAULT", "")
    └─ graph (e.g., "hugegraph", "
    ")
    └─ resource-type (VERTEX, EDGE, SCHEMA, GREMLIN, …)
    └─ label (vertex/edge label name, "*")
    Access types directly map to HugeGraph's HugePermission enum (read, write, delete, execute, admin).
  2. Plugin Components (hugegraph-ranger-plugin):
  • RangerHugeGraphAuthenticator: Drop-in auth.authenticator implementation.
  • RangerAuthManager: Delegates identity operations and merges Ranger grants.
  • RangerHugeGraphPlugin: Translates HugeGraph resource requests to Ranger access requests.
  • RangerHugeGraphService: Runs inside Ranger Admin's JVM to power connectivity testing and autocomplete in the policy editor.

Configuration & Packaging
  • Configuration (rest-server.properties):
auth.authenticator = org.apache.hugegraph.ranger.RangerHugeGraphAuthenticator
auth.ranger.service_name = hugegraph
auth.ranger.config = /etc/ranger/hugegraph/ranger-hugegraph-security.xml

  • Build Integration: Opt-in via a Maven profile (-Dwith-ranger-plugin) in hugegraph-dist.

References
Open Questions
  1. Dependency Packaging: Is embedding ranger-plugins-common (and its Hadoop dependency tree) as an opt-in Maven profile (-Dwith-ranger-plugin) acceptable, or should this plugin be maintained in a separate downstream repository?
  2. Hook Placement: Should ResourceAuthorizer live in hugegraph-core (as implemented) or be moved to hugegraph-api alongside HugeGraphAuthProxy?
Lingua principale
Java
Stelle
3.2k
Fork
640
Merge medio
3g 9h
PR unite (30g)
22

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di apache/hugegraph

Tutte le issue di apache/hugegraph

Issue simili

Altre issue su Java

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.