Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

[Feature] Apache Ranger Authorization Plugin for HugeGraph

Đang mở
#3,272 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Maintainer thường phản hồi trong vòng 1 ngày

@vaijosh đang làm issue này rồi.

Từ ngày 5/10/2026.

  • #3273 của @vaijosh — đang mở

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
25/100
Loại issue
Tính năng
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Sôi nổi
Công nghệ
java
Lĩnh vực
authorization, database

Hướng nghiên cứu

Start with the linked design document and the working RangerPlugin branch, then trace HugeGraphAuthProxy and AuthManager to understand the proposed authorization hook. The issue leaves dependency packaging and hook placement open, so those decisions need resolution before implementation; done would include the optional plugin, Ranger policy checks and audit behavior, and Maven-profile packaging described here.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

feature
Feature Description (功能描述)
Summary

This issue proposes the addition of an optional hugegraph-ranger-plugin module that allows HugeGraph to delegate authorization decisions to [Apache Ranger](https://github.com/apache/hugegraph/discussions/3240) while continuing to use HugeGraph's native store for user identity and credentials.


Motivation

Currently, authorization in HugeGraph is enforced by HugeGraphAuthProxy, which checks operations against a RolePermission object produced by AuthManager (StandardAuthManager or StandardAuthManagerV2).

However, organizations using Apache Ranger to centralize access control across their Hadoop and data infrastructure (HDFS, Hive, HBase, Kafka, Solr) lack a supported way to bring HugeGraph under the same policy umbrella. Ranger provides attribute- and tag-based policies, group-based grants, explicit deny overrides, and centralized auditing.


Non-Goals
  • No Authentication Changes: Does not alter StandardAuthenticator or password/JWT authentication (matchUser, loginUser).
  • No Ranger UI Replication: Existing auth-entity REST APIs (createAccess, createBelong, createTarget, etc.) remain the local record-keeping path.
  • No Sub-Resource Masking: Does not introduce granularity beyond HugeGraph's ResourceObject model (graph space / graph / resource type / label).

Architecture & Design Highlights
  1. Two-Tier Enforcement Model:
  • Tier 1 (Login Level - Coarse): RangerAuthManager.authenticate() delegates credential validation to the local store and merges Ranger grants into RolePermission so per-session caching works unmodified.
  • Tier 2 (Per-Request Level - Fine-Grained): Introduces a ResourceAuthorizer interface hook in hugegraph-core. When registered, verifyResPermission() evaluates requests against live Ranger policies.
  • Tier 2 can only narrow access already granted by Tier 1 local checks—never expand it.
  • Admin requests bypass denial checks (maintaining trust boundaries) but are still recorded in Ranger's audit log.
  • Bulk-Read Sampling: Iterator-based reads are rate-limited per (username, graphSpace, graph, resourceType) to avoid excessive policy calls and log volume.
  1. Ranger Resource Hierarchy:
    A 4-level resource hierarchy is introduced in Ranger for HugeGraph:
    graphspace (e.g., "DEFAULT", "")
    └─ graph (e.g., "hugegraph", "
    ")
    └─ resource-type (VERTEX, EDGE, SCHEMA, GREMLIN, …)
    └─ label (vertex/edge label name, "*")
    Access types directly map to HugeGraph's HugePermission enum (read, write, delete, execute, admin).
  2. Plugin Components (hugegraph-ranger-plugin):
  • RangerHugeGraphAuthenticator: Drop-in auth.authenticator implementation.
  • RangerAuthManager: Delegates identity operations and merges Ranger grants.
  • RangerHugeGraphPlugin: Translates HugeGraph resource requests to Ranger access requests.
  • RangerHugeGraphService: Runs inside Ranger Admin's JVM to power connectivity testing and autocomplete in the policy editor.

Configuration & Packaging
  • Configuration (rest-server.properties):
auth.authenticator = org.apache.hugegraph.ranger.RangerHugeGraphAuthenticator
auth.ranger.service_name = hugegraph
auth.ranger.config = /etc/ranger/hugegraph/ranger-hugegraph-security.xml

  • Build Integration: Opt-in via a Maven profile (-Dwith-ranger-plugin) in hugegraph-dist.

References
Open Questions
  1. Dependency Packaging: Is embedding ranger-plugins-common (and its Hadoop dependency tree) as an opt-in Maven profile (-Dwith-ranger-plugin) acceptable, or should this plugin be maintained in a separate downstream repository?
  2. Hook Placement: Should ResourceAuthorizer live in hugegraph-core (as implemented) or be moved to hugegraph-api alongside HugeGraphAuthProxy?
Ngôn ngữ chính
Java
Star
3.2k
Fork
640
Merge trung bình
3 ngày 9 giờ
Pull request đã merge (30 ngày)
22

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của apache/hugegraph

Tất cả issue của apache/hugegraph

Issue tương tự

Thêm issue về Java

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.