[Feature] Apache Ranger Authorization Plugin for HugeGraph
Maintainer thường phản hồi trong vòng 1 ngày
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 25/100
- Loại issue
- Tính năng
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Sôi nổi
- Công nghệ
- java
- Lĩnh vực
- authorization, database
Hướng nghiên cứu
Start with the linked design document and the working RangerPlugin branch, then trace HugeGraphAuthProxy and AuthManager to understand the proposed authorization hook. The issue leaves dependency packaging and hook placement open, so those decisions need resolution before implementation; done would include the optional plugin, Ranger policy checks and audit behavior, and Maven-profile packaging described here.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Feature Description (功能描述)
Summary
This issue proposes the addition of an optional hugegraph-ranger-plugin module that allows HugeGraph to delegate authorization decisions to [Apache Ranger](https://github.com/apache/hugegraph/discussions/3240) while continuing to use HugeGraph's native store for user identity and credentials.
Motivation
Currently, authorization in HugeGraph is enforced by HugeGraphAuthProxy, which checks operations against a RolePermission object produced by AuthManager (StandardAuthManager or StandardAuthManagerV2).
However, organizations using Apache Ranger to centralize access control across their Hadoop and data infrastructure (HDFS, Hive, HBase, Kafka, Solr) lack a supported way to bring HugeGraph under the same policy umbrella. Ranger provides attribute- and tag-based policies, group-based grants, explicit deny overrides, and centralized auditing.
Non-Goals
- No Authentication Changes: Does not alter
StandardAuthenticatoror password/JWT authentication (matchUser,loginUser). - No Ranger UI Replication: Existing auth-entity REST APIs (
createAccess,createBelong,createTarget, etc.) remain the local record-keeping path. - No Sub-Resource Masking: Does not introduce granularity beyond HugeGraph's
ResourceObjectmodel (graph space / graph / resource type / label).
Architecture & Design Highlights
- Two-Tier Enforcement Model:
- Tier 1 (Login Level - Coarse):
RangerAuthManager.authenticate()delegates credential validation to the local store and merges Ranger grants intoRolePermissionso per-session caching works unmodified. - Tier 2 (Per-Request Level - Fine-Grained): Introduces a
ResourceAuthorizerinterface hook inhugegraph-core. When registered,verifyResPermission()evaluates requests against live Ranger policies. - Tier 2 can only narrow access already granted by Tier 1 local checks—never expand it.
- Admin requests bypass denial checks (maintaining trust boundaries) but are still recorded in Ranger's audit log.
- Bulk-Read Sampling: Iterator-based reads are rate-limited per
(username, graphSpace, graph, resourceType)to avoid excessive policy calls and log volume.
- Ranger Resource Hierarchy:
A 4-level resource hierarchy is introduced in Ranger for HugeGraph:
graphspace(e.g., "DEFAULT", "")
└─graph(e.g., "hugegraph", "")
└─resource-type(VERTEX, EDGE, SCHEMA, GREMLIN, …)
└─label(vertex/edge label name, "*")
Access types directly map to HugeGraph'sHugePermissionenum (read,write,delete,execute,admin). - Plugin Components (
hugegraph-ranger-plugin):
RangerHugeGraphAuthenticator: Drop-inauth.authenticatorimplementation.RangerAuthManager: Delegates identity operations and merges Ranger grants.RangerHugeGraphPlugin: Translates HugeGraph resource requests to Ranger access requests.RangerHugeGraphService: Runs inside Ranger Admin's JVM to power connectivity testing and autocomplete in the policy editor.
Configuration & Packaging
- Configuration (
rest-server.properties):
auth.authenticator = org.apache.hugegraph.ranger.RangerHugeGraphAuthenticator
auth.ranger.service_name = hugegraph
auth.ranger.config = /etc/ranger/hugegraph/ranger-hugegraph-security.xml
- Build Integration: Opt-in via a Maven profile (
-Dwith-ranger-plugin) inhugegraph-dist.
References
- Design Document: [Google Document](https://docs.google.com/document/d/1j-OITmUTVrsMjTNiUuQVXCyt213lSkdevA50rj5xDr8/edit?usp=sharing)
- Working Implementation: [GitHub Branch - RangerPlugin](https://github.com/vaijosh/hugegraph/tree/RangerPlugin)
Open Questions
- Dependency Packaging: Is embedding
ranger-plugins-common(and its Hadoop dependency tree) as an opt-in Maven profile (-Dwith-ranger-plugin) acceptable, or should this plugin be maintained in a separate downstream repository? - Hook Placement: Should
ResourceAuthorizerlive inhugegraph-core(as implemented) or be moved tohugegraph-apialongsideHugeGraphAuthProxy?
- Ngôn ngữ chính
- Java
- Star
- 3.2k
- Fork
- 640
- Merge trung bình
- 3 ngày 9 giờ
- Pull request đã merge (30 ngày)
- 22
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của apache/hugegraph
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 70/100
apache/hugegraph#3231 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
bug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 64/100
apache/hugegraph#3142 · 7 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug] HStore Server image (`hugegraph/server`) keeps crash diagnostics only inside the container, so a restart on Kubernetes loses themCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
Maintainer thường phản hồi trong vòng 1 ngày
-
[Bug] Store IpUtil.getNearestAddress logs ERROR for hostname addresses and can return 127.0.0.1Đang mở
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 52/100
apache/hugegraph#3254 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của apache/hugegraph
Issue tương tự
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
-
Make branch and label autocomplete matching locale-independentCó thể đã có người làm Có pull request liên kết đang mở hoặc đã được merge. Đang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 83/100
jenkinsci/gitlab-plugin#1950 ·
-
Place type search does not workĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 65/100
commons-app/apps-android-commons#6984 ·
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
Maintainer thường phản hồi trong vòng 1 ngày
-
It's not necessary to copy the memory block in the readWrite() of org.h2.store.fs.mem.FileMemDataĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
h2database/h2database#4435 ·
Maintainer thường phản hồi trong vòng 1 ngày