±à¼ÍƼö: |
±¾ÎÄÖ÷Òª½éÉÜÁËhive
ÊÚȨÁ÷³Ì¡¢ranger Óû§´´½¨Á÷³Ì¡¢Óû§É¾³ý¡¢´´½¨²ßÂÔ¡¢É¾³ý²ßÂÔ¡¢¸üвßÂÔµÈÏà¹ØÄÚÈÝ¡£
±¾ÎÄÀ´×Ôcsdn£¬ÓÉ»ðÁú¹ûÈí¼þAnna±à¼¡¢ÍƼö¡£ |
|
1.hive ÊÚȨÁ÷³Ì
(1) ¹ÜÀíÔ±ÉèÖòßÂÔÒÔ¼°Óû§(ÀýÈçÒ»¸öÓû§¶ÔÒ»¸öhiveÊý¾Ý¿âÏà¹ØµÄȨÏÞ£©
(2) Óû§Í¨¹ý jdbc beeline È¥ÇëÇóHiveServe2
(3)hive ȨÏÞcheck£¬ ÇëÇóranger api »ñÈ¡²ßÂÔÊÇ·ñÒѾ¸üУ¬¸üÐÂÁ˾ÍÀûÓÃеIJßÂÔ£¬Èç¹ûûÓиüÐÂÀûÓñ¾µØ»º´æÊý¾Ý£¬
plugin »á30 Ãë·ÃÎÊranger·þÎñ ¸üвßÂÔ
(4) hiveserver2 ¿ÉÒÔͨ¹ýgrant ºÍ revoke È¥ÇëÇó ranger ·þÎñ
È¥¸üвßÂÔ
(5) check ºÍ grant ºÍ revoke ²Ù×÷¼Ç¼ »á·Åµ½ranger µÄaudit
Éó¼ÆÈÕÖ¾Àï¡£
2. ranger Óû§´´½¨Á÷³Ì


Ö÷Òª²½Ö裺(1) check ÊÇ·ñÓÐadmin µÄȨÏÞ ºÍ ´´½¨µÄÓû§Êý¾Ý¼ìÑé
(2) ³õʼ»¯XPortalUser ºÍ XUser Á½¸öÊý¾Ý½á¹¹¶ÔÓ¦Êý¾Ý¿â x_portal_user,
x_user,
(3) Èç¹ûÓÐÓû§×éÐÅÏ¢£¬ ½«ÐÅÏ¢¼ÓÈëµ½ Êý¾Ý¿â x_group_users ÖÐ
(4) ½«²Ù×÷µÄÈÕÖ¾XXTRxLog дÈëÊý¾Ý¿â x_trx_log
(5) ͨ¹ýXPortalUser Óû§µÄ½ÇÉ« ¸üÐÂÓû§µÄÄ£¿éȨÏÞ £¬Êý¾Ý¿â¶ÔÓ¦x_user_module_perm
3. Óû§É¾³ý
http://172.24.5.149: 6080/service/xusers/secure/users/delete?
forceDelete=true


(1) check ȨÏÞ, »ñÈ¡x_user ±íÐÅÏ¢£¬ »ñÈ¡x_portal_user ±íÐÅÏ¢
»ñÈ¡x_group_users ÐÅÏ¢£¬ »ñÈ¡x_perm_map ÐÅÏ¢ »ñÈ¡x_audit_map
ÐÅÏ¢
ͨ¹ýx_portal_user µÄid »ñÈ¡x_auth_sess x_user_module_perm
x_portal_user_role
ͨ¹ýx_user µÄid »ñÈ¡x_policyÐÅÏ¢£º(²Î¿¼security-admin resource
ÀïÃæµÄjpa_named_queries.xml
select obj from XXPolicy obj, XXPolicyItem polItem ,XXPolicyItemUserPerm
polItemUserPerm where
obj.id = polItem.policyId and polItem.id = polItemUserPerm.policyItemId
and polItemUserPerm.userId = :userId
Èç¹ûÇ¿ÖÆÉ¾³ý£º
a.ɾ³ý x_gruop_users µÄx_userÐÅÏ¢
b.ɾ³ýx_perm_map ÐÅÏ¢
c.ɾ³ýx_audit_map ÐÅÏ¢
Èç¹ûprotalUser ²»Îª¿Õ:
a. ɾ³ý x_auth_sessÐÅÏ¢£¬ ɾ³ýx_user_module_perm ÐÅÏ¢
b. ɾ³ýx_portal_user_role ÐÅÏ¢
±éÀú´ËÓû§µÄx_policy ÐÅÏ¢ »ñÈ¡rangerPolicy ÐÅÏ¢£¬»ñÈ¡policyItem ÐÅÏ¢£¬È»ºóɾ³ý´ËÓû§Ïà¹ØµÄ£¬
¸üвßÂÔ¡£
ɾ³ýx_user, x_portal_user ÐÅÏ¢£¬ ²¢ÇÒͳ¼ÆÈÕ־дÈëx_trx_log ÖÐ
4. ´´½¨²ßÂÔ




(1) ÑéÖ¤policyÊÇ·ñ¹æ·¶£¬ ±ÈÈçÊÇ·ñΪnull£¬ Èç¹ûÊǸüвÙ×÷£¬id ÊÇ·ñΪ¿Õ£¬ Ãû³ÆÊÇ·ñÖØ¸´£¬´Ë²ßÂÔ¶ÔÓ¦µÄ·þÎñÃû²»´æÔڵȵȡ£
(2) È·¶¨È¨ÏÞÊÇ·ñÊÇadmin
(3) »ñÈ¡RangerService ºÍ XXServiceDef ÐÅÏ¢ ¿´ÊÇ·ñΪ¿Õ
(4) »ñÈ¡resource ºÍ policyItem ÐÅÏ¢¡£
(5) ͨ¹ýpolicyService ´´½¨ policy дÈëÊý¾Ý¿âx_policy ÖÐ
(6) ͨ¹ý´´½¨µÄXXPolicy È¥´´½¨ Resouces ÐÅÏ¢
Ê×ÏÈ»ñÈ¡resouceDef ÐÅÏ¢x_resouce_def, ÔÚ´´½¨Í¬res_def_id ºÍ
policy_id È¥´´½¨policy_resouce ¶ÔÓ¦Êý¾Ý¿âx_policy_resouce
ͨ¹ýpolicy_resouce ºÍ¾ßÌåµÄÖµ ÏòÊý¾Ý¿âx_policy_resouce_map
ÐÅÏ¢¡£
(7)ͨ¹ý´´½¨µÄXXPolicy È¥´´½¨PolicyItem
(8) ¸üÐÂx_service ÀïÃæµÄversion °æ±¾
(9) dataHisService ²åÈëx_data_hist ²Ù×÷¼Ç¼ÐÅÏ¢
(10) ²åÈëx_trx_log ²Ù×÷¼Ç¼ÐÅÏ¢
5.ɾ³ý²ßÂÔ


(1) ͨ¹ýpolicyId »ñÈ¡RangerPolicy ÐÅÏ¢, ͨ¹ýx_policy µÄservice
È¥²éѯ RangerService ÐÅÏ¢
(2) »ñÈ¡Verrsion µÄ°æ±¾ÐÅÏ¢£¬ ²¢ÇÒ½«É¾³ý¼Ç¼ дÈëx_trx_log ÖÐ
(3) ͨ¹ýpolicyɾ³ý policyItemsÐÅÏ¢
ͨ¹ýpolicy id »ñÈ¡ËùÓÐpolicyItems ÐÅÏ¢£¬ Ñ»·policyItems£¬ ͨ¹ýpolicyItemId
ȥɾ³ýx_policy_item_condition£¬
x_policy_item_group_perm£¬x_policy_item_user_perm£¬x_policy_item_access
ÐÅÏ¢
(4) ͨ¹ýpolicyɾ³ý policyResourceÐÅÏ¢
Ê×ÏÈͨ¹ýpolicyId »ñÈ¡ËùÓÐx_policy_resource µÄÐÅÏ¢£¬Ñ»·±éÀúresourceÐÅÏ¢£¬Í¨¹ýresourceId
È¥»ñÈ¡x_policy_resoure_mapÐÅÏ¢
Ñ»·resourceMaps ÐÅÏ¢ ɾ³ýresrouceMap ÐÅÏ¢¡£
(5) ͨ¹ýpolicy ɾ³ý policy ÐÅÏ¢
(6) ¸üÐÂservice ÐÅÏ¢£¬ °æ±¾±ä¸ü
(7) ¼Ç¼x_data_hist ÐÅÏ¢
6.¸üвßÂÔ



(1) ÑéÖ¤²Ù×÷
(2) ͨ¹ýpolicyId ÐÅÏ¢»ñÈ¡x_policy ÐÅÏ¢£¬ ͨ¹ýservice »ñÈ¡x_service
ÐÅÏ¢, ͨ¹ýx_serviceµÄtypeÐÅÏ¢»ñÈ¡x_service_defÐÅÏ¢
(3) ²é¿´ÊÇ·ñÊǸüÐÂÃû³Æ£¬Èç¹ûÊÇÃû³Æ£¬»ñÈ¡ÑéÖ¤£¬Õâ¸öÃû³ÆÊÇ·ñÒѾ´æÔÚÁË
(4) »ñÈ¡¸üеĺóµÄresouces ºÍ policyItems ÐÅÏ¢, ²¢ÔÚpolicy ÉèÖÃеĴ´½¨Ê±¼äºÍguidºÍversion£¬
²¢Ìí¼Óx_trx_log ÐÅÏ¢
(5) ¸üÐÂpolicy µ½Êý¾Ý¿âx_policyÖУ¬ ɾ³ý֮ǰµÄresouces ºÍ policyItemsÐÅÏ¢
(6)´´½¨ÐµÄresource ºÍpolicyItems ÐÅÏ¢
(7) ¸üÐÂx_service µÄ°æ±¾£¬ Ìí¼Óx_data_hist ÐÅÏ¢¡£
|