[ 
https://issues.apache.org/jira/browse/RANGER-1300?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15943963#comment-15943963
 ] 

Goden Yao edited comment on RANGER-1300 at 3/30/17 6:50 PM:
------------------------------------------------------------

I'll check with my engineering team (suppose you're asking me) :)
*updates*
my company can do some of the work that would benefit our product roadmap. so 
is there any chance you can elaborate on the couple solutions you described?

One thing I'm thinking, to make ranger do:
1) a mapping between user and IAM role (e.g. user ranger got from Kerberos / 
LDAP or Exchange directory, mapped to hive users, mapped to IAM role from S3)
2) an auto injection for S3 IAM role permission profile - (e.g. user's 
permission to S3 is set through Ranger, ranger then can inject the JSON 
permission script to IAM role definition somehow and keep it synchronized) 




was (Author: godenyao):
I'll check with my engineering team (suppose you're asking me) :)
*updates*
my company can do some of the work that would benefit our product roadmap. so 
is there any chance you can elaborate on the couple solutions you described?



> S3 support
> ----------
>
>                 Key: RANGER-1300
>                 URL: https://issues.apache.org/jira/browse/RANGER-1300
>             Project: Ranger
>          Issue Type: New Feature
>          Components: plugins
>            Reporter: Jose
>
> As more and more people are deploying hadoop into AWS and as S3 is used in 
> lots of application. It'd be nice to have S3 support built into Ranger.
> It's not a trivial task. Right now Ranger Storage support (only hdfs) runs 
> directly in the Namenode



--
This message was sent by Atlassian JIRA
(v6.3.15#6346)

Reply via email to