Ramachandran Krishnan created RANGER-5723:
---------------------------------------------

             Summary: Plugin SPIFFE outbound auth for audit-server destination
                 Key: RANGER-5723
                 URL: https://issues.apache.org/jira/browse/RANGER-5723
             Project: Ranger
          Issue Type: Sub-task
          Components: Ranger
            Reporter: Ramachandran Krishnan
            Assignee: Ramachandran Krishnan


Wires all Ranger plugins to send workload SPIFFE identity on audit POSTs to the 
Audit Ingestor, completing the plugin → ingestor trust boundary.

Plugins already batch authorization audits to the audit-server destination 
({{{}POST /api/audit/access{}}}). This change adds optional SPIFFE header 
authentication on those outbound calls so the ingestor can validate the 
caller’s Kubernetes service account without username/password.
h3. Audit destination changes

Extends the shared audit-server destination so each audit HTTP request can 
include:
 * {{X-Spiffe-Id}} (or configured header name) with the plugin workload’s 
SPIFFE ID
 * SPIFFE ID resolved from install-time value, identity file, or standard 
workload identity path (via shared utilities from PR1)

When SPIFFE auth is disabled, behavior matches today (no header; existing 
Kerberos/JWT paths on ingestor still apply if configured).
h3. Plugin install and enable templates

Updates install properties and config changers across all supported plugins 
(HDFS, Hive, HBase, Knox, Kafka, Ozone, YARN, Storm, Atlas, Elasticsearch, 
Solr, Sqoop, Trino, Presto, Kylin, KMS, etc.) so {{enable-*-plugin.sh}} / 
install writes SPIFFE settings into each plugin’s audit and security 
configuration, for example:
 * Enable flag for audit-server SPIFFE auth
 * Header name (default {{{}X-Spiffe-Id{}}})
 * SPIFFE ID value or file path per workload ({{{}…/sa/hive{}}}, 
{{{}…/sa/hdfs{}}}, {{{}…/sa/om{}}}, …)

Operators set these at install/upgrade time; the service account in the SPIFFE 
ID must match that repo’s {{policy.download.auth.users}} (enforced by ingestor 
allow-list in dynamic mode).



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to