System Access Control

openLooKeng separates the concept of the principal who authenticates to the coordinator from the username that is responsible for running queries.

When running the openLooKeng CLI, for example, the openLooKeng username can be specified using the --user option.

By default, the openLooKeng coordinator allows any principal to run queries as any openLooKeng user. In a secure environment, this is probably not desirable behavior and likely requires customization.

Implementation

SystemAccessControlFactory is responsible for creating a SystemAccessControl instance. It also defines a SystemAccessControl name which is used by the administrator in a openLooKeng configuration.

SystemAccessControl implementations have several responsibilities:

  • Verifying whether or not a given principal is authorized to execute queries as a specific user.
  • Determining whether or not a given user can alter values for a given system property.
  • Performing access checks across all catalogs. These access checks happen before any connector specific checks and thus can deny permissions that would otherwise be allowed by ConnectorAccessControl.

The implementation of SystemAccessControl and SystemAccessControlFactory must be wrapped as a plugin and installed on the openLooKeng cluster.

Configuration

After a plugin that implements SystemAccessControl and SystemAccessControlFactory has been installed on the coordinator, it is configured using an etc/access-control.properties file. All of the properties other than access-control.name are specific to the SystemAccessControl implementation.

The access-control.name property is used by openLooKeng to find a registered SystemAccessControlFactory based on the name returned by SystemAccessControlFactory.getName(). The remaining properties are passed as a map to SystemAccessControlFactory.create().

Example configuration file:

access-control.name=custom-access-control
custom-property1=custom-value1
custom-property2=custom-value2

有奖捉虫

“有虫”文档片段

0/500

存在的问题

文档存在风险与错误

● 拼写,格式,无效链接等错误;

● 技术原理、功能、规格等描述和软件不一致,存在错误;

● 原理图、架构图等存在错误;

● 版本号不匹配:文档版本或内容描述和实际软件不一致;

● 对重要数据或系统存在风险的操作,缺少安全提示;

● 排版不美观,影响阅读;

内容描述不清晰

● 描述存在歧义;

● 图形、表格、文字等晦涩难懂;

● 逻辑不清晰,该分类、分项、分步骤的没有给出;

内容获取有困难

● 很难通过搜索引擎,openLooKeng官网,相关博客找到所需内容;

示例代码有错误

● 命令、命令参数等错误;

● 命令无法执行或无法完成对应功能;

内容有缺失

● 关键步骤错误或缺失,无法指导用户完成任务,比如安装、配置、部署等;

● 逻辑不清晰,该分类、分项、分步骤的没有给出

● 图形、表格、文字等晦涩难懂

● 缺少必要的前提条件、注意事项等;

● 描述存在歧义

0/500

您对文档的总体满意度

非常不满意
非常满意

请问是什么原因让您参与到这个问题中

您的邮箱

创Issue赢奖品
根据您的反馈,会自动生成issue模板。您只需点击按钮,创建issue即可。
有奖捉虫