๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๐Ÿ’ปTech/๐Ÿ˜hadoop

Apache Ranger ์‚ฌ์šฉ๋ฒ•

by _viper_ 2023. 8. 23.
๋ฐ˜์‘ํ˜•

Ranger Web UI ๊ฐ ๊ธฐ๋Šฅ๋“ค ์‚ฌ์šฉ๋ฐฉ๋ฒ•์ž…๋‹ˆ๋‹ค.

Ranger๋ž€?

  • ํ•˜๋‘ก ์ „์ฒด ์„œ๋น„์Šค์— ๋Œ€ํ•œ ๋ณด์•ˆ ์ •์ฑ…์„ ์ ์šฉํ•  ์ˆ˜ ์žˆ๊ณ  ๊ด€๋ฆฌ ๋ฐ ์šด์˜ํ•  ์ˆ˜ ์žˆ๋Š” Hadoop Component
  • ํ•˜๋‘ก์˜ ๋ณด์•ˆ ๊ด€๋ จ ์กฐ์น˜๋Š” ๋Œ€๋ถ€๋ถ„ Ranger์—์„œ ์ฒ˜๋ฆฌ ๊ฐ€๋Šฅํ•˜๋‹ค๊ณ  ๋ณด์‹œ๋ฉด ๋ฉ๋‹ˆ๋‹ค.

Ranger Architecture

  • Ranger๋Š” Hadoop์˜ ์ „์ฒด ์ปดํฌ๋„ŒํŠธ์— ๋Œ€ํ•œ Ranger ํ”Œ๋Ÿฌ๊ทธ์ธ์„ ํ™œ์„ฑํ™”ํ•˜์—ฌ ๋ชจ๋“  ์•ก์„ธ์Šค๋ฅผ ์ œ์–ดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Ranger ํ”Œ๋Ÿฌ๊ทธ์ธ๊ณผ Ranger policy server ๊ฐ„์—๋Š” ์–‘๋ฐฉํ–ฅ ํ†ต์‹ ์ด ์ด๋ฃจ์–ด์ง€๋ฉฐ, Ranger ํ”Œ๋Ÿฌ๊ทธ์ธ์€ ์ •๊ธฐ์ ์œผ๋กœ(30์ดˆ) Ranger Policy Server๋ฅผ ํ˜ธ์ถœํ•˜์—ฌ ์ƒˆ๋กœ์šด ์ •์ฑ…์ด ์ •์˜๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

๐Ÿ”— https://doc.hcs.huawei.com/productdesc/mrs/mrs_08_00411.html

Ranger Web UI (v2.0.0)

โ—พ ๋กœ๊ทธ์ธ ํ™”๋ฉด

 

โ—พ ์ƒ๋‹จ ๋ฉ”๋‰ด

 

โ—พ Access Manager > Resource Based Policies

  • ๊ฐ ์„œ๋น„์Šค๋“ค์„ ๋ฆฌ์†Œ์Šค ๊ธฐ๋ฐ˜์œผ๋กœ ๋ณด์•ˆ ์ •์ฑ… ์ƒ์„ฑ ๋ฐ ๊ด€๋ฆฌ

 

โ—พ Access Manager > Resource Based Policies > HADOOP SQL

  • HADOOP SQL์€ Hive, Impala ํ…Œ์ด๋ธ”์— ๋Œ€ํ•œ ์ ‘๊ทผ ๊ถŒํ•œ ์ •์ฑ…์„ ์ƒ์„ฑ
    - Ranger๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฐ€์žฅ ํฐ ์ด์œ ์ด๋ฉฐ, ์ œ์ผ ๋งŽ์ด ์‚ฌ์šฉ๋˜๋Š” ์˜์—ญ
  • Access ํƒญ: ์‚ฌ์šฉ์ž/๊ทธ๋ฃน๋ณ„ ์ ‘๊ทผ ์ œ์–ด
  • Masking ํƒญ: ํ…Œ์ด๋ธ”๋ณ„ ๋งˆ์Šคํ‚น ์ •์ฑ… ์ ์šฉ
    - Masking ์˜ต์…˜ ์ค‘ Custom์„ ์„ ํƒํ•˜๋ฉด Hive ํ•จ์ˆ˜๋‚˜ UDF๋„ ์‚ฌ์šฉ ๊ฐ€๋Šฅ
    - ์‚ฌ์šฉ ์˜ˆ์‹œ: substr({col},1,1)
  • Row Level Filter: ์‚ฌ์šฉ์ž๋‚˜ ๊ทธ๋ฃน์—๊ฒŒ ์กฐํšŒํ•  ์ˆ˜ ์žˆ๋Š” ํŠน์ • ๋ฐ์ดํ„ฐ๋ฅผ ์ ์šฉ
    - ์˜ˆ์‹œ: Aํ…Œ์ด๋ธ”์—์„œ a ๊ฐ’์„ ๊ฐ€์ง€๋Š” ๋ฐ์ดํ„ฐ๋Š” admin ์‚ฌ์šฉ์ž๋งŒ ๋ณผ ์ˆ˜ ์žˆ๊ฒŒ ์„ค์ •
  • ์˜ค๋ฅธ์ชฝ ์ƒ๋‹จ์˜ Add New Policy ๋ฒ„ํŠผ์œผ๋กœ ์ •์ฑ…์„ ์ƒ์„ฑ

 

โ—พ Access Manager > Resource Based Policies > HADOOP SQL > Add New Policy

  • Hive ์ ‘๊ทผ์ œ์–ด ์ •์ฑ… ์„ค์ • ํ™”๋ฉด (Hive์˜ Resource๋Š” database,table,column)
  • Allow Conditions, Deny Conditions ์˜์—ญ์—์„œ ์‚ฌ์šฉ์ž๋ณ„ ํ…Œ์ด๋ธ” ์ ‘๊ทผ์— ๋Œ€ํ•œ ํ—ˆ์šฉ, ์ œํ•œ์„ ์„ค์ •

 

โ—พ Access Manager > Tag Based Policies

  • ๊ฐ ์„œ๋น„์Šค๋“ค์„ Atlas์—์„œ ์ •์˜ํ•œ ํƒœ๊ทธ ๊ธฐ๋ฐ˜์œผ๋กœ ๋ณด์•ˆ ์ •์ฑ… ์ƒ์„ฑ ๊ฐ€๋Šฅ

 

โ—พ Access Manager > Reports

  • ๋“ฑ๋ก๋œ ์ •์ฑ…์„ Excel, Json, CSV ํ˜•ํƒœ๋กœ ์ถœ๋ ฅ ๊ฐ€๋Šฅ

 

โ—พ Audit > Access

  • HDFS ๊ฒฝ๋กœ๋‚˜ ํ…Œ์ด๋ธ”์— ์ ‘๊ทผํ•˜๋Š” ๊ธฐ๋ก๊ณผ ์ƒ์„ธ ์ •๋ณด ์ œ๊ณต
  • ๋ชจ๋“  ์‚ฌ์šฉ์ž History ํ™•์ธ ๊ฐ€๋Šฅํ•˜๋ฉฐ, HDFS ๊ฒฝ๋กœ์—๋„ Audit ๋กœ๊ทธ๊ฐ€ ์˜๊ตฌ์ ์œผ๋กœ ๋ณด๊ด€๋˜์–ด ๋ณ„๋„๋กœ External ํ…Œ์ด๋ธ”์„ ์ƒ์„ฑํ•˜์—ฌ ํ™•์ธ ๊ฐ€๋Šฅ

 

โ—พ Security Zone

  • ํŠน์ • Resource๋ฅผ ๋…๋ฆฝ์ ์œผ๋กœ ๊ด€๋ฆฌํ•˜๊ธฐ ์œ„ํ•œ ๊ธฐ๋Šฅ

 

โ—พ Settings >  Users/Groups/Roles

  • ์‚ฌ์šฉ์ž/๊ทธ๋ฃน/๋กค ์ƒ์„ฑ ๋ฐ ์„ค์ •

 

โ—พ Settings > Permissions

  • Ranger ํ™”๋ฉด์— ๋Œ€ํ•œ ์‚ฌ์šฉ์ž๋ณ„ ์ ‘๊ทผ ์ œ์–ด