Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Ch1 #3

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
9 changes: 7 additions & 2 deletions sections/kerberos_the_madness.md
Original file line number Diff line number Diff line change
Expand Up @@ -91,8 +91,9 @@ users. When cluster node labels are used to differentiate parts of the cluster (
more RAM, GPUs or other features), then the queues can be used to restrict access
to specific sets of nodes.

Similarly, HBase and Accumulo have their users and permissions, while Hive uses the
permissions of the source files as its primary access control mechanism.
Similarly, HBase and Accumulo have their users and permissions, while Hive can
authorize users either through its permisions model or use the
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1. More appropriate would be to mention "SQL Standard based" - permission model.

permissions of the source files as its primary access control mechanism or.

These various mechanisms are all a bit disjoint, hence the emergence of tools
to work across the entire stack for a unified view, Apache Ranger being one example.
Expand Down Expand Up @@ -146,3 +147,7 @@ hence should have their replication factor increased), and which do not get
used more then 7 days after their creation —and hence can be automatically deleted
as part of a workflow.

HBase, Hive and HDFS allow for creation and management of such audit logs. Various
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

We don't really need to repeat the same line from Authorization to convey that Apache Ranger can provide uniform auditing capabilities for HDFS, Hive and HBase.

mechanisms are all a bit disjoint, hence as in case for Authorization, the emergence of tools
to work across the entire stack for a unified view, Apache Ranger being one example.