Configure a resource-based policy: NiFi Registry
How to add a new policy to an existing Atlas service.
- 
            On Service Manager >  Resource Policies, select an existing NiFi Registry service.
            List of Policies displays a list of the policies defined for NiFi Registry service. 
- 
            Click Add New Policy.
            Create Policy displays controls for creating details for a new policy. 
 
- 
            Complete the Create Policy page as follows:
            Table 1. Policy Details Field Description Policy Name Enter an appropriate policy name. This name cannot be duplicated across the system. This field is mandatory. normal/override Enables you to specify an override policy. When override is selected, the access permissions in the policy override the access permissions in existing policies. This feature can be used with Add Validity Period to create temporary access policies that override existing policies. NiFi Registry Resource Identifier In a NiFi cluster, all nodes must be granted the ability to view and modify component data in order for user to list or empty queues in processor component outbound connections. With Ranger this can be accomplished by using a wildcard to grant all of the NiFi nodes read and write access to the /data/*NiFi resource.Description (Optional) Describe the purpose of the policy. Audit Logging Specify whether this policy is audited. (De-select to disable auditing). Policy Label Specify a label for this policy. You can search reports and filter policies based on these labels. Add Validity Period Specify a start and end time for the policy. Table 2. Allow Conditions Label Description Select Role Specify the roles to which this policy applies. To designate a role as an Administrator, select Delegate Admin. Administrators can edit or delete the policy, and can also create child policies based on the original policy. Select Group Specify the groups to which this policy applies. To designate a group as an Administrator, select Delegate Admin. Administrators can edit or delete the policy, and can also create child policies based on the original policy. The public group contains all users, so granting access to the public group grants access to all users. Select User Specify the users to which this policy applies. To designate a user as an Administrator, select Delegate Admin. Administrators can edit or delete the policy, and can also create child policies based on the original policy. Permissions Add or edit permissions: Read, Write, Delete, Select/Deselect All. Delegate Admin You can use Delegate Admin to assign administrator privileges to the roles, groups, or users specified in the policy. Administrators can edit or delete the policy, and can also create child policies based on the original policy. 
- You can use + to add additional conditions. Conditions are evaluated in the order listed in the policy. The condition at the top of the list is applied first, then the second, then the third, and so on.
- 
            You can use Deny All Other Accesses to deny access to all
               other users, groups, and roles other than those specified in the allow conditions for
               the policy. 
            Combination of Deny All Other Accesses and Ranger macros (for example,{USER}) are not supported.
- Click Add.
