Configuring roles for Cloudera Lakehouse Optimizer users

Depending on your role, you can add the service to Cloudera Manager, create the Cloudera Lakehouse Optimizer policies, and monitor the policies. Cloudera Lakehouse Optimizer REST APIs uses Knox to infer authentication and group membership.

To access the Cloudera Lakehouse Optimizer features and REST APIs, you might require one or more of the following roles:
Role Description Default values
Administrators Can access and use all the features including all the REST APIs. dlm_admin
Operators Have limited access to REST APIs. They can run certain tasks, and have no privileges to modify the service configuration. dlm_operator
Monitors Can only observe the health and status of the service and its running tasks. dlm_monitor

The CLO Security Role Admin, CLO Security Role Operator, and CLO Security Role Monitor properties on the Cloudera Manager > Clusters > [***CLOUDERA LAKEHOUSE OPTIMIZER***] > Configuration tab contain the group names that define the user roles. By default, the properties contain the dlm_admin, dlm_operator, and dlm_monitor values respectively.

Ensure that you are in the administrator, operator, or monitor group to use the Cloudera Lakehouse Optimizer REST APIs.