Configuring the Knox IDBroker for Ozone S3 environments

Configure the Knox IDBroker STS endpoint, session policy, and AWS user mapping to vend temporary Ozone S3 credentials to external clients.

For Cloudera Object Store (powered by Apache Ozone) environments, you must manually configure the IDBroker STS endpoint, session policy, and AWS user mapping. Complete this procedure after Installing the Knox IDBroker.

The sts-assume-role role must already exist in Ranger and be granted read access to the shared Ozone volume, bucket, and key resources, as described in Creating the Ranger role for Ozone STS.

  1. Go to Cloudera Manager > Knox > Configuration and search for Save Alias Command Input - IDBroker.
  2. Enter the S3-compatible storage credential access key alias, click Save Changes, and then run Actions > Save Alias - IDBroker.
    Figure 1. Save Alias Command Input - IDBroker property
    aws-cab.aws.credentials.key=[***OZONE_S3_ACCESS_KEY***]
  3. Search for Save Alias Command Input - IDBroker again, enter the S3-compatible storage credential secret access key alias, click Save Changes, and then run Actions > Save Alias - IDBroker again.
    Figure 2. Save Alias - IDBroker action
    aws-cab.aws.credentials.secret=[***OZONE_S3_SECRET_KEY***]
  4. Set the Save Alias Command Input - IDBroker property back to empty, and click Save Changes.
  5. Go to Cloudera Manager > Knox > Configuration and search for Knox IDBroker Advanced Configuration Snippet (Safety Valve) for conf/cdp-resources.xml.
  6. Add the following entry to override the IDBroker STS endpoint to point at the Ozone S3 Gateway:
    • Name:
      aws-cab
    • Value:
      providerConfigRef=cab-providers#IDBROKER:cloud.policy.config.provider=default#IDBROKER:cloud.client.provider=AWS#IDBROKER:aws.region.name=us-east-1#IDBROKER:org.apache.knox.idbroker.endpoint.override=
      https://[***OZONE_S3_GATEWAY_HOST***]:[***Secure Ozone S3 Gateway API Port (TLS/SSL)***]
    Name:
  7. Add the read-only session IDBroker policy template to the Knox IDBroker Advanced Configuration Snippet (Safety Valve) for conf/cdp-resources.xml:
    Figure 3. Read-only session policy template
    • Name:
      sessionPolicyTemplate:read-only
    • Value:
      {"Version":"2012-10-17","Statement":[{"Sid":"AllowListingOfDataLakeFolderOnly","Effect":"Allow","Action":["s3:List*"],"Resource":"arn:aws:s3:::${bucket}","Condition":{"StringEquals":{"s3:prefix":["${prefix}","${prefix}/"]}}},{"Sid":"AllowAccessToDataLakeFolder","Effect":"Allow","Action":["s3:Get"],"Resource":"arn:aws:s3:::${bucket}/${prefix}/*"}]}
  8. In Cloudera Manager > Knox > Configuration, search for Knox IDBroker AWS User Mapping, set the mapping for the hive user to the Ranger role created for Ozone STS (for example, sts-assume-role), and click Save Changes.

    Map the hive Kerberos user to the STS role ARN. Use the Ranger role name from Creating the Ranger role for Ozone STS; change only the account ID and role name in the ARN to match your environment.

    hive=arn:aws:iam::[***ACCOUNT_ID***]:role/[***RANGER_ROLE_NAME***]
  9. Click Save Changes, and then restart the Knox service.

Continue with Declaring Knox topologies for on premises Data Sharing.