Configuring the Knox IDBroker for Ozone S3 environments
Configure the Knox IDBroker STS endpoint, session policy, and AWS user mapping to
vend temporary Ozone S3 credentials to external clients.
For Cloudera Object Store (powered by Apache Ozone) environments, you must manually
configure the IDBroker STS endpoint, session policy, and AWS user mapping. Complete
this procedure after Installing the Knox IDBroker.
The sts-assume-role role must already exist in Ranger and be
granted read access to the shared Ozone volume, bucket, and key resources, as
described in Creating the Ranger role for Ozone STS.
Go to Cloudera Manager > Knox > Configuration and search for Save Alias Command Input -
IDBroker.
Enter the S3-compatible storage credential access key alias, click
Save Changes, and then run Actions > Save Alias - IDBroker.
Figure 1. Save Alias Command Input - IDBroker property
Search for Save Alias Command Input - IDBroker again,
enter the S3-compatible storage credential secret access key alias, click
Save Changes, and then run Actions > Save Alias - IDBroker again.
Set the Save Alias Command Input - IDBroker property
back to empty, and click Save Changes.
Go to Cloudera Manager > Knox > Configuration and search for Knox IDBroker Advanced Configuration
Snippet (Safety Valve) for conf/cdp-resources.xml.
Add the following entry to override the IDBroker STS endpoint to point at
the Ozone S3 Gateway:
Name:
aws-cab
Value:
providerConfigRef=cab-providers#IDBROKER:cloud.policy.config.provider=default#IDBROKER:cloud.client.provider=AWS#IDBROKER:aws.region.name=us-east-1#IDBROKER:org.apache.knox.idbroker.endpoint.override=
https://[***OZONE_S3_GATEWAY_HOST***]:[***Secure Ozone S3 Gateway API Port (TLS/SSL)***]
Name:
Add the read-only session IDBroker policy template to the Knox
IDBroker Advanced Configuration Snippet (Safety Valve) for
conf/cdp-resources.xml:
In Cloudera Manager > Knox > Configuration, search for Knox IDBroker AWS User
Mapping, set the mapping for the hive user to
the Ranger role created for Ozone STS (for example,
sts-assume-role), and click Save
Changes.
Map the hive Kerberos user to the STS role ARN. Use the
Ranger role name from Creating the Ranger role for Ozone
STS; change only the account ID and role name in the ARN to
match your environment.