Declaring Knox topologies for on premises Data Sharing

Declare the cdp-datashare-access and cdp-share-management Knox topologies so external clients can reach Cloudera Iceberg REST Catalog and administrators can generate client IDs and secrets.

  • Identify the share-administrative users who generate CLIENT_ID and CLIENT_SECRET values and who must be Knox proxy users and Ranger administrators.
  • Identify the Hive Metastore hosts where Cloudera Iceberg REST Catalog is enabled and the Ranger Admin hosts that cdp-share-management proxies to.

The cdp-datashare-access topology proxies external REST Catalog and OAuth token requests to the Hive Metastore Iceberg REST servlet and issues bearer tokens for the IDBroker audience. The cdp-share-management topology exposes the Knox token service and Ranger Admin APIs that you use to generate CLIENT_ID and CLIENT_SECRET pairs and register external clients. Declaring the topologies does not create a client; it provides the endpoints you call later.

Add all four properties in this procedure to the same Knox Gateway Advanced Configuration Snippet (Safety Valve) for conf/cdp-resources.xml.

  1. In Cloudera Manager, go to Clusters > Knox > Configuration and search for Knox Gateway Advanced Configuration Snippet (Safety Valve) for conf/cdp-resources.xml.
  2. Add the cdp-datashare-access provider configuration. Enter the following values:
    • Name:
      providerConfigs:cdp-datashare-access-provider
    • Value:
      role=federation#federation.name=JWTProvider#federation.enabled=true#federation.param.knox.token.exp.server-managed=true#role=identity-assertion#identity-assertion.name=Default#identity-assertion.enabled=true#identity-assertion.param.group.mapping.$PRIMARY_GROUP=(not (member username))#role=ha#ha.name=HaProvider#ha.param.ICEBERG-REST=enabled=true;maxFailoverAttempts=3;failoverSleep=1000
  3. Add the cdp-datashare-access topology descriptor. Set the following:
    • Name:
      cdp-datashare-access
    • Value:
      providerConfigRef=cdp-datashare-access-provider#KNOXTOKEN:knox.token.ttl=36000000#KNOXTOKEN:knox.token.exp.server-managed=true#KNOXTOKEN:knox.token.audiences=idbroker#KNOXTOKEN:gateway.knox.token.limit.per.user=-1#ICEBERG-REST:url=http://[***HMS_HOST***]:[***REST_CATALOG_PORT***]/icecli#ICEBERG-REST:url=http://[***HMS_HOST_2***]:[***REST_CATALOG_PORT***]/icecli#
  4. Add the cdp-share-management provider configuration. Enter the following values:
    • Name:
      providerConfigs:cdp-share-management-providers
    • Value:
      role=authentication#authentication.name=ShiroProvider#authentication.param.main.invalidRequest=org.apache.shiro.web.filter.InvalidRequestFilter#authentication.param.main.invalidRequest.blockBackslash=false#authentication.param.main.invalidRequest.blockNonAscii=false#authentication.param.main.invalidRequest.blockSemicolon=false#authentication.param.main.pamRealm=org.apache.knox.gateway.shirorealm.KnoxPamRealm#authentication.param.main.knoxAnonFilter=org.apache.knox.gateway.filter.AnonymousAuthFilter#authentication.param.urls./knoxtoken/api/v1/jwks.json=knoxAnonFilter#authentication.param.main.pamRealm.service=login#authentication.param.sessionTimeout=30#authentication.param.urls./**=authcBasic#role=identity-assertion#identity-assertion.name=HadoopGroupProvider#identity-assertion.param.hadoop.proxyuser.impersonation.enabled=true#identity-assertion.param.hadoop.proxyuser.[***KNOX-ADMIN-USER***].users=*#identity-assertion.param.hadoop.proxyuser.[***KNOX-ADMIN-USER***].groups=*#identity-assertion.param.hadoop.proxyuser.[***KNOX-ADMIN-USER***].hosts=*#identity-assertion.param.CENTRAL_GROUP_CONFIG_PREFIX=gateway.group.config.#role=authorization#authorization.name=XASecurePDPKnox#authorization.enabled=false#role=ha#ha.name=HaProvider#ha.enabled=true#ha.param.RANGER=enableStickySession=false;noFallback=false;enableLoadBalancing=true
  5. Optional: If additional share-administrative users need access, duplicate the three identity-assertion.param.hadoop.proxyuser.[***KNOX-ADMIN-USER***].* fragments in the providerConfigs:cdp-share-management-providers value for each user.
  6. Add the cdp-share-management topology descriptor. Set the following:
    • Name:
      cdp-share-management
    • Value:
      providerConfigRef=cdp-share-management-providers#RANGER:url=https://[***RANGER-HOST***]:[***RANGER-PORT***]#KNOXTOKEN:knox.token.ttl=36000000#KNOXTOKEN:knox.token.type=JWT#KNOXTOKEN:knox.token.target.url=cdp-proxy-token#KNOXTOKEN:knox.token.audiences=cdp-proxy-token#KNOXTOKEN:knox.token.client.data=homepage_url=homepage/home?profile=token&topologies=cdp-proxy-token#KNOXTOKEN:knox.token.exp.tokengen.allowed.tss.backends=JDBCTokenStateService,AliasBasedTokenStateService#KNOXTOKEN:knox.token.lifespan.input.enabled=true#KNOXTOKEN:knox.token.user.limit.exceeded.action=RETURN_ERROR#KNOXTOKEN:knox.token.exp.server-managed=true#KNOXTOKEN:gateway.knox.token.limit.per.user=-1#KNOXTOKEN:knox.token.renewer.whitelist=[***SHARE_ADMIN_USERS***]
  7. Optional: In the same Knox service, search for Knox Gateway Advanced Configuration Snippet (Safety Valve) for conf/gateway-site.xml and add the following properties:
    <property><name>gateway.knox.admin.users</name><value>[***SHARE_ADMIN_USERS***]</value></property>
    <property><name>gateway.knox.token.limit.per.user</name><value>-1</value></property>

    Use the same comma-separated share-administrative user list as in knox.token.renewer.whitelist.

  8. Click Save Changes, deploy client configuration if your environment requires it, and restart the Knox service.

Continue with Trusting the Ozone STS certificate in the Knox IDBroker truststore.