Declaring Knox topologies for on premises Data Sharing
Declare the cdp-datashare-access and
cdp-share-management Knox topologies so external clients can reach Cloudera Iceberg REST Catalog and administrators can generate client
IDs and secrets.
Identify the share-administrative users who generate
CLIENT_ID and CLIENT_SECRET values and
who must be Knox proxy users and Ranger administrators.
Identify the Hive Metastore hosts where Cloudera Iceberg REST Catalog is enabled and the Ranger
Admin hosts that cdp-share-management proxies to.
The cdp-datashare-access topology proxies external REST Catalog and
OAuth token requests to the Hive Metastore Iceberg REST servlet and issues bearer
tokens for the IDBroker audience. The cdp-share-management topology
exposes the Knox token service and Ranger Admin APIs that you use to generate
CLIENT_ID and CLIENT_SECRET pairs and
register external clients. Declaring the topologies does not create a client; it
provides the endpoints you call later.
Add all four properties in this procedure to the same Knox Gateway
Advanced Configuration Snippet (Safety Valve) for
conf/cdp-resources.xml.
In Cloudera Manager, go to Clusters > Knox > Configuration and search for Knox Gateway Advanced Configuration
Snippet (Safety Valve) for conf/cdp-resources.xml.
Add the cdp-datashare-access provider configuration. Enter the
following values:
Optional: If additional share-administrative users need access, duplicate the three
identity-assertion.param.hadoop.proxyuser.[***KNOX-ADMIN-USER***].*
fragments in the
providerConfigs:cdp-share-management-providers value for
each user.
Add the cdp-share-management topology descriptor. Set the
following:
Optional: In the same Knox service, search for Knox Gateway Advanced
Configuration Snippet (Safety Valve) for conf/gateway-site.xml
and add the following properties: