Setting up Cloudera Iceberg REST Catalog for data sharing
Learn how to perform the preparatory configurations in Cloudera to enable data sharing. These configurations are required for the creation of a data share in Cloudera and allow your clients to access data in Cloudera environments.
Installation and Upgrade Scenarios
Different versions of Cloudera Runtime and Data Lakes require different steps to enable data sharing.
Fresh 7.3.2.20000 or Higher Cloudera Base on premises Installation
-
Installing the Metering V2 Service
Install and configure the Metering V2 service. This is a prerequisite for Cloudera Data Sharing on Ozone storage. If Metering V2 is TLS-enabled, also import the Metering V2 certificate authority into the Hive Metastore truststore.
-
HMS REST Catalog configuration for Ozone storage
Enable the Iceberg REST Catalog in the Hive Metastore and point it at your Ozone Object Manager and S3 Gateway so Cloudera Data Sharing can vend temporary S3 credentials through the gateway. Only Iceberg tables whose storage locations use
s3a://paths are shareable; tables registered withofs://locations only cannot be shared this way. -
Add the IDBroker role to the Knox service. On premises deployments do not provision the IDBroker automatically, so you must install it manually before you can configure it for Ozone S3 credential vending.
-
Configuring Ozone STS for on premises Data Sharing
Enable the Ozone Security Token Service (STS) and the Ranger action-matcher condition, and then complete the Ranger role, Knox IDBroker, certificate, and topology configuration required so that REST Catalog can vend temporary Ozone S3 credentials.
-
Creating the Ranger role for Ozone STS
Create the
sts-assume-roleRanger role and grant thehiveuser Assume Role access so that Ozone STS can generate session credentials for the REST Catalog. -
Configuring the Knox IDBroker for Ozone S3 environments
Configure the Knox IDBroker STS endpoint override, session policy template, and AWS user mapping so that IDBroker can vend temporary Ozone S3 credentials to external clients.
-
Trusting the Ozone STS certificate in the Knox IDBroker truststore
Import the cluster's SCM Local CA into the Knox IDBroker truststore so that IDBroker can call the Ozone STS and S3 Gateway endpoint over HTTPS.
-
Declaring Knox topologies for on premises Data Sharing
Declare the
cdp-datashare-accessandcdp-share-managementKnox topologies so external clients can reach REST Catalog through Knox and administrators can generate theCLIENT_IDandCLIENT_SECRETused by external clients. -
Registering external clients for on premises deployments
Generate a
CLIENT_IDandCLIENT_SECRETfor the external client through thecdp-share-managementKnox topology, create the Ranger group and role that represent the client, and then create the Data Share policy in Managing Ranger policies to grant that roleSELECTaccess to the shared Iceberg tables.
Upgrade from a lower version of Cloudera Base on premises to a 7.3.2.20000 or Higher version of Cloudera Base on premises
-
Installing the Metering V2 Service
Install and configure the Metering V2 service. This is a prerequisite for Cloudera Data Sharing on Ozone storage. If Metering V2 is TLS-enabled, also import the Metering V2 certificate authority into the Hive Metastore truststore.
-
HMS REST Catalog configuration for Ozone storage
Enable the Iceberg REST Catalog in the Hive Metastore and point it at your Ozone Object Manager and S3 Gateway so Data Sharing can vend temporary S3 credentials through the gateway. Only Iceberg tables whose storage locations use
s3a://paths are shareable; tables registered withofs://locations only cannot be shared this way. -
Add the IDBroker role to the Knox service. On premises deployments do not provision the IDBroker automatically, so you must install it manually before you can configure it for Ozone S3 credential vending.
-
Configuring Ozone STS for on premises Data Sharing
Enable the Ozone Security Token Service (STS) and the Ranger action-matcher condition, and then complete the Ranger role, Knox IDBroker, certificate, and topology configuration required so that REST Catalog can vend temporary Ozone S3 credentials.
-
Creating the Ranger role for Ozone STS
Create the
sts-assume-roleRanger role and grant thehiveuser Assume Role access so that Ozone STS can generate session credentials for the REST Catalog. -
Configuring the Knox IDBroker for Ozone S3 environments
Configure the Knox IDBroker STS endpoint override, session policy template, and AWS user mapping so that IDBroker can vend temporary Ozone S3 credentials to external clients.
-
Trusting the Ozone STS certificate in the Knox IDBroker truststore
Import the cluster's SCM Local CA into the Knox IDBroker truststore so that IDBroker can call the Ozone STS and S3 Gateway endpoint over HTTPS.
-
Declaring Knox topologies for on premises Data Sharing
Declare the
cdp-datashare-accessandcdp-share-managementKnox topologies so external clients can reach REST Catalog through Knox and administrators can generate theCLIENT_IDandCLIENT_SECRETused by external clients. -
Registering external clients for on premises deployments
Generate a
CLIENT_IDandCLIENT_SECRETfor the external client through thecdp-share-managementKnox topology, create the Ranger group and role that represent the client, and then create the Data Share policy in Managing Ranger policies to grant that roleSELECTaccess to the shared Iceberg tables.
