Configuring authentication and authorization for NiFi

Configure authentication for NiFi and declare NiFi users, groups, and access policies through operator-managed Kubernetes custom resources.

Operator-managed authorization

Cloudera Flow Management Operator for Kubernetes can create and maintain NiFi users, groups, and access policies declaratively through Kubernetes custom resources, so authorizations do not have to be edited by hand:

  • A User creates a NiFi user and can grant it access policies.

  • A UserGroup creates a NiFi user group, manages its members, and can grant it access policies.

  • An AccessPolicyProfile bundles reusable policies that several User or UserGroup resources can share.

  • A ProcessGroup deploys a flow and records its NiFi-assigned identifier in status.identifier.

Policies are declared as accessPolicies entries that pair actions (read, write) with either literal NiFi resource paths (resources) or references to Kubernetes resources (resourceRefs); each entry needs at least one of the two. A resourceRefs entry names a ProcessGroup by its Kubernetes name, so a user can be granted access to a flow without first looking up the NiFi-assigned identifier.

spec:
  instanceTarget:
    kind: Nifi
    name: my-nifi
  identity: alice
  accessPolicies:
    - actions:
        - read
        - write
      resourceRefs:
        - kind: ProcessGroup
          name: my-flow

At reconcile time, Cloudera Flow Management Operator for Kubernetes reads the ProcessGroup's status.identifier and grants the policy on /process-groups/<identifier>. A ProcessGroup that does not exist yet or is not ready is skipped and picked up automatically once it is; the CompleteAccessPolicies status condition on the User or UserGroup reports whether every reference resolved and does not gate readiness.