Configuring authentication and authorization for NiFi
Configure authentication for NiFi and declare NiFi users, groups, and access policies through operator-managed Kubernetes custom resources.
Operator-managed authorization
Cloudera Flow Management Operator for Kubernetes can create and maintain NiFi users, groups, and access policies declaratively through Kubernetes custom resources, so authorizations do not have to be edited by hand:
-
A
Usercreates a NiFi user and can grant it access policies. -
A
UserGroupcreates a NiFi user group, manages its members, and can grant it access policies. -
An
AccessPolicyProfilebundles reusable policies that severalUserorUserGroupresources can share. -
A
ProcessGroupdeploys a flow and records its NiFi-assigned identifier instatus.identifier.
Policies are declared as accessPolicies entries that pair
actions (read, write) with either literal
NiFi resource paths (resources) or references to Kubernetes resources
(resourceRefs); each entry needs at least one of the two. A
resourceRefs entry names a ProcessGroup by its Kubernetes
name, so a user can be granted access to a flow without first looking up the NiFi-assigned
identifier.
spec:
instanceTarget:
kind: Nifi
name: my-nifi
identity: alice
accessPolicies:
- actions:
- read
- write
resourceRefs:
- kind: ProcessGroup
name: my-flow
At reconcile time, Cloudera Flow Management Operator for Kubernetes reads the
ProcessGroup's status.identifier and grants the policy on
/process-groups/<identifier>. A ProcessGroup that does
not exist yet or is not ready is skipped and picked up automatically once it is; the
CompleteAccessPolicies status condition on the User or
UserGroup reports whether every reference resolved and does not gate
readiness.
