Configuring NiFi access policy profiles
An AccessPolicyProfile is a reusable collection of NiFi access policies that User and UserGroup resources can share, including ProcessGroup references resolved at reconcile time.
Defining an AccessPolicyProfile
apiVersion: cfm.cloudera.com/v1alpha1
kind: AccessPolicyProfile
metadata:
name: read-only-profile
namespace: nifi
spec:
accessPolicies:
- actions:
- "read"
resources:
- /flow
- /process-groups/root
- actions:
- "read"
resources:
- /data/process-groups/root
Each entry in accessPolicies pairs one or more actions
(read, write) with one or more NiFi resource paths.
An accessPolicies entry can also reference a ProcessGroup by
name through resourceRefs instead of (or alongside) literal
resources paths:
spec:
accessPolicies:
- actions:
- read
resourceRefs:
- kind: ProcessGroup
name: my-flow
Only kind: ProcessGroup is supported. Each accessPolicies
entry must set at least one of resources or resourceRefs.
Cloudera Flow Management Operator for Kubernetes accepts at most 500 resourceRefs per
entry; this is an operator-side validation bound, not a NiFi limit. When both are set, the
resolved /process-groups/<id> paths are combined with the literal
resources into one policy sharing the entry's actions.
The ProcessGroup reference is resolved to
/process-groups/<status.identifier> when a User or
UserGroup that references this profile is reconciled. An
AccessPolicyProfile is a shared data type with no controller of its own; the
User and UserGroup controllers resolve its references when
they reconcile.
Two points differ from an inline reference on a User or
UserGroup:
-
A
resourceRefinside a profile that omitsnamespacedefaults to the profile's own namespace, not the namespace of the consumingUserorUserGroup. Setnamespaceexplicitly to reference aProcessGroupelsewhere. -
The referenced
ProcessGroupmust target the sameNifiinstance as the consumingUserorUserGroup. A mismatch is reported on the consumer'sCompleteAccessPoliciescondition with reasonProcessGroupTargetsDifferentNiFiand requires correcting the reference.
Unresolved references are skipped for the current reconcile and reported on the consuming
resource's CompleteAccessPolicies condition; the policies that did resolve are
still applied.
Referencing a profile from a User
Use accessPolicyProfileRef on the User to attach one or more
profiles:
apiVersion: cfm.cloudera.com/v1alpha1
kind: User
metadata:
name: alice
namespace: nifi
spec:
instanceTarget:
name: my-nifi
namespace: nifi
identity: alice@example.com
accessPolicyProfileRef:
- name: read-only-profile
namespace: nifi
Multiple profiles can be listed and their policies are unioned together:
accessPolicyProfileRef:
- name: read-only-profile
namespace: nifi
- name: component-admin-profile
namespace: nifi
The namespace field in each entry defaults to the User
resource's own namespace when omitted.
Inline policies override profile policies
Policies defined directly in spec.accessPolicies take precedence over
policies from referenced profiles. When the same NiFi resource appears in both places, the
inline policy wins and the policy from the AccessPolicyProfile for that resource is ignored
entirely.
spec:
accessPolicies:
# This write policy for /flow overrides any /flow policy from
# the profile.
- actions: ["read", "write"]
resources:
- /flow
accessPolicyProfileRef:
# has read-only /flow — ignored for /flow
- name: read-only-profile
namespace: nifi
The override is per-resource: other resources in the profile that are not covered by inline policies are still applied.
Reconciliation behavior
The User and UserGroup controllers watch
AccessPolicyProfile resources. When a profile is updated, every
User or UserGroup that references it is automatically
re-reconciled, so NiFi access policies are kept in sync without manual intervention.
All referenced AccessPolicyProfile resources must exist before the consuming
User or UserGroup is reconciled. If any profile is not found,
the reconciliation fails without updating NiFi and is retried until all profiles are
available.
