Configuring NiFi access policy profiles

An AccessPolicyProfile is a reusable collection of NiFi access policies that User and UserGroup resources can share, including ProcessGroup references resolved at reconcile time.

Defining an AccessPolicyProfile

apiVersion: cfm.cloudera.com/v1alpha1
kind: AccessPolicyProfile
metadata:
  name: read-only-profile
  namespace: nifi
spec:
  accessPolicies:
    - actions: 
        - "read"
      resources:
        - /flow
        - /process-groups/root
    - actions: 
        - "read"
      resources:
        - /data/process-groups/root

Each entry in accessPolicies pairs one or more actions (read, write) with one or more NiFi resource paths.

An accessPolicies entry can also reference a ProcessGroup by name through resourceRefs instead of (or alongside) literal resources paths:

spec:
  accessPolicies:
    - actions:
        - read
      resourceRefs:
        - kind: ProcessGroup
          name: my-flow

Only kind: ProcessGroup is supported. Each accessPolicies entry must set at least one of resources or resourceRefs. Cloudera Flow Management Operator for Kubernetes accepts at most 500 resourceRefs per entry; this is an operator-side validation bound, not a NiFi limit. When both are set, the resolved /process-groups/<id> paths are combined with the literal resources into one policy sharing the entry's actions.

The ProcessGroup reference is resolved to /process-groups/<status.identifier> when a User or UserGroup that references this profile is reconciled. An AccessPolicyProfile is a shared data type with no controller of its own; the User and UserGroup controllers resolve its references when they reconcile.

Two points differ from an inline reference on a User or UserGroup:

  • A resourceRef inside a profile that omits namespace defaults to the profile's own namespace, not the namespace of the consuming User or UserGroup. Set namespace explicitly to reference a ProcessGroup elsewhere.

  • The referenced ProcessGroup must target the same Nifi instance as the consuming User or UserGroup. A mismatch is reported on the consumer's CompleteAccessPolicies condition with reason ProcessGroupTargetsDifferentNiFi and requires correcting the reference.

Unresolved references are skipped for the current reconcile and reported on the consuming resource's CompleteAccessPolicies condition; the policies that did resolve are still applied.

Referencing a profile from a User

Use accessPolicyProfileRef on the User to attach one or more profiles:

apiVersion: cfm.cloudera.com/v1alpha1
kind: User
metadata:
  name: alice
  namespace: nifi
spec:
  instanceTarget:
    name: my-nifi
    namespace: nifi
  identity: alice@example.com
  accessPolicyProfileRef:
    - name: read-only-profile
      namespace: nifi

Multiple profiles can be listed and their policies are unioned together:

accessPolicyProfileRef:
    - name: read-only-profile
      namespace: nifi
    - name: component-admin-profile
      namespace: nifi

The namespace field in each entry defaults to the User resource's own namespace when omitted.

Inline policies override profile policies

Policies defined directly in spec.accessPolicies take precedence over policies from referenced profiles. When the same NiFi resource appears in both places, the inline policy wins and the policy from the AccessPolicyProfile for that resource is ignored entirely.

spec:
  accessPolicies:
    # This write policy for /flow overrides any /flow policy from
    # the profile.
    - actions: ["read", "write"]
      resources:
        - /flow
  accessPolicyProfileRef:
    # has read-only /flow — ignored for /flow
    - name: read-only-profile
      namespace: nifi

The override is per-resource: other resources in the profile that are not covered by inline policies are still applied.

Reconciliation behavior

The User and UserGroup controllers watch AccessPolicyProfile resources. When a profile is updated, every User or UserGroup that references it is automatically re-reconciled, so NiFi access policies are kept in sync without manual intervention.

All referenced AccessPolicyProfile resources must exist before the consuming User or UserGroup is reconciled. If any profile is not found, the reconciliation fails without updating NiFi and is retried until all profiles are available.