Knox Gateway Diagnostics Collection Timeout |
The timeout in milliseconds to wait for diagnostics collection to complete. |
|
5 minute(s) |
csd_role_diagnostics_timeout
|
false |
Knox Simplified Topology Management - API Authentication Provider |
Authentication provider declaration used by pre-deinfed topologies such as admin, metadata or cdp-proxy-api. |
gateway_api_authentication_provider
|
role=authentication
authentication.name=ShiroProvider
authentication.param.sessionTimeout=30
authentication.param.main.pamRealm=org.apache.knox.gateway.shirorealm.KnoxPamRealm
authentication.param.main.pamRealm.service=login
authentication.param.urls./**=authcBasic |
gateway_api_authentication_provider
|
false |
Auto Discovery - Advanced Configuration Monitoring Interval |
Defines the frequency of Knox's service auto-discovery advanced configuration files (auto-discovery-advanced-configuration-[cdp-proxy|cdp-proxy-api].properties) monitoring. |
gateway.cloudera.manager.advanced.service.discovery.config.monitor.interval
|
10 second(s) |
gateway_auto_discovery_advanced_configuration_monitor_interval
|
false |
Enable Auto Discovery (cdp-proxy-api) - Atlas API |
Enables Knox auto-discovery for the Atlas API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.atlas-api
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_atlas
|
false |
Enable Auto Discovery (cdp-proxy-api) - Phoenix/Avatica |
Enables Knox auto-discovery for the Phoenix/Avatica API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.avatica
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_avatica
|
false |
Enable Auto Discovery (cdp-proxy-api) - Cloudera Manager API |
Enables Knox auto-discovery for the Cloudera Manager API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.cm-api
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_cm_api
|
false |
Enable Auto Discovery (cdp-proxy-api) - Cruise Control API |
Enables Knox auto-discovery for the Cruise Control API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.cruise-control-api
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_cruise_control
|
false |
Enable Auto Discovery (cdp-proxy-api) - Hive Server |
Enables Knox auto-discovery for the Hive Server in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.hive
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_hive
|
false |
Enable Auto Discovery (cdp-proxy-api) - Impala Catalog Server |
Enables Knox auto-discovery for the Impala Catalog Server in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.impala
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_impala
|
false |
Enable Auto Discovery (cdp-proxy-api) - Livy Server API |
Enables Knox auto-discovery for the Livy Server API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.livyserver
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_livyserver
|
false |
Enable Auto Discovery (cdp-proxy-api) - NameNode |
Enables Knox auto-discovery for the NameNode in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.namenode
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_namenode
|
false |
Enable Auto Discovery (cdp-proxy-api) - NiFi |
Enables Knox auto-discovery for the NiFi in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.nifi
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_nifi
|
false |
Enable Auto Discovery (cdp-proxy-api) - NiFi Registry |
Enables Knox auto-discovery for the NiFi Registry in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.nifi-registry
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_nifi_registry
|
false |
Enable Auto Discovery (cdp-proxy-api) - Oozie Server |
Enables Knox auto-discovery for the Oozie Server in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.oozie
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_oozie
|
false |
Enable Auto Discovery (cdp-proxy-api) - Profiler Admin API |
Enables Knox auto-discovery for the Profiler Admin API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.profiler-admin-api
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_profiler_admin_api
|
false |
Enable Auto Discovery (cdp-proxy-api) - Profiler Metrics API |
Enables Knox auto-discovery for the Profiler Metrics API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.profiler-metrics-api
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_profiler_metrics_api
|
false |
Enable Auto Discovery (cdp-proxy-api) - Profiler Scheduler API |
Enables Knox auto-discovery for the Profiler Scheduler API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.profiler-scheduler-api
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_profiler_scheduler_api
|
false |
Enable Auto Discovery (cdp-proxy-api) - Ranger Admin |
Enables Knox auto-discovery for the Ranger Admin in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.ranger
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_ranger
|
false |
Enable Auto Discovery (cdp-proxy-api) - ResourceManager |
Enables Knox auto-discovery for the ResourceManager in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.resourcemanager
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_resourcemanager
|
false |
Enable Auto Discovery (cdp-proxy-api) - Schema Registry API |
Enables Knox auto-discovery for the Schema Registry API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.schema-registry
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_schema_registry
|
false |
Enable Auto Discovery (cdp-proxy-api) - Stream Messaging Manager API |
Enables Knox auto-discovery for the Stream Messaging Manager API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.smm-api
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_smm
|
false |
Enable Auto Discovery (cdp-proxy-api) - Solr Server |
Enables Knox auto-discovery for the Solr Server in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.solr
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_solr
|
false |
Enable Auto Discovery (cdp-proxy-api) - HBase Master API |
Enables Knox auto-discovery for the HBase Master API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.webhbase
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_webhbase
|
false |
Enable Auto Discovery (cdp-proxy-api) - WebHDFS API |
Enables Knox auto-discovery for the WebHDFS API in the cdp-proxy-api topology. |
gateway.auto.discovery.cdp-proxy-api.enabled.webhdfs
|
true |
gateway_auto_discovery_cdp_proxy_api_enabled_webhdfs
|
false |
Enable Auto Discovery (cdp-proxy) - Atlas API |
Enables Knox auto-discovery for the Atlas API in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.atlas-api
|
true |
gateway_auto_discovery_cdp_proxy_enabled_atlas
|
false |
Enable Auto Discovery (cdp-proxy) - Atlas Web UI |
Enables Knox auto-discovery for the Atlas Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.atlas
|
true |
gateway_auto_discovery_cdp_proxy_enabled_atlas_ui
|
false |
Enable Auto Discovery (cdp-proxy) - Cloudera Manager API |
Enables Knox auto-discovery for the Cloudera Manager API in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.cm-api
|
true |
gateway_auto_discovery_cdp_proxy_enabled_cm_api
|
false |
Enable Auto Discovery (cdp-proxy) - Cloudera Manager Admin Console |
Enables Knox auto-discovery for the Cloudera Manager Admin Console in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.cm-ui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_cm_ui
|
false |
Enable Auto Discovery (cdp-proxy) - Data Analytics Studio |
Enables Knox auto-discovery for the Data Analytics Studio in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.das
|
true |
gateway_auto_discovery_cdp_proxy_enabled_das
|
false |
Enable Auto Discovery (cdp-proxy) - HBase Web UI |
Enables Knox auto-discovery for the HBase Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.hbaseui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_hbase_ui
|
false |
Enable Auto Discovery (cdp-proxy) - Namenode Web UI |
Enables Knox auto-discovery for the Namenode Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.hdfsui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_hdfs_ui
|
false |
Enable Auto Discovery (cdp-proxy) - Hue Server |
Enables Knox auto-discovery for the Hue Server in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.hue
|
true |
gateway_auto_discovery_cdp_proxy_enabled_hue
|
false |
Enable Auto Discovery (cdp-proxy) - Impala Catalog Server Web UI |
Enables Knox auto-discovery for the Impala Catalog Server Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.impalaui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_impala_ui
|
false |
Enable Auto Discovery (cdp-proxy) - HistoryServer Web UI |
Enables Knox auto-discovery for the HistoryServer Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.jobhistoryui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_jobhistory_ui
|
false |
Enable Auto Discovery (cdp-proxy) - Kudu Master Web UI |
Enables Knox auto-discovery for the Kudu Master Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.kuduui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_kudu_ui
|
false |
Enable Auto Discovery (cdp-proxy) - Livy Server Web UI |
Enables Knox auto-discovery for the Livy Server Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.livyserver
|
true |
gateway_auto_discovery_cdp_proxy_enabled_livyserver
|
false |
Enable Auto Discovery (cdp-proxy) - NameNode |
Enables Knox auto-discovery for the NameNode in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.namenode
|
true |
gateway_auto_discovery_cdp_proxy_enabled_namenode
|
false |
Enable Auto Discovery (cdp-proxy) - NiFi |
Enables Knox auto-discovery for the NiFi in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.nifi
|
true |
gateway_auto_discovery_cdp_proxy_enabled_nifi
|
false |
Enable Auto Discovery (cdp-proxy) - NiFi Registry |
Enables Knox auto-discovery for the NiFi Registry in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.nifi-registry
|
true |
gateway_auto_discovery_cdp_proxy_enabled_nifi_registry
|
false |
Enable Auto Discovery (cdp-proxy) - Oozie Server |
Enables Knox auto-discovery for the Oozie Server in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.oozie
|
true |
gateway_auto_discovery_cdp_proxy_enabled_oozie
|
false |
Enable Auto Discovery (cdp-proxy) - Oozie Web UI |
Enables Knox auto-discovery for the Oozie Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.oozieui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_oozie_ui
|
false |
Enable Auto Discovery (cdp-proxy) - Ranger Admin |
Enables Knox auto-discovery for the Ranger Admin in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.ranger
|
true |
gateway_auto_discovery_cdp_proxy_enabled_ranger
|
false |
Enable Auto Discovery (cdp-proxy) - Ranger Admin Web UI |
Enables Knox auto-discovery for the Ranger Admin Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.rangerui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_ranger_ui
|
false |
Enable Auto Discovery (cdp-proxy) - ResourceManager |
Enables Knox auto-discovery for the ResourceManager in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.resourcemanager
|
true |
gateway_auto_discovery_cdp_proxy_enabled_resourcemanager
|
false |
Enable Auto Discovery (cdp-proxy) - Stream Messaging Manager API |
Enables Knox auto-discovery for the Stream Messaging Manager API in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.smm-api
|
true |
gateway_auto_discovery_cdp_proxy_enabled_smm
|
false |
Enable Auto Discovery (cdp-proxy) - Stream Messaging Manager Web UI |
Enables Knox auto-discovery for the Stream Messaging Manager Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.smm-ui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_smm_ui
|
false |
Enable Auto Discovery (cdp-proxy) - Solr Server |
Enables Knox auto-discovery for the Solr Server in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.solr
|
true |
gateway_auto_discovery_cdp_proxy_enabled_solr
|
false |
Enable Auto Discovery (cdp-proxy) - Spark 3 History Server Web UI |
Enables Knox auto-discovery for the Spark 3 History Server Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.spark3historyui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_spark3history_ui
|
false |
Enable Auto Discovery (cdp-proxy) - Spark History Server Web UI |
Enables Knox auto-discovery for the Spark History Server Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.sparkhistoryui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_sparkhistory_ui
|
false |
Enable Auto Discovery (cdp-proxy) - ResourceManager Web UI |
Enables Knox auto-discovery for the ResourceManager Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.yarnui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_yarn_ui
|
false |
Enable Auto Discovery (cdp-proxy) - ResourceManager Web UI V2 |
Enables Knox auto-discovery for the ResourceManager Web UI V2 in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.yarnuiv2
|
true |
gateway_auto_discovery_cdp_proxy_enabled_yarn_ui_v2
|
false |
Enable Auto Discovery (cdp-proxy) - Zeppelin Server Web UI |
Enables Knox auto-discovery for the Zeppelin Server Web UI in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.zeppelinui
|
true |
gateway_auto_discovery_cdp_proxy_enabled_zeppelin_ui
|
false |
Enable Auto Discovery (cdp-proxy) - Zeppelin Server |
Enables Knox auto-discovery for the Zeppelin Server in the cdp-proxy topology. |
gateway.auto.discovery.cdp-proxy.enabled.zeppelinws
|
true |
gateway_auto_discovery_cdp_proxy_enabled_zeppelin_ws
|
false |
Enable/Disable Service Auto-Discovery |
Whether Knox's service auto-discovery feature is enabled |
gateway.auto.discovery.enabled
|
true |
gateway_auto_discovery_enabled
|
false |
Knox Simplified Topology Management - Monitoring Interval |
Defines the frequency of Cloudera Manager resources (descriptors and shared providers) file (cdp-resources.xml) monitoring. |
gateway.cloudera.manager.descriptors.monitor.interval
|
10 second(s) |
gateway_cloudera_manager_descriptors_monitor_interval
|
false |
Auto Discovery - Cluster Configuration Monitoring Interval |
Defines the frequency of cluster configuration monitoring. |
gateway.cluster.config.monitor.cm.interval
|
1 minute(s) |
gateway_cluster_configuration_monitor_interval
|
false |
Knox Gateway Configuration Directory |
Contains configuration files that apply to the gateway globally (i.e. not cluster specific ). |
gateway_conf_dir
|
/var/lib/knox/gateway/conf |
gateway_conf_dir
|
false |
Knox Gateway Data Directory |
Contains security and topology specific artifacts as well as important applications for admin-ui |
gateway_data_dir
|
/var/lib/knox/gateway/data |
gateway_data_dir
|
false |
Gateway - Default App Topology Name |
When a topology file is deployed with a file name that matches the configured default topology name, a specialized mapping for URLs is installed for that particular topology. This allows the URLs that are expected by the existing Hadoop CLIs for WebHDFS to be used in interacting with the specific Hadoop cluster that is represented by the default topology file. |
default.app.topology.name
|
cdp-proxy |
gateway_default_topology_name
|
false |
Knox Simplified Topology Management - cdp-proxy |
Knox descriptor block for 'cdp-proxy' topology. 'providerConfigRef' indicates the name of shared-provider the given descriptor would like to use. The rest of the entries hold service information. The structure of an service information entry is: $SERVICE_NAME[:$PARAMETER_NAME=$PARAMETER_VALUE]. The 'url' and 'version' parameter names are preserved keywords to set the given service's URL and version. For instance: HIVE:url=http://localhost:123, HIVE:version:3.0.0, HIVE:test.pramameter.name=test.parameter.value |
cdp-proxy
|
providerConfigRef=sso
CM-API:httpclient.connectionTimeout=5m
CM-API:httpclient.socketTimeout=5m
HUE:httpclient.connectionTimeout=5m
HUE:httpclient.socketTimeout=5m
IMPALA:httpclient.connectionTimeout=5m
IMPALA:httpclient.socketTimeout=5m
NIFI:useTwoWaySsl=true
NIFI-REGISTRY:useTwoWaySsl=true
RANGER:replayBufferSize=65 |
gateway_descriptor_cdp_proxy
|
false |
Knox Simplified Topology Management - cdp-proxy-api |
Knox descriptor block for 'cdp-proxy-api topology. 'providerConfigRef' indicates the name of shared-provider the given descriptor would like to use. The rest of the entries hold service information. The structure of an service information entry is: $SERVICE_NAME[:$PARAMETER_NAME=$PARAMETER_VALUE]. The 'url' and 'version' parameter names are preserved keywords to set the given service's URL and version. For instance: NIFI, HIVE:url=http://localhost:123, HIVE:version:3.0.0, HIVE:test.pramameter.name=test.parameter.value |
cdp-proxy-api
|
providerConfigRef=pam
CM-API:httpclient.connectionTimeout=5m
CM-API:httpclient.socketTimeout=5m
HIVE:httpclient.connectionTimeout=5m
HIVE:httpclient.socketTimeout=5m
IMPALA:httpclient.connectionTimeout=5m
IMPALA:httpclient.socketTimeout=5m
NIFI:useTwoWaySsl=true
NIFI-REGISTRY:useTwoWaySsl=true
RANGER:replayBufferSize=65 |
gateway_descriptor_cdp_proxy_api
|
false |
Knox Gateway Dispatch Whitelist |
The whitelist to be applied for dispatches associated with the service roles specified by gateway.dispatch.whitelist.services. By default this is replaced with DEFAULT or HTTPS_ONLY based on if TLS is enabled. |
gateway.dispatch.whitelist
|
WHITELIST_CONFIG_REPLACEME |
gateway_dispatch_whitelist
|
false |
Knox Gateway Dispatch Whitelist Services |
The comma-delimited list of service roles for which the 'gateway.dispatch.whitelist' should be applied |
gateway.dispatch.whitelist.services
|
DATANODE, HBASEUI, HDFSUI, IMPALAUI, JOBHISTORYUI, KUDUUI, NODEUI, YARNUI, YARNUIV2, knoxauth |
gateway_dispatch_whitelist_services
|
false |
Gateway Config Directory |
The directory within 'gateway_data_dir' that contains gateway topology files and deployments. |
gateway.gateway.conf.dir
|
deployments |
gateway_gateway_conf_dir
|
false |
Knox Gateway Initial/Max Heapsize |
Initial/Maximum size for the Java Process heap. Passed to Java -Xmx/-Xms. Measured in megabytes. |
gateway_heap_size
|
1 GiB |
gateway_heap_size
|
true |
Additional Gateway Java Options |
These arguments are passed as part of the Java command line. Commonly, garbage collection flags or extra debugging flags are passed here. -Xmx/-Xms should not be specified here: to set the heapsize use the 'Knox Gateway Initial/Max Heapsize' parameter |
gateway_java_opts
|
|
gateway_java_opts
|
false |
Admin Groups |
Admin groups for Knox |
gateway.knox.admin.groups
|
|
gateway_knox_admin_groups
|
false |
Knox Gateway Log Level |
The logging level of Knox Gateway |
gateway_log_level
|
ERROR |
gateway_log_level
|
false |
Knox Master Secret |
The master secret is used to access secured artifacts by the gateway instance. Keystore, trust stores and credential stores are all protected with the master secret. NOTE: changing the master secret will require you to change passwords protecting the keystores for the gateway, identity keystores and all credential stores |
gateway_master_secret
|
|
gateway_master_secret
|
true |
Gateway Path |
The default context path for the gateway. |
gateway.path
|
gateway |
gateway_path
|
true |
Ranger Knox Plugin Conf Path |
Staging directory for Ranger Knox Plugin Configuration. This should generally not be changed. |
gateway_ranger_knox_plugin_conf_path
|
/var/lib/knox/ranger-knox-plugin |
gateway_ranger_knox_plugin_conf_path
|
true |
Ranger Knox Plugin Audit Hdfs Spool Directory Path |
Spool directory for Ranger audits being written to DFS. |
xasecure.audit.destination.hdfs.batch.filespool.dir
|
/var/log/knox/gateway/audit/hdfs/spool |
gateway_ranger_knox_plugin_hdfs_audit_spool_directory
|
true |
Ranger Knox Plugin Policy Cache Directory Path |
The directory where Ranger security policies are cached locally. |
ranger.plugin.knox.policy.cache.dir
|
/var/lib/ranger/knox/gateway/policy-cache |
gateway_ranger_knox_plugin_policy_cache_directory
|
true |
Ranger Knox Plugin Audit Solr Spool Directory Path |
Spool directory for Ranger audits being written to Solr. |
xasecure.audit.destination.solr.batch.filespool.dir
|
/var/log/knox/gateway/audit/solr/spool |
gateway_ranger_knox_plugin_solr_audit_spool_directory
|
true |
Ranger Plugin Trusted Proxy IP Address |
Accepts a list of IP addresses of proxy servers for trusting. |
ranger.plugin.knox.trusted.proxy.ipaddress
|
|
gateway_ranger_plugin_trusted_proxy_ipaddress
|
false |
Ranger Plugin Use X-Forwarded For IP Address |
The parameter is used for identifying the originating IP address of a user connecting to a component through proxy for audit logs. |
ranger.plugin.knox.use.x-forwarded-for.ipaddress
|
false |
gateway_ranger_plugin_use_x_forwarded_for_ipaddress
|
false |
Cookie Scoping Enabled |
Enable/Disable cookie scoping feature. |
gateway.scope.cookies.feature.enabled
|
false |
gateway_scope_cookies_feature_enabled
|
false |
Security - Signing Key Alias |
The alias for the signing keypair within the keystore specified via gateway_signing_keystore_name |
gateway.signing.key.alias
|
|
gateway_signing_key_alias
|
false |
Security - Signing Keystore Name |
The filename of keystore file that contains the signing keypair |
gateway.signing.keystore.name
|
|
gateway_signing_keystore_name
|
false |
Security - Signing Keystore Type |
The type of the keystore file where the signing keypair is stored. See gateway_signing_keystore_name |
gateway.signing.keystore.type
|
|
gateway_signing_keystore_type
|
false |
Knox Simplified Topology Management - SSO Authentication Provider |
Authentication provider declaration used by the UIs using the Knox SSO capabilities such as the Admin and Home Page UIs. |
gateway_sso_authentication_provider
|
role=authentication
authentication.name=ShiroProvider
authentication.param.sessionTimeout=30
authentication.param.redirectToUrl=/$GATEWAY_PATH/knoxsso/knoxauth/login.html
authentication.param.restrictedCookies=rememberme, WWW-Authenticate
authentication.param.main.pamRealm=org.apache.knox.gateway.shirorealm.KnoxPamRealm
authentication.param.main.pamRealm.service=login
authentication.param.urls./**=authcBasic |
gateway_sso_authentication_provider
|
false |
Security - TLS Certificate Alias (Optional) |
The alias for the Gateway’s TLS certificate and keypair within the default keystore or the keystore specified via gateway.tls.keystore.path |
gateway_tls_certificate_alias
|
|
gateway_tls_certificate_alias
|
false |
Security - TLS Certificate Path (Optional) |
The path for the TLS certificate which Knox will import in the CM generated/distributed keystore in case SSL is enabled (if any). |
gateway_tls_certificate_path
|
|
gateway_tls_certificate_path
|
false |
Websockets Enabled |
Enable/Disable websocket feature. |
gateway.websocket.feature.enabled
|
true |
gateway_websocket_feature_enabled
|
false |
X-Forwarded Header Context Service Name |
The service name to be added in x-forward-context header. |
gateway.xforwarded.header.context.append.servicename
|
LIVYSERVER |
gateway_xforwarded_header_context_append_servicename
|
false |
Admin Group Mapping - Class Name |
The class name used for Hadoop admin group mapping |
gateway.group.config.hadoop.security.group.mapping
|
org.apache.hadoop.security.ShellBasedUnixGroupsMapping |
hadoop_security_group_mapping_class
|
false |
Hadoop Group Mapping - Negative Cache Expiration |
The Hadoop group mapping negative cache expiration in seconds |
gateway.group.config.hadoop.security.groups.negative-cache.secs
|
5 second(s) |
hadoop_security_group_negative_cache_expiration_seconds
|
false |
Hadoop Group Mapping - Positive Cache Expiration |
The Hadoop group mapping positive cache expiration in seconds |
gateway.group.config.hadoop.security.groups.cache.secs
|
10 second(s) |
hadoop_security_group_positive_cache_expiration_seconds
|
false |
krb5.conf Location |
Absolute path to krb5.conf file |
java.security.krb5.conf
|
/etc/krb5.conf |
java_security_krb5_conf
|
false |
KRB5 Debug |
Boolean flag indicating whether to enable debug messages for krb5 authentication |
sun.security.krb5.debug
|
false |
sun_security_krb5_debug
|
false |