Configuring Atlas Authorization
Atlas in CDP uses Ranger policies to control access to metadata that are managed by Atlas. Ranger policies also control access to Atlas administrative tasks.
Ranger provides authorization to access the following metadata and operations:
- Types
- Atlas "types" are the entity model definitions, whether provided in
Atlas or added in your environment. Types include these "categories":
- Entity
- Classification
- Relationship
- Business Metadata
- Struct
- Enum
- Entities
- Atlas "entities" are instances of entity types: entities represent
assets and processes on your cluster. Ranger authorization allows you
to configure access to users and groups to perform the following
operations on entities:
- Read
- Create
- Update
- Delete
- Read classification
- Add classification
- Update classification
- Remove classification
- Add label
- Remove label
- Update Business Metadata
- Relationships
- Atlas "relationships" describe connections between two entities, including, but not limited to, the input and output relationships that are used to build lineage graphs. Ranger authorization allows you to configure access to users and groups to perform the following operations on relationships:
- Admin operations
- Atlas administrative operations include:
- Import entities
- Export entities