Enabling S3 File Browser for Hue with RAZ in DataHub
Hue offers you the capability to browse S3 buckets, upload files to S3, and create tables by importing files from S3. With RAZ, you can grant fine-grained access to per-user home directories and other directories within the S3 bucket using Ranger policies.
Hue administrators can create home directories for users by selecting the Create home directory option on the user's profile in Hue. If fine-grained authorization is enabled to access S3 buckets, then user home directories are automatically created when a user logs into Hue. You can disable automatic creation of user directories.
- Register an AWS environment with the Enable Ranger authorization for AWS S3 option enabled. You can use the CDP web interface or the CDP CLI to complete this task.
- Create a Data Hub cluster with Data Engineering or Data Mart cluster template.
- Create the following Ranger policies:
- Hadoop SQL policy (all - database, table, column, all - url).
- S3 (cm_S3) policy (Default: User Home).
You must specify the bucket name in the S3 Bucket field and the directory path in the Path field of the cm_S3 Ranger policy.
- Grant appropriate permissions to the users in CDP User Management Service (UMS). For example, EnvironmentUser.