Configure the Knox IDBroker in Cloudera Manager to enable the secure exchange of
scoped temporary credentials for data access in Azure environments.
For AWS environments, the Knox IDBroker is automatically configured with a read-only
session policy template that provides secure, read-only access to specific S3 paths
for data sharing scenarios. No manual IDBroker configuration is required for AWS.
For Azure environments, you must manually save the Knox IDBroker storage account
alias.
In Azure environments, go to Cloudera Manager > Knox > Configuration and search for Save Alias Command Input -
IDBroker.
Add the following alias, replacing the value with the Azure Data Lake Storage
Gen2 storage account name used by your environment:
Optional: To change how long vended User Delegation Shared Access Signature (SAS) tokens
remain valid before external clients must request new credentials, add the
following alias on the same Save Alias Command Input -
IDBroker field.
Specify the lifetime in seconds. If you do not set this alias, Knox IDBroker
uses a default of 1 hour (3600 seconds).