Skip to content

Conversation

@rich7420
Copy link

@rich7420 rich7420 commented Jan 1, 2026

What changes were proposed in this pull request?

Migrate the whole page in the v1 doc "Apache Ranger
" https://ozone.apache.org/docs/edge/security/securitywithranger.html minus the last section pertaining to the Ranger permissions,
to v2 doc page "Configuring Apache Ranger" https://ozone-site-v2.staged.apache.org/docs/administrator-guide/configuration/security/ranger

What is the link to the Apache Jira?

HDDS-14266

How was this patch tested?

Check off which of the following tests were done on this change. If additional testing was done, please elaborate here as well.

  • The CI checks on my fork are passing
  • I verified the rendered content using a local preview
  • I manually verified the steps provided in this change work as described

Copy link
Contributor

@jojochuang jojochuang left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm. will merge as is.

Some review comments added. We can address them later. @rich7420 please help open jiras to follow up.

Note this page just talks about initializing Ozone to perform authorization check using Ranger. It does not touch upon using Ranger to configure authorization policies for Ozone volume/bucket/key.

export OZONE_MANAGER_CLASSPATH="${OZONE_HOME}/share/ozone/lib/libext/*"
```

- The location of the ranger-ozone-plugin jars depends on where the Ranger Plugin is installed.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Not clear what this "ranger-ozone-plugin jars" is. A little explanation is needed.

cc @smengcl


To use Apache Ranger, you must have Apache Ranger installed in your Hadoop Cluster. For installation instructions of Apache Ranger, please take a look at the [Apache Ranger website](https://ranger.apache.org/index.html).

If you have a working Apache Ranger installation that is aware of Ozone, then configuring Ozone to work with Apache Ranger is trivial. You have to enable the ACLs support and set the acl authorizer class inside Ozone to be Ranger authorizer. Please add the following properties to the `ozone-site.xml`.
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

the configurations are to be added to the ozone-site.xml of Ozone Managers.

@jojochuang jojochuang merged commit 7e8f689 into apache:HDDS-9225-website-v2 Jan 1, 2026
11 checks passed
@rich7420
Copy link
Author

rich7420 commented Jan 1, 2026

thanks for the review @jojochuang ! I've opened a jira issue HDDS-14331.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants