目录
1 文档目的..............................................................................................................................5
2 CDH 集群多租户...................................................................................................................5
2.1 身份认证...............................................................................................................................................5
2.2 权限控制...............................................................................................................................................7
2.3 资源管理.............................................................................................................................................11
3 租户管理............................................................................................................................14
3.1 账户身份管理.....................................................................................................................................15
3.2 资源管理.............................................................................................................................................16
3.3 权限控制.............................................................................................................................................16
4 Cloudera 安全方案.............................................................................................................17
4.1 Cloudera Security 需求........................................................................................................................17
4.2 Hadoop 集群安全之路........................................................................................................................18
5 Cloudera Security 参考架构................................................................................................19
5.1 整体架构.............................................................................................................................................19
6 认证与授权先决条件.........................................................................................................21
6.1 CDH License.........................................................................................................................................21
6.2 Root/sudo 访问...................................................................................................................................21
6.3 认证 Packages......................................................................................................................................21
6.4 Ac%ve Directory OU 和 OU 用户..........................................................................................................21
6.5 启用 Ac%ve Directory 的 SSL/TLS.........................................................................................................22
6.6 建议启用 Ac%ve Directory 高可用方案..............................................................................................22
6.7 Principal 与 Keytabs.............................................................................................................................22
6.8 特权用户的 Ac%ve Directory 群组......................................................................................................23
6.9 Ac%ve Directory 测试用户和群组.......................................................................................................23
6.10 多域/ Ac%ve Directory 域..................................................................................................................24
6.11 Direct-to-AD 方法的注意事项..........................................................................................................24
7 认证方案............................................................................................................................24
7.1 认证与 Kerberos..................................................................................................................................24
7.2 Cloudera Manager 启用外部认证.......................................................................................................30
7.3 Cloudera Navigator 启用外部认证......................................................................................................31
7.4 Hue 配置外部认证..............................................................................................................................32
7.5 Hive/Impala 启用 LDAP 认证...............................................................................................................33
8 授权方案............................................................................................................................34
8.1 Cloudera Security 授权........................................................................................................................34