Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions .github/workflows/build.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -29,10 +29,10 @@ jobs:
with:
persist-credentials: false

- name: Set up JDK 11
- name: Set up JDK 17
uses: actions/setup-java@1bcf9fb12cf4aa7d266a90ae39939e61372fe520 # v5.4.0
with:
java-version: "11"
java-version: "17"
distribution: temurin
cache: maven

Expand Down
10 changes: 10 additions & 0 deletions .mvn/jvm.config
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
--add-exports jdk.compiler/com.sun.tools.javac.api=ALL-UNNAMED
--add-exports jdk.compiler/com.sun.tools.javac.file=ALL-UNNAMED
--add-exports jdk.compiler/com.sun.tools.javac.main=ALL-UNNAMED
--add-exports jdk.compiler/com.sun.tools.javac.model=ALL-UNNAMED
--add-exports jdk.compiler/com.sun.tools.javac.parser=ALL-UNNAMED
--add-exports jdk.compiler/com.sun.tools.javac.processing=ALL-UNNAMED
--add-exports jdk.compiler/com.sun.tools.javac.tree=ALL-UNNAMED
--add-exports jdk.compiler/com.sun.tools.javac.util=ALL-UNNAMED
--add-opens jdk.compiler/com.sun.tools.javac.code=ALL-UNNAMED
--add-opens jdk.compiler/com.sun.tools.javac.comp=ALL-UNNAMED
22 changes: 17 additions & 5 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,8 @@ The CoProcessor is built from source and included in the Stackable Apache HBase
## OPA authorizer

> [!IMPORTANT]
> The authorizer work best with product images for Apache HBase 2.6.0 (and later) as the HBase code in these versions provides more comprehensive coverage for ACL hooks.
> Version 1.x of the authorizer is built for Apache HBase 3.0.0 and requires Java 17.
> For Apache HBase 2.x, use the 0.3.x releases.

### Configuration

Expand All @@ -37,6 +38,8 @@ For every action a request similar to the one below is sent to OPA. The importan
- the namespace
- the table (optional: omitted when e.g. creating a namespace)
- the action (one of `READ`, `WRITE`, `EXEC`, `CREATE`, `ADMIN`)
- the operation type of data access requests (e.g. `GET`, `SCAN`, `PUT`, `DELETE`; `NONE` for administrative actions)
- the column families and qualifiers being accessed (`families`, empty when the request is not restricted to specific families)

```json
{
Expand Down Expand Up @@ -86,13 +89,22 @@ The following actions are subject to ACL checks:
- creation and deletion of tables
- enabling and disabling of tables
- truncation and modification of tables
- modification of store file trackers (table, column family)
- reading data (`Get`, `Scan`)
- writing data (`Put`, `Append`, `Delete`)
- batch mutations
- moving, assigning and unassigning regions
- snapshot operations (create, list, clone, restore, delete)
- bulk loading of HFiles
- quotas and throttling
- balancer
- replication peer management (including sync replication state transitions)
- cluster management (stopping the Master and RegionServers, shutdown, decommissioning, clearing dead servers)
- procedures and locks
- split and merge switches

The following actions are currently excluded but will be included in future releases:

- modification of store file trackers (table, column family)
- moving, assigning and unassigning tables
- snapshot operations (create, list, clone, restore, delete)
- bulk loading of HFiles
- RSGroup management
- listing namespaces
- reading cluster metrics
66 changes: 54 additions & 12 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -5,7 +5,7 @@

<groupId>tech.stackable</groupId>
<artifactId>hbase-opa-authorizer</artifactId>
<version>0.3.0</version>
<version>1.0.0</version>
<packaging>jar</packaging>

<name>Apache Hadoop HBase OPA Authorizer</name>
Expand All @@ -31,7 +31,7 @@
</issueManagement>

<properties>
<java.version>11</java.version>
<java.version>17</java.version>
<maven.compiler.source>${java.version}</maven.compiler.source>
<maven.compiler.target>${java.version}</maven.compiler.target>
<maven.compiler.release>${java.version}</maven.compiler.release>
Expand All @@ -52,22 +52,36 @@
<maven-surefire-plugin.version>3.5.5</maven-surefire-plugin.version>
<spotless-maven-plugin.version>2.44.5</spotless-maven-plugin.version>

<hbase.version>2.6.4</hbase.version>
<hbase.protobuf.version>2.5.0</hbase.protobuf.version>
<hbase.version>3.0.0</hbase.version>
<hbase-thirdparty.version>4.1.14</hbase-thirdparty.version>
<caffeine.version>3.2.0</caffeine.version>
<opa.version>1.12.3</opa.version>
<opa.version>1.20.2</opa.version>

<junit.version>5.13.4</junit.version>
</properties>

<dependencyManagement>
<dependencies>
<dependency>
<groupId>org.junit</groupId>
<artifactId>junit-bom</artifactId>
<version>${junit.version}</version>
<type>pom</type>
<scope>import</scope>
</dependency>
</dependencies>
</dependencyManagement>

<dependencies>
<dependency>
<groupId>com.github.ben-manes.caffeine</groupId>
<artifactId>caffeine</artifactId>
<version>${caffeine.version}</version>
</dependency>
<dependency>
<groupId>com.google.protobuf</groupId>
<artifactId>protobuf-java</artifactId>
<version>${hbase.protobuf.version}</version>
<groupId>org.apache.hbase.thirdparty</groupId>
<artifactId>hbase-shaded-protobuf</artifactId>
<version>${hbase-thirdparty.version}</version>
<scope>provided</scope>
</dependency>
<dependency>
Expand Down Expand Up @@ -123,13 +137,18 @@
<dependency>
<groupId>com.fasterxml.jackson.core</groupId>
<artifactId>jackson-databind</artifactId>
<version>2.12.7.1</version>
<!-- provided by HBase at runtime: keep in line with the HBase version (HBase 3.0.0: 2.21.1) -->
<version>2.21.1</version>
<scope>provided</scope>
</dependency>
<dependency>
<groupId>junit</groupId>
<artifactId>junit</artifactId>
<version>4.13.2</version>
<groupId>org.junit.jupiter</groupId>
<artifactId>junit-jupiter-api</artifactId>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.junit.jupiter</groupId>
<artifactId>junit-jupiter-engine</artifactId>
<scope>test</scope>
</dependency>
<dependency>
Expand Down Expand Up @@ -271,6 +290,29 @@
<groupId>org.apache.maven.plugins</groupId>
<artifactId>maven-surefire-plugin</artifactId>
<version>${maven-surefire-plugin.version}</version>
<configuration>
<!-- Same JVM flags HBase 3.0.0 uses for its own tests (hbase-surefire.jdk17.flags) -->
<argLine>
-Dorg.apache.hbase.thirdparty.io.netty.tryReflectionSetAccessible=true
--add-modules jdk.unsupported
--add-opens java.base/java.io=ALL-UNNAMED
--add-opens java.base/java.nio=ALL-UNNAMED
--add-opens java.base/sun.nio.ch=ALL-UNNAMED
--add-opens java.base/java.lang=ALL-UNNAMED
--add-opens java.base/jdk.internal.ref=ALL-UNNAMED
--add-opens java.base/java.lang.reflect=ALL-UNNAMED
--add-opens java.base/java.util=ALL-UNNAMED
--add-opens java.base/java.util.concurrent=ALL-UNNAMED
--add-exports java.base/jdk.internal.misc=ALL-UNNAMED
--add-exports java.security.jgss/sun.security.krb5=ALL-UNNAMED
--add-exports java.base/sun.net.dns=ALL-UNNAMED
--add-exports java.base/sun.net.util=ALL-UNNAMED
--add-opens java.base/jdk.internal.util.random=ALL-UNNAMED
--add-opens java.base/sun.security.x509=ALL-UNNAMED
--add-opens java.base/sun.security.util=ALL-UNNAMED
--add-opens java.base/java.net=ALL-UNNAMED
</argLine>
</configuration>
</plugin>
<plugin>
<groupId>com.googlecode.maven-download-plugin</groupId>
Expand Down
Loading
Loading