AMBARI-19795 Ambari upgrade to not add ranger plugin configs under ranger plugin supported services (mugdha)
Project: http://git-wip-us.apache.org/repos/asf/ambari/repo Commit: http://git-wip-us.apache.org/repos/asf/ambari/commit/f7bb18db Tree: http://git-wip-us.apache.org/repos/asf/ambari/tree/f7bb18db Diff: http://git-wip-us.apache.org/repos/asf/ambari/diff/f7bb18db Branch: refs/heads/branch-2.5 Commit: f7bb18db4928995e4a05804bf51b7ff08313cbf8 Parents: 5a9f381 Author: Mugdha Varadkar <[email protected]> Authored: Fri Feb 3 15:06:15 2017 +0530 Committer: Mugdha Varadkar <[email protected]> Committed: Mon Feb 6 13:27:51 2017 +0530 ---------------------------------------------------------------------- .../0.9.0/configuration/ranger-kafka-audit.xml | 32 ++++----- .../ranger-kafka-plugin-properties.xml | 14 ++-- .../ranger-kafka-policymgr-ssl.xml | 12 ++-- .../configuration/ranger-kafka-security.xml | 12 ++-- .../ranger-knox-plugin-properties.xml | 12 ++-- .../0.10.0/configuration/ranger-storm-audit.xml | 32 ++++----- .../ranger-storm-policymgr-ssl.xml | 12 ++-- .../configuration/ranger-storm-security.xml | 12 ++-- .../ranger-storm-plugin-properties.xml | 71 -------------------- .../ranger-hbase-plugin-properties.xml | 10 +-- .../ranger-hdfs-plugin-properties.xml | 12 ++-- .../ranger-hive-plugin-properties.xml | 10 +-- .../ranger-knox-plugin-properties.xml | 2 +- .../HBASE/configuration/ranger-hbase-audit.xml | 32 ++++----- .../ranger-hbase-policymgr-ssl.xml | 12 ++-- .../configuration/ranger-hbase-security.xml | 14 ++-- .../configuration/ranger-hdfs-policymgr-ssl.xml | 12 ++-- .../HDFS/configuration/ranger-hdfs-security.xml | 14 ++-- .../HIVE/configuration/ranger-hive-audit.xml | 32 ++++----- .../configuration/ranger-hive-policymgr-ssl.xml | 12 ++-- .../HIVE/configuration/ranger-hive-security.xml | 14 ++-- .../ranger-kafka-policymgr-ssl.xml | 4 +- .../KNOX/configuration/ranger-knox-audit.xml | 32 ++++----- .../configuration/ranger-knox-policymgr-ssl.xml | 12 ++-- .../KNOX/configuration/ranger-knox-security.xml | 12 ++-- .../ranger-storm-policymgr-ssl.xml | 4 +- .../configuration/ranger-storm-security.xml | 2 +- .../YARN/configuration/ranger-yarn-audit.xml | 32 ++++----- .../ranger-yarn-plugin-properties.xml | 12 ++-- .../configuration/ranger-yarn-policymgr-ssl.xml | 12 ++-- .../YARN/configuration/ranger-yarn-security.xml | 12 ++-- .../ATLAS/configuration/ranger-atlas-audit.xml | 18 ++--- .../ranger-atlas-plugin-properties.xml | 58 ++-------------- .../ranger-atlas-policymgr-ssl.xml | 12 ++-- .../configuration/ranger-atlas-security.xml | 14 ++-- .../ranger-hbase-plugin-properties.xml | 71 -------------------- .../ranger-hdfs-plugin-properties.xml | 50 +------------- .../ranger-hive-plugin-properties.xml | 71 -------------------- .../HIVE/configuration/ranger-hive-security.xml | 2 +- .../ranger-kafka-plugin-properties.xml | 71 -------------------- .../ranger-knox-plugin-properties.xml | 71 -------------------- .../ranger-storm-policymgr-ssl.xml | 4 +- .../configuration/ranger-storm-security.xml | 2 +- .../ranger-yarn-plugin-properties.xml | 71 -------------------- .../ranger-atlas-plugin-properties.xml | 71 ++++++++++++++++++++ .../ranger-hbase-plugin-properties.xml | 71 ++++++++++++++++++++ .../ranger-hdfs-plugin-properties.xml | 70 +++++++++++++++++++ .../ranger-hive-plugin-properties.xml | 71 ++++++++++++++++++++ .../ranger-kafka-plugin-properties.xml | 71 ++++++++++++++++++++ .../ranger-knox-plugin-properties.xml | 71 ++++++++++++++++++++ .../ranger-storm-plugin-properties.xml | 71 ++++++++++++++++++++ .../ranger-yarn-plugin-properties.xml | 71 ++++++++++++++++++++ 52 files changed, 823 insertions(+), 778 deletions(-) ---------------------------------------------------------------------- http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-audit.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-audit.xml b/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-audit.xml index 5257549..b4c0790 100644 --- a/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-audit.xml +++ b/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-audit.xml @@ -23,7 +23,7 @@ <name>xasecure.audit.is.enabled</name> <value>true</value> <description>Is Audit enabled?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db</name> @@ -39,19 +39,19 @@ <name>xasecure.audit.destination.db</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.url</name> <value>{{audit_jdbc_url}}</value> <description>Audit DB JDBC URL</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.user</name> <value>{{xa_audit_db_user}}</value> <description>Audit DB JDBC User</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.password</name> @@ -61,25 +61,25 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.driver</name> <value>{{jdbc_driver}}</value> <description>Audit DB JDBC Driver</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.credential.provider.file</name> <value>jceks://file{{credential_file}}</value> <description>Credential file store</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.batch.filespool.dir</name> <value>/var/log/kafka/audit/db/spool</value> <description>/var/log/kafka/audit/db/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs</name> @@ -95,7 +95,7 @@ <name>xasecure.audit.destination.hdfs</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.dir</name> @@ -107,13 +107,13 @@ <name>xasecure.audit.destination.hdfs.dir</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.batch.filespool.dir</name> <value>/var/log/kafka/audit/hdfs/spool</value> <description>/var/log/kafka/audit/hdfs/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr</name> @@ -129,7 +129,7 @@ <name>xasecure.audit.destination.solr</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.urls</name> @@ -144,7 +144,7 @@ <name>ranger.audit.solr.urls</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.zookeepers</name> @@ -156,13 +156,13 @@ <name>ranger.audit.solr.zookeepers</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.batch.filespool.dir</name> <value>/var/log/kafka/audit/solr/spool</value> <description>/var/log/kafka/audit/solr/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.provider.summary.enabled</name> @@ -172,6 +172,6 @@ <value-attributes> <type>boolean</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-plugin-properties.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-plugin-properties.xml b/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-plugin-properties.xml index 7f594a0..3949402 100644 --- a/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-plugin-properties.xml +++ b/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-plugin-properties.xml @@ -24,7 +24,7 @@ <value>ambari-qa</value> <display-name>Policy user for KAFKA</display-name> <description>This user must be system user and also present at Ranger admin portal</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>hadoop.rpc.protection</name> @@ -33,7 +33,7 @@ <value-attributes> <empty-value-valid>true</empty-value-valid> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>common.name.for.certificate</name> @@ -42,13 +42,13 @@ <value-attributes> <empty-value-valid>true</empty-value-valid> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>zookeeper.connect</name> <value>localhost:2181</value> <description>Used for repository creation on ranger admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger-kafka-plugin-enabled</name> @@ -65,14 +65,14 @@ <type>boolean</type> <overridable>false</overridable> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_USERNAME</name> <value>kafka</value> <display-name>Ranger repository config user</display-name> <description>Used for repository creation on ranger admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_PASSWORD</name> @@ -83,6 +83,6 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-policymgr-ssl.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-policymgr-ssl.xml b/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-policymgr-ssl.xml index f0fc160..cf4a82e 100644 --- a/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-policymgr-ssl.xml +++ b/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-policymgr-ssl.xml @@ -23,7 +23,7 @@ <name>xasecure.policymgr.clientssl.keystore</name> <value>kafkadev-clientcert.jks</value> <description>Java Keystore files</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.password</name> @@ -33,13 +33,13 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore</name> <value>cacerts-xasecure.jks</value> <description>java truststore file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.password</name> @@ -49,18 +49,18 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.credential.file</name> <value>jceks://file/{{credential_file}}</value> <description>java keystore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.credential.file</name> <value>jceks://file/{{credential_file}}</value> <description>java truststore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-security.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-security.xml b/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-security.xml index a9f84a4..47ea2a8 100644 --- a/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-security.xml +++ b/ambari-server/src/main/resources/common-services/KAFKA/0.9.0/configuration/ranger-kafka-security.xml @@ -23,19 +23,19 @@ <name>ranger.plugin.kafka.service.name</name> <value>{{repo_name}}</value> <description>Name of the Ranger service containing policies for this Kafka instance</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.kafka.policy.source.impl</name> <value>org.apache.ranger.admin.client.RangerAdminRESTClient</value> <description>Class to retrieve policies from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.kafka.policy.rest.url</name> <value>{{policymgr_mgr_url}}</value> <description>URL to Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> <depends-on> <property> <type>admin-properties</type> @@ -47,18 +47,18 @@ <name>ranger.plugin.kafka.policy.rest.ssl.config.file</name> <value>/etc/kafka/conf/ranger-policymgr-ssl.xml</value> <description>Path to the file containing SSL details to contact Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.kafka.policy.pollIntervalMs</name> <value>30000</value> <description>How often to poll for changes in policies?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.kafka.policy.cache.dir</name> <value>/etc/ranger/{{repo_name}}/policycache</value> <description>Directory where Ranger policies are cached after successful retrieval from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/common-services/KNOX/0.5.0.2.2/configuration/ranger-knox-plugin-properties.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/common-services/KNOX/0.5.0.2.2/configuration/ranger-knox-plugin-properties.xml b/ambari-server/src/main/resources/common-services/KNOX/0.5.0.2.2/configuration/ranger-knox-plugin-properties.xml index 7f85667..ae9314b 100644 --- a/ambari-server/src/main/resources/common-services/KNOX/0.5.0.2.2/configuration/ranger-knox-plugin-properties.xml +++ b/ambari-server/src/main/resources/common-services/KNOX/0.5.0.2.2/configuration/ranger-knox-plugin-properties.xml @@ -24,7 +24,7 @@ <value>ambari-qa</value> <display-name>Policy user for KNOX</display-name> <description>This user must be system user and also present at Ranger admin portal</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>common.name.for.certificate</name> @@ -33,7 +33,7 @@ <value-attributes> <empty-value-valid>true</empty-value-valid> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger-knox-plugin-enabled</name> @@ -50,14 +50,14 @@ <type>boolean</type> <overridable>false</overridable> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_USERNAME</name> <value>admin</value> <display-name>Ranger repository config user</display-name> <description>Used for repository creation on ranger admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_PASSWORD</name> @@ -68,14 +68,14 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>KNOX_HOME</name> <value>/usr/local/knox-server</value> <display-name>Knox Home</display-name> <description>Knox home folder</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>XAAUDIT.DB.IS_ENABLED</name> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-audit.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-audit.xml b/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-audit.xml index b7cf4c5..4dc51eb 100644 --- a/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-audit.xml +++ b/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-audit.xml @@ -23,7 +23,7 @@ <name>xasecure.audit.is.enabled</name> <value>true</value> <description>Is Audit enabled?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db</name> @@ -39,19 +39,19 @@ <name>xasecure.audit.destination.db</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.url</name> <value>{{audit_jdbc_url}}</value> <description>Audit DB JDBC URL</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.user</name> <value>{{xa_audit_db_user}}</value> <description>Audit DB JDBC User</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.password</name> @@ -61,25 +61,25 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.driver</name> <value>{{jdbc_driver}}</value> <description>Audit DB JDBC Driver</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.credential.provider.file</name> <value>jceks://file{{credential_file}}</value> <description>Credential file store</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.batch.filespool.dir</name> <value>/var/log/storm/audit/db/spool</value> <description>/var/log/storm/audit/db/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs</name> @@ -95,7 +95,7 @@ <name>xasecure.audit.destination.hdfs</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.dir</name> @@ -107,13 +107,13 @@ <name>xasecure.audit.destination.hdfs.dir</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.batch.filespool.dir</name> <value>/var/log/storm/audit/hdfs/spool</value> <description>/var/log/storm/audit/hdfs/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr</name> @@ -129,7 +129,7 @@ <name>xasecure.audit.destination.solr</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.urls</name> @@ -144,7 +144,7 @@ <name>ranger.audit.solr.urls</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.zookeepers</name> @@ -156,13 +156,13 @@ <name>ranger.audit.solr.zookeepers</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.batch.filespool.dir</name> <value>/var/log/storm/audit/solr/spool</value> <description>/var/log/storm/audit/solr/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.provider.summary.enabled</name> @@ -172,6 +172,6 @@ <value-attributes> <type>boolean</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-policymgr-ssl.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-policymgr-ssl.xml b/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-policymgr-ssl.xml index 9592914..b1f6e1e 100644 --- a/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-policymgr-ssl.xml +++ b/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-policymgr-ssl.xml @@ -23,7 +23,7 @@ <name>xasecure.policymgr.clientssl.keystore</name> <value>hadoopdev-clientcert.jks</value> <description>Java Keystore files</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.password</name> @@ -33,13 +33,13 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore</name> <value>cacerts-xasecure.jks</value> <description>java truststore file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.password</name> @@ -49,18 +49,18 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java keystore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java truststore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-security.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-security.xml b/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-security.xml index 84e394b4..b72b302 100644 --- a/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-security.xml +++ b/ambari-server/src/main/resources/common-services/STORM/0.10.0/configuration/ranger-storm-security.xml @@ -23,19 +23,19 @@ <name>ranger.plugin.storm.service.name</name> <value>{{repo_name}}</value> <description>Name of the Ranger service containing policies for this Storm instance</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.storm.policy.source.impl</name> <value>org.apache.ranger.admin.client.RangerAdminRESTClient</value> <description>Class to retrieve policies from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.storm.policy.rest.url</name> <value>{{policymgr_mgr_url}}</value> <description>URL to Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> <depends-on> <property> <type>admin-properties</type> @@ -47,18 +47,18 @@ <name>ranger.plugin.storm.policy.rest.ssl.config.file</name> <value>/etc/storm/conf/ranger-policymgr-ssl.xml</value> <description>Path to the file containing SSL details to contact Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.storm.policy.pollIntervalMs</name> <value>30000</value> <description>How often to poll for changes in policies?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.storm.policy.cache.dir</name> <value>/etc/ranger/{{repo_name}}/policycache</value> <description>Directory where Ranger policies are cached after successful retrieval from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/common-services/STORM/1.0.1/configuration/ranger-storm-plugin-properties.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/common-services/STORM/1.0.1/configuration/ranger-storm-plugin-properties.xml b/ambari-server/src/main/resources/common-services/STORM/1.0.1/configuration/ranger-storm-plugin-properties.xml deleted file mode 100644 index 3450970..0000000 --- a/ambari-server/src/main/resources/common-services/STORM/1.0.1/configuration/ranger-storm-plugin-properties.xml +++ /dev/null @@ -1,71 +0,0 @@ -<?xml version="1.0" encoding="UTF-8"?> -<!-- -/** - * Licensed to the Apache Software Foundation (ASF) under one - * or more contributor license agreements. See the NOTICE file - * distributed with this work for additional information - * regarding copyright ownership. The ASF licenses this file - * to you under the Apache License, Version 2.0 (the - * "License"); you may not use this file except in compliance - * with the License. You may obtain a copy of the License at - * - * http://www.apache.org/licenses/LICENSE-2.0 - * - * Unless required by applicable law or agreed to in writing, software - * distributed under the License is distributed on an "AS IS" BASIS, - * WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. - * See the License for the specific language governing permissions and - * limitations under the License. - */ ---> -<configuration> - - <property> - <name>external_admin_username</name> - <value></value> - <display-name>External Ranger admin username</display-name> - <description>Add ranger default admin username if want to communicate to external ranger</description> - <value-attributes> - <empty-value-valid>true</empty-value-valid> - </value-attributes> - <on-ambari-upgrade add="true"/> - </property> - - <property> - <name>external_admin_password</name> - <value></value> - <display-name>External Ranger admin password</display-name> - <property-type>PASSWORD</property-type> - <description>Add ranger default admin password if want to communicate to external ranger</description> - <value-attributes> - <type>password</type> - <empty-value-valid>true</empty-value-valid> - </value-attributes> - <on-ambari-upgrade add="true"/> - </property> - - <property> - <name>external_ranger_admin_username</name> - <value></value> - <display-name>External Ranger Ambari admin username</display-name> - <description>Add ranger default ambari admin username if want to communicate to external ranger</description> - <value-attributes> - <empty-value-valid>true</empty-value-valid> - </value-attributes> - <on-ambari-upgrade add="true"/> - </property> - - <property> - <name>external_ranger_admin_password</name> - <value></value> - <display-name>External Ranger Ambari admin password</display-name> - <property-type>PASSWORD</property-type> - <description>Add ranger default ambari admin password if want to communicate to external ranger</description> - <value-attributes> - <type>password</type> - <empty-value-valid>true</empty-value-valid> - </value-attributes> - <on-ambari-upgrade add="true"/> - </property> - -</configuration> \ No newline at end of file http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.2/services/HBASE/configuration/ranger-hbase-plugin-properties.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.2/services/HBASE/configuration/ranger-hbase-plugin-properties.xml b/ambari-server/src/main/resources/stacks/HDP/2.2/services/HBASE/configuration/ranger-hbase-plugin-properties.xml index 0de538d..960c751 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.2/services/HBASE/configuration/ranger-hbase-plugin-properties.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.2/services/HBASE/configuration/ranger-hbase-plugin-properties.xml @@ -26,7 +26,7 @@ <value-attributes> <empty-value-valid>true</empty-value-valid> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>policy_user</name> @@ -39,7 +39,7 @@ </property> </depends-on> <description>This user must be system user and also present at Ranger admin portal</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger-hbase-plugin-enabled</name> @@ -56,14 +56,14 @@ <name>ranger-hbase-plugin-enabled</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_USERNAME</name> <value>hbase</value> <display-name>Ranger repository config user</display-name> <description>Used for repository creation on ranger admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_PASSWORD</name> @@ -74,7 +74,7 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>XAAUDIT.DB.IS_ENABLED</name> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.2/services/HDFS/configuration/ranger-hdfs-plugin-properties.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.2/services/HDFS/configuration/ranger-hdfs-plugin-properties.xml b/ambari-server/src/main/resources/stacks/HDP/2.2/services/HDFS/configuration/ranger-hdfs-plugin-properties.xml index 7460d26..c57c5f0 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.2/services/HDFS/configuration/ranger-hdfs-plugin-properties.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.2/services/HDFS/configuration/ranger-hdfs-plugin-properties.xml @@ -17,7 +17,7 @@ <display-name>Policy user for HDFS</display-name> <description>This user must be system user and also present at Ranger admin portal</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>hadoop.rpc.protection</name> @@ -27,7 +27,7 @@ <value-attributes> <empty-value-valid>true</empty-value-valid> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>common.name.for.certificate</name> @@ -36,7 +36,7 @@ <value-attributes> <empty-value-valid>true</empty-value-valid> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger-hdfs-plugin-enabled</name> @@ -53,7 +53,7 @@ <type>boolean</type> <overridable>false</overridable> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_USERNAME</name> @@ -61,7 +61,7 @@ <display-name>Ranger repository config user</display-name> <description>Used for repository creation on ranger admin </description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_PASSWORD</name> @@ -73,7 +73,7 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>XAAUDIT.DB.IS_ENABLED</name> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.2/services/HIVE/configuration/ranger-hive-plugin-properties.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.2/services/HIVE/configuration/ranger-hive-plugin-properties.xml b/ambari-server/src/main/resources/stacks/HDP/2.2/services/HIVE/configuration/ranger-hive-plugin-properties.xml index 0db5565..830c539 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.2/services/HIVE/configuration/ranger-hive-plugin-properties.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.2/services/HIVE/configuration/ranger-hive-plugin-properties.xml @@ -24,13 +24,13 @@ <value>ambari-qa</value> <display-name>Policy user for HIVE</display-name> <description>This user must be system user and also present at Ranger admin portal</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>jdbc.driverClassName</name> <value>org.apache.hive.jdbc.HiveDriver</value> <description>Used for repository creation on ranger admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>common.name.for.certificate</name> @@ -39,14 +39,14 @@ <value-attributes> <empty-value-valid>true</empty-value-valid> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_USERNAME</name> <value>hive</value> <display-name>Ranger repository config user</display-name> <description>Used for repository creation on ranger admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_PASSWORD</name> @@ -57,7 +57,7 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>XAAUDIT.DB.IS_ENABLED</name> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.2/services/KNOX/configuration/ranger-knox-plugin-properties.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.2/services/KNOX/configuration/ranger-knox-plugin-properties.xml b/ambari-server/src/main/resources/stacks/HDP/2.2/services/KNOX/configuration/ranger-knox-plugin-properties.xml index ad2b1e4..d5880dd 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.2/services/KNOX/configuration/ranger-knox-plugin-properties.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.2/services/KNOX/configuration/ranger-knox-plugin-properties.xml @@ -24,6 +24,6 @@ <value>/usr/hdp/current/knox-server</value> <display-name>Knox Home</display-name> <description>Knox home folder</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-audit.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-audit.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-audit.xml index f670d7e..85c16c8 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-audit.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-audit.xml @@ -23,7 +23,7 @@ <name>xasecure.audit.is.enabled</name> <value>true</value> <description>Is Audit enabled?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db</name> @@ -39,19 +39,19 @@ <name>xasecure.audit.destination.db</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.url</name> <value>{{audit_jdbc_url}}</value> <description>Audit DB JDBC URL</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.user</name> <value>{{xa_audit_db_user}}</value> <description>Audit DB JDBC User</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.password</name> @@ -61,25 +61,25 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.driver</name> <value>{{jdbc_driver}}</value> <description>Audit DB JDBC Driver</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.credential.provider.file</name> <value>jceks://file{{credential_file}}</value> <description>Credential file store</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.batch.filespool.dir</name> <value>/var/log/hbase/audit/db/spool</value> <description>/var/log/hbase/audit/db/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs</name> @@ -95,7 +95,7 @@ <name>xasecure.audit.destination.hdfs</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.dir</name> @@ -107,13 +107,13 @@ <name>xasecure.audit.destination.hdfs.dir</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.batch.filespool.dir</name> <value>/var/log/hbase/audit/hdfs/spool</value> <description>/var/log/hbase/audit/hdfs/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr</name> @@ -129,7 +129,7 @@ <name>xasecure.audit.destination.solr</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.urls</name> @@ -144,7 +144,7 @@ <name>ranger.audit.solr.urls</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.zookeepers</name> @@ -156,13 +156,13 @@ <name>ranger.audit.solr.zookeepers</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.batch.filespool.dir</name> <value>/var/log/hbase/audit/solr/spool</value> <description>/var/log/hbase/audit/solr/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.provider.summary.enabled</name> @@ -172,6 +172,6 @@ <value-attributes> <type>boolean</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-policymgr-ssl.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-policymgr-ssl.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-policymgr-ssl.xml index 79370bc..c761b26 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-policymgr-ssl.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-policymgr-ssl.xml @@ -23,7 +23,7 @@ <name>xasecure.policymgr.clientssl.keystore</name> <value>/usr/hdp/current/hbase-client/conf/ranger-plugin-keystore.jks</value> <description>Java Keystore files</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.password</name> @@ -33,13 +33,13 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore</name> <value>/usr/hdp/current/hbase-client/conf/ranger-plugin-truststore.jks</value> <description>java truststore file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.password</name> @@ -49,18 +49,18 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java keystore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java truststore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-security.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-security.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-security.xml index 0ad5e60..4a0909a 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-security.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HBASE/configuration/ranger-hbase-security.xml @@ -23,19 +23,19 @@ <name>ranger.plugin.hbase.service.name</name> <value>{{repo_name}}</value> <description>Name of the Ranger service containing HBase policies</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hbase.policy.source.impl</name> <value>org.apache.ranger.admin.client.RangerAdminRESTClient</value> <description>Class to retrieve policies from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hbase.policy.rest.url</name> <value>{{policymgr_mgr_url}}</value> <description>URL to Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> <depends-on> <property> <type>admin-properties</type> @@ -47,19 +47,19 @@ <name>ranger.plugin.hbase.policy.rest.ssl.config.file</name> <value>/etc/hbase/conf/ranger-policymgr-ssl.xml</value> <description>Path to the file containing SSL details to contact Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hbase.policy.pollIntervalMs</name> <value>30000</value> <description>How often to poll for changes in policies?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hbase.policy.cache.dir</name> <value>/etc/ranger/{{repo_name}}/policycache</value> <description>Directory where Ranger policies are cached after successful retrieval from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.hbase.update.xapolicies.on.grant.revoke</name> @@ -69,6 +69,6 @@ <value-attributes> <type>boolean</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/HDFS/configuration/ranger-hdfs-policymgr-ssl.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HDFS/configuration/ranger-hdfs-policymgr-ssl.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HDFS/configuration/ranger-hdfs-policymgr-ssl.xml index e14a9e8..71ba3a6 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HDFS/configuration/ranger-hdfs-policymgr-ssl.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HDFS/configuration/ranger-hdfs-policymgr-ssl.xml @@ -23,7 +23,7 @@ <name>xasecure.policymgr.clientssl.keystore</name> <value>/usr/hdp/current/hadoop-client/conf/ranger-plugin-keystore.jks</value> <description>Java Keystore files</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.password</name> @@ -33,13 +33,13 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore</name> <value>/usr/hdp/current/hadoop-client/conf/ranger-plugin-truststore.jks</value> <description>java truststore file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.password</name> @@ -49,18 +49,18 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java keystore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java truststore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/HDFS/configuration/ranger-hdfs-security.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HDFS/configuration/ranger-hdfs-security.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HDFS/configuration/ranger-hdfs-security.xml index b2b8edb..f23706e 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HDFS/configuration/ranger-hdfs-security.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HDFS/configuration/ranger-hdfs-security.xml @@ -23,19 +23,19 @@ <name>ranger.plugin.hdfs.service.name</name> <value>{{repo_name}}</value> <description>Name of the Ranger service containing Hdfs policies</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hdfs.policy.source.impl</name> <value>org.apache.ranger.admin.client.RangerAdminRESTClient</value> <description>Class to retrieve policies from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hdfs.policy.rest.url</name> <value>{{policymgr_mgr_url}}</value> <description>URL to Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> <depends-on> <property> <type>admin-properties</type> @@ -47,24 +47,24 @@ <name>ranger.plugin.hdfs.policy.rest.ssl.config.file</name> <value>/etc/hadoop/conf/ranger-policymgr-ssl.xml</value> <description>Path to the file containing SSL details to contact Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hdfs.policy.pollIntervalMs</name> <value>30000</value> <description>How often to poll for changes in policies?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hdfs.policy.cache.dir</name> <value>/etc/ranger/{{repo_name}}/policycache</value> <description>Directory where Ranger policies are cached after successful retrieval from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.add-hadoop-authorization</name> <value>true</value> <description>Enable/Disable the default hadoop authorization (based on rwxrwxrwx permission on the resource) if Ranger Authorization fails.</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-audit.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-audit.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-audit.xml index 874d0d5..b210fca 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-audit.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-audit.xml @@ -23,7 +23,7 @@ <name>xasecure.audit.is.enabled</name> <value>true</value> <description>Is Audit enabled?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db</name> @@ -39,19 +39,19 @@ <name>xasecure.audit.destination.db</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.url</name> <value>{{audit_jdbc_url}}</value> <description>Audit DB JDBC URL</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.user</name> <value>{{xa_audit_db_user}}</value> <description>Audit DB JDBC User</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.password</name> @@ -61,25 +61,25 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.driver</name> <value>{{jdbc_driver}}</value> <description>Audit DB JDBC Driver</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.credential.provider.file</name> <value>jceks://file{{credential_file}}</value> <description>Credential file store</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.batch.filespool.dir</name> <value>/var/log/hive/audit/db/spool</value> <description>/var/log/hive/audit/db/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs</name> @@ -95,7 +95,7 @@ <name>xasecure.audit.destination.hdfs</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.dir</name> @@ -107,13 +107,13 @@ <name>xasecure.audit.destination.hdfs.dir</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.batch.filespool.dir</name> <value>/var/log/hive/audit/hdfs/spool</value> <description>/var/log/hive/audit/hdfs/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr</name> @@ -129,7 +129,7 @@ <name>xasecure.audit.destination.solr</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.urls</name> @@ -144,7 +144,7 @@ <name>ranger.audit.solr.urls</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.zookeepers</name> @@ -156,13 +156,13 @@ <name>ranger.audit.solr.zookeepers</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.batch.filespool.dir</name> <value>/var/log/hive/audit/solr/spool</value> <description>/var/log/hive/audit/solr/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.provider.summary.enabled</name> @@ -172,6 +172,6 @@ <value-attributes> <type>boolean</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-policymgr-ssl.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-policymgr-ssl.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-policymgr-ssl.xml index 14e7b16..a538843 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-policymgr-ssl.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-policymgr-ssl.xml @@ -23,7 +23,7 @@ <name>xasecure.policymgr.clientssl.keystore</name> <value>/usr/hdp/current/hive-server2/conf/ranger-plugin-keystore.jks</value> <description>Java Keystore files</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.password</name> @@ -33,13 +33,13 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore</name> <value>/usr/hdp/current/hive-server2/conf/ranger-plugin-truststore.jks</value> <description>java truststore file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.password</name> @@ -49,18 +49,18 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java keystore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java truststore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-security.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-security.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-security.xml index a07972a..7ea3391 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-security.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/HIVE/configuration/ranger-hive-security.xml @@ -23,19 +23,19 @@ <name>ranger.plugin.hive.service.name</name> <value>{{repo_name}}</value> <description>Name of the Ranger service containing policies for this HIVE instance</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hive.policy.source.impl</name> <value>org.apache.ranger.admin.client.RangerAdminRESTClient</value> <description>Class to retrieve policies from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hive.policy.rest.url</name> <value>{{policymgr_mgr_url}}</value> <description>URL to Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> <depends-on> <property> <type>admin-properties</type> @@ -47,19 +47,19 @@ <name>ranger.plugin.hive.policy.rest.ssl.config.file</name> <value>/usr/hdp/current/hive-server2/conf/conf.server/ranger-policymgr-ssl.xml</value> <description>Path to the file containing SSL details to contact Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hive.policy.pollIntervalMs</name> <value>30000</value> <description>How often to poll for changes in policies?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.hive.policy.cache.dir</name> <value>/etc/ranger/{{repo_name}}/policycache</value> <description>Directory where Ranger policies are cached after successful retrieval from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.hive.update.xapolicies.on.grant.revoke</name> @@ -69,6 +69,6 @@ <value-attributes> <type>boolean</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/KAFKA/configuration/ranger-kafka-policymgr-ssl.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/KAFKA/configuration/ranger-kafka-policymgr-ssl.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/KAFKA/configuration/ranger-kafka-policymgr-ssl.xml index 2f4c121..24fd407 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/KAFKA/configuration/ranger-kafka-policymgr-ssl.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/KAFKA/configuration/ranger-kafka-policymgr-ssl.xml @@ -23,12 +23,12 @@ <name>xasecure.policymgr.clientssl.keystore</name> <value>/usr/hdp/current/kafka-broker/config/ranger-plugin-keystore.jks</value> <description>Java Keystore files</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore</name> <value>/usr/hdp/current/kafka-broker/config/ranger-plugin-truststore.jks</value> <description>java truststore file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-audit.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-audit.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-audit.xml index abdf2bd..1f3c1d1 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-audit.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-audit.xml @@ -23,7 +23,7 @@ <name>xasecure.audit.is.enabled</name> <value>true</value> <description>Is Audit enabled?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db</name> @@ -39,19 +39,19 @@ <name>xasecure.audit.destination.db</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.url</name> <value>{{audit_jdbc_url}}</value> <description>Audit DB JDBC URL</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.user</name> <value>{{xa_audit_db_user}}</value> <description>Audit DB JDBC User</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.password</name> @@ -61,25 +61,25 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.driver</name> <value>{{jdbc_driver}}</value> <description>Audit DB JDBC Driver</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.credential.provider.file</name> <value>jceks://file{{credential_file}}</value> <description>Credential file store</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.batch.filespool.dir</name> <value>/var/log/knox/audit/db/spool</value> <description>/var/log/knox/audit/db/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs</name> @@ -95,7 +95,7 @@ <name>xasecure.audit.destination.hdfs</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.dir</name> @@ -107,13 +107,13 @@ <name>xasecure.audit.destination.hdfs.dir</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.batch.filespool.dir</name> <value>/var/log/knox/audit/hdfs/spool</value> <description>/var/log/knox/audit/hdfs/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr</name> @@ -129,7 +129,7 @@ <name>xasecure.audit.destination.solr</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.urls</name> @@ -144,7 +144,7 @@ <name>ranger.audit.solr.urls</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.zookeepers</name> @@ -156,13 +156,13 @@ <name>ranger.audit.solr.zookeepers</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.batch.filespool.dir</name> <value>/var/log/knox/audit/solr/spool</value> <description>/var/log/knox/audit/solr/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.provider.summary.enabled</name> @@ -172,6 +172,6 @@ <value-attributes> <type>boolean</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-policymgr-ssl.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-policymgr-ssl.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-policymgr-ssl.xml index 6cc2351..bb0878f 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-policymgr-ssl.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-policymgr-ssl.xml @@ -23,7 +23,7 @@ <name>xasecure.policymgr.clientssl.keystore</name> <value>/usr/hdp/current/knox-server/conf/ranger-plugin-keystore.jks</value> <description>Java Keystore files</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.password</name> @@ -33,13 +33,13 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore</name> <value>/usr/hdp/current/knox-server/conf/ranger-plugin-truststore.jks</value> <description>java truststore file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.password</name> @@ -49,18 +49,18 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java keystore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java truststore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-security.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-security.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-security.xml index 0f0d3a7..37bda4c 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-security.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/KNOX/configuration/ranger-knox-security.xml @@ -23,19 +23,19 @@ <name>ranger.plugin.knox.service.name</name> <value>{{repo_name}}</value> <description>Name of the Ranger service containing policies for this Knox instance</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.knox.policy.source.impl</name> <value>org.apache.ranger.admin.client.RangerAdminJersey2RESTClient</value> <description>Class to retrieve policies from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.knox.policy.rest.url</name> <value>{{policymgr_mgr_url}}</value> <description>URL to Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> <depends-on> <property> <type>admin-properties</type> @@ -47,18 +47,18 @@ <name>ranger.plugin.knox.policy.rest.ssl.config.file</name> <value>/usr/hdp/current/knox-server/conf/ranger-policymgr-ssl.xml</value> <description>Path to the file containing SSL details to contact Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.knox.policy.pollIntervalMs</name> <value>30000</value> <description>How often to poll for changes in policies?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger.plugin.knox.policy.cache.dir</name> <value>/etc/ranger/{{repo_name}}/policycache</value> <description>Directory where Ranger policies are cached after successful retrieval from the source</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/STORM/configuration/ranger-storm-policymgr-ssl.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/STORM/configuration/ranger-storm-policymgr-ssl.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/STORM/configuration/ranger-storm-policymgr-ssl.xml index 21658e7..5672f04 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/STORM/configuration/ranger-storm-policymgr-ssl.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/STORM/configuration/ranger-storm-policymgr-ssl.xml @@ -23,12 +23,12 @@ <name>xasecure.policymgr.clientssl.keystore</name> <value>/usr/hdp/current/storm-client/conf/ranger-plugin-keystore.jks</value> <description>Java Keystore files</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore</name> <value>/usr/hdp/current/storm-client/conf/ranger-plugin-truststore.jks</value> <description>java truststore file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/STORM/configuration/ranger-storm-security.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/STORM/configuration/ranger-storm-security.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/STORM/configuration/ranger-storm-security.xml index 8a3dd2e..f3d7530 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/STORM/configuration/ranger-storm-security.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/STORM/configuration/ranger-storm-security.xml @@ -23,6 +23,6 @@ <name>ranger.plugin.storm.policy.rest.ssl.config.file</name> <value>/usr/hdp/current/storm-client/conf/ranger-policymgr-ssl.xml</value> <description>Path to the file containing SSL details to contact Ranger Admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-audit.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-audit.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-audit.xml index 8237f1c..a6b1baa 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-audit.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-audit.xml @@ -23,7 +23,7 @@ <name>xasecure.audit.is.enabled</name> <value>true</value> <description>Is Audit enabled?</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db</name> @@ -39,19 +39,19 @@ <name>xasecure.audit.destination.db</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.url</name> <value>{{audit_jdbc_url}}</value> <description>Audit DB JDBC URL</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.user</name> <value>{{xa_audit_db_user}}</value> <description>Audit DB JDBC User</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.password</name> @@ -61,25 +61,25 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.jdbc.driver</name> <value>{{jdbc_driver}}</value> <description>Audit DB JDBC Driver</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.credential.provider.file</name> <value>jceks://file{{credential_file}}</value> <description>Credential file store</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.db.batch.filespool.dir</name> <value>/var/log/hadoop/yarn/audit/db/spool</value> <description>/var/log/hadoop/yarn/audit/db/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs</name> @@ -95,7 +95,7 @@ <name>xasecure.audit.destination.hdfs</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.dir</name> @@ -107,13 +107,13 @@ <name>xasecure.audit.destination.hdfs.dir</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.hdfs.batch.filespool.dir</name> <value>/var/log/hadoop/yarn/audit/hdfs/spool</value> <description>/var/log/hadoop/yarn/audit/hdfs/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr</name> @@ -129,7 +129,7 @@ <name>xasecure.audit.destination.solr</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.urls</name> @@ -144,7 +144,7 @@ <name>ranger.audit.solr.urls</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.zookeepers</name> @@ -156,13 +156,13 @@ <name>ranger.audit.solr.zookeepers</name> </property> </depends-on> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.destination.solr.batch.filespool.dir</name> <value>/var/log/hadoop/yarn/audit/solr/spool</value> <description>/var/log/hadoop/yarn/audit/solr/spool</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.audit.provider.summary.enabled</name> @@ -172,6 +172,6 @@ <value-attributes> <type>boolean</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-plugin-properties.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-plugin-properties.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-plugin-properties.xml index 1899d44..97867cc 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-plugin-properties.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-plugin-properties.xml @@ -24,7 +24,7 @@ <value>ambari-qa</value> <display-name>Policy user for YARN</display-name> <description>This user must be system user and also present at Ranger admin portal</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>hadoop.rpc.protection</name> @@ -33,7 +33,7 @@ <value-attributes> <empty-value-valid>true</empty-value-valid> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>common.name.for.certificate</name> @@ -42,7 +42,7 @@ <value-attributes> <empty-value-valid>true</empty-value-valid> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>ranger-yarn-plugin-enabled</name> @@ -59,14 +59,14 @@ <type>boolean</type> <overridable>false</overridable> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_USERNAME</name> <value>yarn</value> <display-name>Ranger repository config user</display-name> <description>Used for repository creation on ranger admin</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>REPOSITORY_CONFIG_PASSWORD</name> @@ -77,6 +77,6 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration> http://git-wip-us.apache.org/repos/asf/ambari/blob/f7bb18db/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-policymgr-ssl.xml ---------------------------------------------------------------------- diff --git a/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-policymgr-ssl.xml b/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-policymgr-ssl.xml index 6ad6e62..5410104 100644 --- a/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-policymgr-ssl.xml +++ b/ambari-server/src/main/resources/stacks/HDP/2.3/services/YARN/configuration/ranger-yarn-policymgr-ssl.xml @@ -23,7 +23,7 @@ <name>xasecure.policymgr.clientssl.keystore</name> <value>/usr/hdp/current/hadoop-client/conf/ranger-yarn-plugin-keystore.jks</value> <description>Java Keystore files</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.password</name> @@ -33,13 +33,13 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore</name> <value>/usr/hdp/current/hadoop-client/conf/ranger-yarn-plugin-truststore.jks</value> <description>java truststore file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.password</name> @@ -49,18 +49,18 @@ <value-attributes> <type>password</type> </value-attributes> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.keystore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java keystore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> <property> <name>xasecure.policymgr.clientssl.truststore.credential.file</name> <value>jceks://file{{credential_file}}</value> <description>java truststore credential file</description> - <on-ambari-upgrade add="true"/> + <on-ambari-upgrade add="false"/> </property> </configuration>
